Skip to content
Klacos

European Cloudflare alternative: which part to replace, and on what terms

Lists of European alternatives mostly compare content delivery networks. But Cloudflare is also the proxy in front of your site, its rules and its bot handling. Before comparing, know which part you are replacing and what you require from its new operator.

By the Klacos team Published Updated

A European alternative to Cloudflare is chosen one component at a time. If you use Cloudflare to deliver heavy files all over the world, you are looking for a content delivery network. If you mainly use it as a proxy in front of your site, for certificates, caching, rules and bot handling, you are looking for something else, and the usual lists say little about it.

Either way, being European is not only about where the servers are. A proxy sees every request your visitors make, encryption included: who runs it, who holds the keys and who reads the logs matter as much as the country of the data centre.

What the Cloudflare name covers

Under one brand, Cloudflare sells services that are not replaced in the same way:

  • a global content delivery network, serving your files from points of presence close to your visitors;
  • a DNS service;
  • a proxy in front of your site: TLS certificates, caching, redirect, rewrite and routing rules, written in a common expression language;
  • a web application firewall, bot management and rate limiting;
  • functions that run at the edge of the network;
  • access tools for employees.

Comparisons often lump these together. That is why they offer a content delivery network to people looking for a proxy, or the other way round.

The alternatives European lists mention

Directories of European alternatives (european-alternatives.eu, europeanpurpose.com) mostly list content delivery networks: Bunny.net, KeyCDN, Myra, Gcore, CDN77, Leaseweb or OVHcloud, depending on the list. They are good answers for the first component above, and several add a web application firewall or attack protection. For the proxy in front of your site, its rules and bot handling, check exactly what each service covers, component by component, before setting it against your current configuration. We last checked these lists on 8 October 2026, and they change often.

Component Question to ask the alternative
Content delivery Where are its points of presence, and are your visitors near them?
Proxy and certificates Does it obtain and renew your certificates on its own? Where does TLS terminate?
Rules Can it reproduce your redirects, rewrites and caching rules, and test them before publishing?
Caching and purge Can you clear one page, a folder or a tag without clearing the whole site?
Web application firewall Can it watch before it blocks, and take an exception without switching everything off?
Bots Does it judge visitors without making them solve a CAPTCHA? Does it show you why?
Traffic surges Can it make visitors wait on a sale day, instead of letting your server fall over?
Analytics Can you see the share of bots in your traffic, next to your human audience?

Five European operators, component by component

Three of the names on those lists do much more than deliver files, and two operators the lists leave out focus on website security itself. All five offer a web application firewall and some form of bot filtering. What sets them apart is who they sell to, where your traffic is processed, what a suspicious visitor sees, and the price. The table draws on their official documentation, read on 9 October 2026.

Operator In front of your site Bots, and what a suspicious visitor sees Where traffic goes Public pricing
Bunny.net (Slovenia) Content delivery, DNS, web application firewall, rate limiting, purge by tag, load balancing across your servers Verified bots set by category, AI crawlers included; when in doubt, a challenge page that makes the browser compute a JavaScript task Global network by default; a routing filter can keep traffic on its 24 points of presence in the European Union Bunny Shield free, then $9.50 or $99 a month
Gcore (Luxembourg) Content delivery, DNS, web application firewall, rate limiting, failover between servers, a cached copy served if yours goes down Known bots grouped by purpose, with AI search and training crawlers allowed by default; advanced bot management is a paid add-on; a browser check page, then a CAPTCHA if doubt remains Global network; where the firewall processes traffic isn’t stated Free, then €25 or €125 a month excluding VAT
Link11 (Germany) Web application firewall, rate limiting, API security, load balancing across servers; content delivery and DNS alongside JavaScript redirect challenge, in-page script or CAPTCHA; AI crawlers set one by one since January 2026 Link11’s private cloud, or AWS, Google Cloud and Azure; processing locations not stated From €490 a month excluding VAT on an annual contract, no free plan
Myra Security (Germany) Web application firewall, bot management, content delivery, DNS, certificates, optional waiting room JavaScript challenge or CAPTCHA, depending on settings; AI crawlers blocked in one click BSI C5 certified; TLS terminated only in Germany, on request On quotation
UBIKA (France) Web application firewall and API security, as an online service, in your own cloud or installed on your premises JavaScript challenges, IP reputation, optional CAPTCHA Online service hosted in Europe, by OVHcloud in Roubaix; CSPN certification from ANSSI, the French cybersecurity agency On quotation

All five let you watch before you block: a learning mode at Bunny.net, a “Monitoring” mode at Gcore, a “Monitor” action at Link11, two weeks of logging at onboarding with Myra, and a one-click switch from blocking to logging at UBIKA. In their documentation, we found none of them offering audience analytics, a way to replay a configuration against past traffic, or a link for a blocked visitor to challenge the decision.

Start from your own situation. Bunny.net and Gcore are self-service, with a free plan and a global network: the shortest route for a small business that wants baseline protection. Link11 and Myra target larger companies and regulated sectors, with German certifications; Link11 publishes its prices, Myra quotes. UBIKA serves large organisations and the public sector, and it is the only one of the five you can install on your own servers.

Sources, read on 9 October 2026: Bunny.net (Shield, pricing, getting started, verified bots, routing filters); Gcore (pricing, setup, known bots); Link11 (pricing, bot management, documentation); Myra Security (company, firewall, bot management, AI bots, waiting room); UBIKA (Cloud Protector, WAAP Gateway).

What a European alternative should guarantee

The usual argument is legal: an operator subject to foreign law can be compelled to hand over data. Reading “hosted in Europe” is not enough to rule that out. Ask every candidate, European ones included:

  • Which company runs the service, and under which law?
  • Where does TLS terminate, and who holds the private keys to your certificates?
  • How long are your visitors’ logs kept, where, and who can read them?
  • Which processors touch that data, including for geolocating addresses?
  • Can you leave without starting over: do your rules export, and does the service also run on your own machines?

What you lose without a global network

A service run from Europe, with no points of presence on other continents, has two honest limits. Distant visitors wait a little longer, since every request crosses an ocean. And a very large volumetric attack is easier to absorb on a global network. If a large share of your audience is outside Europe, or you are a known target of that kind of attack, keep a global network in front or alongside.

For a site whose visitors are mostly in Europe, those limits weigh little, and a proxy close to your server can even shorten the path of each request.

Our answer: proxy, security and analytics in one place

Klacos covers the proxy in front of your site: automatic certificates, rules with history and simulation, in-memory or on-disk caching, precise purge, load spread across your servers. On security, it brings a web application firewall that watches before it blocks, rate limiting and bot protection with no CAPTCHA by default, judging each visit as a whole. It adds what CDN lists do not cover: a waiting room for your busiest days, and cookieless analytics that shows you the real share of bots in your traffic.

The managed service is run in the European Union, with early access opening in early 2027. It also runs on your own servers, console included, so your visitors’ data never has to leave your machines. Klacos has no global network of points of presence, no DNS service and no edge functions, and it does not replace protection against very large flooding attacks: details are on the performance and availability page.

For Cloudflare and Klacos side by side, line by line, with what each one does and doesn’t do, see our detailed comparison, which links every Cloudflare fact to its source and shows when it was last checked.

Before leaving Cloudflare: the checklist

  • List the components you really use, and the ones you can do without.
  • Export your caching, redirect and rewrite rules: they will be recreated, which is a good moment to tidy them up.
  • Note who holds the certificates for your domains today and where TLS terminates.
  • Decide what you want to do about bots, and AI crawlers in particular, before copying your current settings.
  • Plan the DNS switch and a period where you compare both services on the same traffic.

See what visits your site before you decide

Klacos opens its first access early 2027. Leave your address, or tell us about your case.