The person who wrote your application stood it up using that CDN though. There are two parties we're concerned about: you and the entity you're communicating with.
You trust your device and the entity, and the entity trusts the infrastructure and services they're using. Everything else is the enemy. So moving the barrier to a CDN which the entity trusts is actually an improvement over intermediate ISPs which neither of you trust.