Europa-only Alternative zu Cloudflare.

Cloudflare is the most US-exposed vendor in most "EU" stacks because it sits in front of the user - every visitor connects to a Cloudflare edge server before reaching your origin. The EU regions of Cloudflare are EU-located edges, but the parent company is a Delaware corporation with US-controlled key material and US-controlled traffic logs. For Schrems II purposes, Cloudflare in front of personal-data traffic is one of the most defensible problems to remove first, because the alternatives - Bunny.net (SI) and KeyCDN (CH) - have comparable feature sets and dramatically simpler legal stories.

United States Ersatz-Stack, ausschließlich EU 11 Dienste zugeordnet
Anbieter
Cloudflare
Hauptsitz
San Francisco, CA
Rechtsmacht
United States
Rechtsregime
CLOUD Act, FISA 702, EO 12333

"EU-Region" ist keine Souveränität. Vier Fragen entscheiden.

Data-Residency sagt, wo die Bits liegen. Souveränität sagt, welches Rechtssystem Zugriff erzwingen kann. Die Antwort muss auf allen vier Punkten halten, sonst ist der Stack nicht souverän.

Residenz

Wo sind die Daten physisch gespeichert?

Nicht "in der Cloud": welches Rechenzentrum, in welchem Land, unter welcher Jurisdiktion.

Subprozessoren

Wer ist sonst noch in Ihrem Datenpfad?

Jeder Anbieter, der die Daten berührt: das CDN, das E-Mail-Relay, der Error-Tracker, die Analytics-Pipeline.

Rechtsmacht

Wessen Gesetze können die Offenlegung erzwingen?

Ein Anbieter mit US-Hauptsitz untersteht FISA 702 und dem CLOUD Act, auch wenn die Bits in Frankfurt liegen.

Schlüsselverwahrung

Wer hält tatsächlich die Verschlüsselungsschlüssel?

Wenn der Cloud-Anbieter sowohl die Daten als auch die Schlüssel hält, sind die Daten für ihn lesbar, unabhängig von jedem AVV.

Erfüllt nicht AWS · Azure · GCP · EU-Region

Scheitert an Rechtsmacht und Schlüsselverwahrung.

EU-Daten, US-Mutterkonzern, US-Subprozessoren im Standardpfad, vom Anbieter verwaltete Schlüssel.

Erfüllt Binadit Managed Stack

Besteht in allen vier Punkten.

EU-gehostet auf Infrastruktur mit EU-Hauptsitz. Null US-Subprozessoren im Standardpfad. Kunden- oder EU-KMS-Schlüssel. Namentlich in Ihrer Artikel-28-AVV aufgeführt.

Warum Teams aussteigen Cloudflare

The pattern we see: a privacy or DPO review identifies Cloudflare as a US subprocessor that processes every visitor request including IP addresses, browser fingerprints (via Bot Management) and cookies. Under Schrems II that is a transfer that needs supplementary measures - typically encryption that Cloudflare cannot read, which defeats the WAF and Bot Management features that were the reason for using Cloudflare. The simpler answer is to swap to an EU-jurisdictional provider where the legal analysis collapses to "no transfer." Bunny.net is the standard target and the migration is genuinely a few hours of DNS and configuration work.

Cloudflare Dienste und ihre EU-only Äquivalente

Eine Migration ist nicht "eine Box gegen eine andere tauschen". Die Zuordnung unten ist das, was wir für Kunden ausführen, die Folgendes verlassen: Cloudflare auf Grundlage von Schrems II: vollständige EU-Jurisdiktion, kein US-Mutterkonzern im Datenpfad.

Cloudflare CDN

Was wir stattdessen betreiben
Wir implementieren und betreiben ein EU-CDN für Sie: Bunny.net oder KeyCDN, mit Nginx- und Varnish-Caching an Ihrem Origin.
Engineering-Hinweis
Ein CDN ist eine der wenigen Schichten, die wir nicht selbst betreiben. Wir wählen den EU-Anbieter aus, konfigurieren Cache-Header, Purge-Strategie und Origin Shielding und betreiben es als Teil des Managed Service.

Cloudflare WAF

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. Coraza oder ModSecurity mit dem OWASP Core Rule Set, plus CrowdSec für verhaltensbasierte Blockierung.
Engineering-Hinweis
Regeln werden gegen Ihren tatsächlichen Traffic abgestimmt, statt als Standardset ausgeliefert zu werden - das verhindert, dass eine WAF unbemerkt echte Kunden blockiert.

Cloudflare DDoS protection

Was wir stattdessen betreiben
Binadit Private Infrastructure. Upstream volumetrische Filterung, mit Rate Limiting und CrowdSec am Application Edge.
Engineering-Hinweis
Volumetrische Angriffe werden vor Ihren Servern abgefangen. Missbrauch auf Applikationsebene wird dort behandelt, wo er tatsächlich verstanden werden kann, direkt neben Ihrem Traffic.

Cloudflare DNS

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. PowerDNS oder Knot, autoritativ, DNSSEC-signiert.
Engineering-Hinweis
Zonen werden als Standard-Zonendateien exportiert und importiert, das ist meist der unspektakulärste Teil einer Migration. Senken Sie die TTLs eine Woche im Voraus.

Cloudflare R2 (storage)

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. MinIO oder Ceph RGW, S3-kompatibel.
Engineering-Hinweis
R2s Zero-Egress-Modell ist einzigartig; bei EU-Anbietern ist Egress ebenfalls meist kostenlos oder sehr günstig, sodass das Kostenargument übertragbar ist.

Cloudflare Workers

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. Knative oder OpenFaaS auf Ihrem Kubernetes-Cluster.
Engineering-Hinweis
Die meisten Funktionen, die wir migrieren, erweisen sich als kleine HTTP-Handler, die problemlos als gewöhnliche Container laufen, oft günstiger und ohne Cold Start.

Cloudflare Pages

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. Nginx liefert gebaute Assets aus, deployed aus GitLab CI.
Engineering-Hinweis
Der Hauptwert von Pages liegt in der Build-Pipeline; dieser Teil wandert zu Ihrem CI-Provider.

Cloudflare Tunnel (Argo)

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. WireGuard-Tunnel oder ein Nginx-Reverse-Proxy in Ihrer eigenen DMZ.
Engineering-Hinweis
Netbird hat seinen Hauptsitz in Deutschland und bietet das „Kein-öffentliche-IP“-Muster mit EU-Gerichtsbarkeit. Selbstverwaltetes Wireguard ist die Standard-souveräne Antwort.

Cloudflare Access (zero trust)

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. WireGuard mit Keycloak oder Authentik vor internen Services.
Engineering-Hinweis
Für rein interne Anwendungen ist ein OIDC-geschützter Reverse Proxy auf EU-Infrastruktur funktional gleichwertig.

Cloudflare Stream (video)

Was wir stattdessen betreiben
Transcoding mit FFmpeg auf Binadit-Infrastruktur, ausgeliefert über ein EU-CDN wie Bunny.net.
Engineering-Hinweis
Transcoding ist ein Batch-Workload, der auf Kapazität läuft, die Sie bereits besitzen. Die Auslieferung erfolgt über gewöhnliches HTTP über ein CDN, das wir für Sie konfigurieren.

Cloudflare Bot Management

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. CrowdSec zur verhaltensbasierten Erkennung, mit Rate Limiting und Challenge-Seiten am Edge.
Engineering-Hinweis
CrowdSec hat seinen Hauptsitz in FR und wird zunehmend leistungsfähiger. Für E-Commerce mit hohem Traffic ist DataDome (ebenfalls FR) die Enterprise-Alternative.

Wie wir migrieren von Cloudflare

Eine typische Mittelstand-Migration läuft in drei Phasen. Die Zahlen unten gehen von einem 6-10-köpfigen Engineering-Team und einem mäßig komplexen Anwendungs-Stack aus.

  1. Days 1-3

    Inventory & risk-rank

    List every Cloudflare product in use: CDN, DNS, WAF rules, Workers, Pages, R2, Tunnel, Access. Map each to a personal-data exposure (does it touch PII?) and migration complexity. Output: priority list, usually CDN/DNS first.

  2. Days 4-10

    Soft swap (CDN, DNS, R2)

    Provision Bunny pull zones for the same hostnames. Test with a staging hostname. Cut DNS over with low TTL pre-stage. R2 → Bunny Storage migration via parallel-write. WAF rules ported manually to Bunny WAF.

  3. Weeks 2-6

    Hard pieces (Workers, Tunnel, Access)

    Worker code reviewed and either ported to Bunny Edge Scripting, rewritten as origin-side middleware, or self-hosted on Knative. Tunnel replaced with Netbird or self-managed Wireguard. Access replaced with Pomerium or Authelia. Pages workloads moved to GitLab Pages or self-hosted.

Cloudflare-to-Bunny migrations almost always reduce monthly spend by 40-70% at typical mid-market volumes. The exceptions are Workers-heavy stacks (where the equivalent self-hosted infrastructure has higher fixed cost) and high-traffic Pages stacks (where Cloudflare's aggressive free tier is hard to match).

Cloudflare has EU-only data plans now - does that solve it?
Cloudflare's "Data Localization Suite" can keep EU traffic on EU edges and EU keys, which addresses residency. It does not address jurisdiction: Cloudflare Inc. remains a US corporation subject to the CLOUD Act. For most Schrems II analyses, the data-localization product is an improvement but not full sovereignty.
Will switching CDN affect performance for European visitors?
For European users specifically, Bunny.net often performs equal or better than Cloudflare because their EU POP density is higher per-traffic. Real-world tests on e-commerce migrations have shown TTFB improvements of 10-30ms for EU-specific traffic. For global users (US, APAC), Cloudflare's POP count is larger.
How do we handle Cloudflare Workers replacement?
Three patterns depending on the Worker: (1) trivial request rewrites move to Bunny Edge Scripting unchanged, (2) Workers that talk to KV / Durable Objects need a re-architect - typically the logic moves to the origin and uses Redis or Postgres, (3) Workers acting as API endpoints become small Knative services on EU infrastructure.
Is Bunny.net a real Schrems II-safe alternative?
Bunny.net is BunnyWay d.o.o., headquartered in Ljubljana, Slovenia (EU member). The legal entity is fully under EU jurisdiction. Their published subprocessor list is short and EU-focused. For Schrems II, the analysis collapses to "no third-country transfer" which is materially easier than Cloudflare's data-localization story.
What about Fastly or Akamai?
Both US-headquartered. Fastly is San Francisco; Akamai is Cambridge, MA. Same CLOUD Act analysis as Cloudflare. They are not Schrems II-easier than Cloudflare; they are different US providers with different feature sets.
How long does a Cloudflare migration take?
For a typical workload (CDN, DNS, basic WAF, no Workers): 1-2 weeks elapsed. For a Workers-heavy or Tunnel-dependent setup: 4-8 weeks. We can run the whole thing as a managed migration if you want it done without burning your team's capacity.

Plane deinen Exit von Cloudflare.

30-minütiges Scoping-Gespräch. Wir bilden Ihren Stack auf EU-only Alternativen ab, schätzen den Migrationsaufwand und sagen Ihnen, ob es die richtige Entscheidung ist.