Meter
Where each vendor stores your data, and what it will guarantee in writing
Jurisdiction is an eligibility filter before price. This 18-vendor map separates sold locations from residency guarantees, distinguishes service attestations from provider or facility claims, and preserves not published, conditional, stale, and unknown states where public evidence does not support a stronger conclusion.
Put your own numbers through the calculator to see what this meter does to a normal month and to the day you restore.
Availability, residency, and attestation are three different questions
A region catalog says where a buyer can create storage. A residency guarantee says where object data is committed to remain. A compliance attestation says what systems, controls, locations, and audit period an independent assessor covered. None of those facts proves the other two. [2] [5] [6]
A vendor-level badge is not automatically an object-storage attestation, and a certified data center is not automatically a certification of the storage service. Where the checked public page does not name the service or expose the report scope, this explainer says not published instead of inferring coverage. [7] [8] [9]
| Buyer question | Evidence required | Honest result when evidence is weaker | Source ref |
|---|---|---|---|
| Can the vendor store in my required country or legal area? | A current official region, endpoint, or location catalog [1] [6] | A best-effort hint is conditional, not a guarantee | [1] [6] |
| Will the object remain inside that boundary? | An explicit storage-location commitment or enforceable jurisdiction control [2] [4] | A selectable endpoint without a non-movement promise remains conditional or not published | [2] [4] |
| Does an audit cover the storage service? | A certificate, attestation report, or official service-in-scope list naming the product [3] [5] | A provider-wide badge is reported with its scope limitation | [3] [5] |
| What if the vendor publishes no attestation on the checked pages? | Record the pages checked and their retrieval date [9] | not published, never absence of compliance | [9] |
| What happens after the jurisdiction filter passes? | Calculate retrieval, requests, temporary-copy storage, and egress for the restore path [10] [11] | Early deletion does not apply to a read-only restore | [10] [11] |
The first nine vendors range from region-locked buckets to best-effort placement
The location column describes published storage availability, not a promise that support access, metadata, billing data, or every optional feature stays in the same place. The guarantee column is deliberately narrower and names replication, CDN, redundancy, or tier exceptions. [4] [26] [30]
Attestations are reported at their published scope. Service-specific audit coverage is stronger evidence than a provider badge, while a facility certification is labeled as facility-level. [3] [27] [22]
The first nine vendors range from region-locked buckets to best-effort placement9 rows
| Provider | Published storage jurisdictions | Single-jurisdiction guarantee | Published compliance attestations and scope | Source ref |
|---|---|---|---|---|
| Amazon S3 | Selectable S3 Regions span the United States, Canada, Brazil, Europe, the Middle East, Africa, Israel, India, Indonesia, Asia Pacific, and Australia [1] | Yes at the selected AWS Region. AWS states that objects in a bucket never leave that Region unless the customer explicitly transfers or replicates them [2] | Amazon S3 is assessed by third-party auditors under SOC, PCI DSS, FedRAMP, and HIPAA programs; reports are available through AWS Artifact and exact program scope must be checked [3] | [1] [2] [3] |
| Azure Blob Storage | Azure publishes geographies in the United States, Canada, Brazil, Chile, Mexico, Europe, Asia Pacific, Australia, China, India, Indonesia, Japan, Korea, Malaysia, New Zealand, Taiwan, Africa, Israel, Qatar, UAE, and Saudi Arabia; Blob availability still varies by region [12] [13] | conditional. LRS keeps copies in one physical location in the primary region and ZRS keeps them within that region's zones; GRS and GZRS add a paired secondary region [4] | Azure states that Storage, including Blobs and cool storage, is included in audits such as CSA STAR, ISO, SOC, PCI DSS, HITRUST, FedRAMP, and DoD; each report has its own service scope [5] | [12] [13] [4] [5] |
| Google Cloud Storage | Single regions are published across North America, South America, Europe, Asia, India, Indonesia, the Middle East, Australia, and Africa; dual-regions and US, EU, and Asia multi-regions are separate choices [14] | Yes for a selected single region. Google states that object data is stored in the bucket location; the EU multi-region is an EU-wide boundary rather than a member-state guarantee [14] | Cloud Storage is named in the service scope for Google Cloud's ISO/IEC 27001 certification and SOC 3 report [15] [16] | [14] [15] [16] |
| Cloudflare R2 | Automatic placement is the default. Optional hints cover Western and Eastern North America, Western and Eastern Europe, Asia-Pacific, and Oceania, but the hints are best effort [6] | conditional. R2 offers an EU jurisdiction restriction that keeps bucket objects stored and processed in the European Union, but it publishes no country-level guarantee; ordinary location hints are not guarantees [6] | Cloudflare publishes ISO 27001, ISO 27018, ISO 27701, SOC 2 Type II, and PCI DSS validations for its global platform. The checked public pages do not separately enumerate R2 in each report's scope, so R2-specific scope is not published [17] [7] | [6] [17] [7] |
| Backblaze B2 | US West, US East, and EU Central are selectable when an account is created [18] | Yes at the account region. Backblaze states that data remains in that region unless the customer directs a move; multiple regions require separate accounts or customer-configured replication [18] | Backblaze states that its cloud storage platform, policies, and procedures have SOC 2 Type 2 attestation by an independent third party. Its ISO 27001 statement describes predominantly used data centers rather than a Backblaze ISO certificate [19] | [18] [19] |
| Wasabi | Published regions include the United States, Canada, the Netherlands, Germany, the United Kingdom, France, Italy, Japan, Singapore, and Australia [20] | Yes for object storage at the selected bucket region. Wasabi says customers control where data is stored by choosing a region-specific bucket; optional replication must stay inside the required boundary [22] [20] | Wasabi publishes ISO 27001 compliance for its products and physical locations, while its hosting data centers are described as SOC 2 compliant and PCI DSS certified. The facility claims must not be presented as a Wasabi SOC 2 report without checking the report [21] [22] | [20] [21] [22] |
| IDrive e2 | Chicago, Dallas, Frankfurt, Ireland, London, Los Angeles, Miami, Milan, Montreal, Oregon, Paris, Phoenix, Singapore, Tokyo, and Virginia are published e2 locations [23] | not published. Region-specific endpoints support location selection, but the checked location page does not state that object data never leaves the selected legal jurisdiction or cover support and processing access [23] | IDrive e2 publishes a SOC 2 Type 2 report for the object-storage solution and ISO/IEC 27001:2022 certification. The SOC report is available to eligible customers, partners, and prospects through support [24] | [23] [24] |
| DigitalOcean Spaces | Spaces is published in NYC3, AMS3, SFO3, SGP1, LON1, FRA1, TOR1, BLR1, SYD1, ATL1, RIC1, and MKC1; Cold availability differs [25] | conditional. A Space is hosted in its selected region and cannot be moved directly between regions, but enabling the optional CDN creates globally cached copies [26] | DigitalOcean explicitly states that Spaces is audited by third parties as part of its SOC 2 Type 2 report [27] | [25] [26] [27] |
| Scaleway Object Storage | Object Storage endpoints are published in Paris, Amsterdam, Warsaw, and Milan; product and class availability differs by location [28] [29] | conditional. Standard storage uses the selected location, but Glacier for Paris and Amsterdam buckets is stored in Scaleway's Paris DC4 cluster, so an Amsterdam bucket is not a Netherlands-only guarantee after that transition [30] | Scaleway publishes ISO/IEC 27001:2022 certification. Its HDS-certified offer explicitly includes Object and Block Storage activities, but HDS requires a dedicated commercial process and the HDS offer is limited to French data centers [31] | [28] [29] [30] [31] |
The remaining nine vendors include single-data-center, sovereign, and global-by-default designs
A single-data-center bucket can satisfy a narrow location rule while requiring the buyer to create a separate compliant disaster-recovery copy. A global-by-default service is ineligible for a hard boundary unless its location control is explicit and enforceable. [36] [51] [53]
Official pages can disagree. Storj's current technical documentation exposes a US-only Regional Workflows location, while its current compliance page also advertises EU restriction. That conflict remains unknown rather than being resolved by inference. [44] [8]
The remaining nine vendors include single-data-center, sovereign, and global-by-default designs9 rows
| Provider | Published storage jurisdictions | Single-jurisdiction guarantee | Published compliance attestations and scope | Source ref |
|---|---|---|---|---|
| OVHcloud Object Storage | Published Object Storage regions cover France, Italy, the United Kingdom, Germany, Poland, Canada, the United States, Singapore, Australia, and India, plus additional Local Zones [32] [33] | Yes for a selected region when optional cross-region replication is not enabled. OVHcloud exposes region-specific endpoints and 1-AZ, 3-AZ, and Local Zone deployment modes [33] [34] | OVHcloud's current product scope lists Object Storage and Object Storage 3-AZ as certified under ISO/IEC 27001:2022, 27017:2015, 27018:2019, and 27701:2019 [35] | [32] [33] [34] [35] |
| Hetzner Object Storage | Falkenstein and Nuremberg in Germany, plus Helsinki in Finland, are the only published Object Storage locations [36] | Yes. Hetzner states that an entire bucket is stored in the selected location and in one data center there [36] | Hetzner publishes an ISO/IEC 27001:2022 certificate whose scope is all hosting services and data centers, with German and Finnish certificate locations listed. Object Storage is covered by the broad hosting-services scope rather than named separately [37] | [36] [37] |
| Akamai Cloud Object Storage | Published endpoints cover the United States, Brazil, Germany, Spain, France, the United Kingdom, Italy, the Netherlands, Sweden, India, Indonesia, Japan, Singapore, and Australia, with some endpoints in limited availability [38] | Yes at the chosen endpoint. Akamai states that an Object Storage endpoint is hosted within a single data center; customer-configured copies elsewhere would create additional jurisdictions [39] [40] | Akamai publishes a SOC 2 Type 1 report whose cloud-computing service scope explicitly includes Object Storage, Block Storage, and Backups [41] | [38] [39] [40] [41] |
| Vultr Object Storage | Amsterdam, Atlanta, Bangalore, Chicago, London, Los Angeles, New Delhi, New Jersey, Seattle, Silicon Valley, Singapore, Sydney, and Tokyo are published Object Storage locations [42] | conditional. Vultr lets the buyer choose a location and recommends explicit multi-location copies for geographic redundancy, but the checked page does not publish a broader non-movement commitment covering all processing [42] | Vultr publishes independently audited SOC 2 Type II with HIPAA Security Rule, ISO/IEC 27001:2022, ISO 20000-1:2018, ISO 27017:2015, and ISO 27018:2019 artifacts at platform level. Object Storage-specific scope is not published on the checked public access page [43] | [42] [43] |
| Storj | Technical docs publish Global Collaboration, US-only Regional Workflows, and global Active Archive locations. A separate compliance page says Storj can restrict data to the EU or US [44] [8] | unknown for EU and yes for the documented US-only Regional Workflows tier. The official EU statements conflict, so an EU guarantee requires a contract and report-scope check before purchase [44] [8] | Storj publishes that Storj Select is hosted exclusively in SOC 2 Type 2 facilities. That is facility-level evidence; the checked page does not publish a Storj product SOC 2 report or audit period, so a service attestation is not published [8] | [44] [8] |
| Oracle OCI Object Storage | OCI publishes commercial cloud regions across the Americas, Europe, the Middle East, Africa, and Asia-Pacific; Object Storage is a regional service [45] [46] | Yes for a normal regional bucket. Oracle also offers separate EU Sovereign Cloud regions in Frankfurt and Madrid with EU-resident operations and support personnel [46] [47] | stale. The public OCI SOC 3 report found in this audit explicitly includes Object Storage but covers April 1 through September 30, 2024. Oracle's compliance catalog lists current programs, but a current Object Storage report period was not verified [48] [49] | [45] [46] [47] [48] [49] |
| Tigris | Global placement is the default. Tigris publishes global, single-region, multi-region, and dual-region choices, including USA and EUR multi-region examples [50] | conditional. Tigris publishes controls that restrict objects to Europe or an individual region; the buyer must set the restriction because the default is global [51] | Tigris announced SOC 2 Type II certification in 2025. The checked public announcement does not publish the report period or enumerate Object Storage components, so exact report scope is not published [52] | [50] [51] [52] |
| Filebase | Filebase exposes one global S3 namespace with region set to auto and no selectable regional buckets [53] [54] | not published. The checked public docs publish no EU-only, country-only, or single-region bucket control or non-movement guarantee [53] | not published. Filebase's encryption page directs buyers to a security page or email contact for certifications but names no certification or audit report on the checked page [9] | [53] [54] [9] |
| Telnyx Cloud Storage | US Central, US East, US West, EU Central, and AP Southeast bucket endpoints are published [55] | not published. The API documentation assigns each bucket a home region and requires regional requests, but it does not state that object data never leaves that legal jurisdiction [55] | Telnyx publishes ISO/IEC 27001, ISO/IEC 27701, SOC 2 Type II, and PCI DSS at company-platform level. Its SOC support page names Voice, Messaging, Wireless, and Video but not Cloud Storage, so Cloud Storage-specific report scope is not published [56] [57] | [55] [56] [57] |
Procurement must verify report scope, period, and location
A badge is screening evidence, not the final control. The buyer still needs the current report or certificate, the named service, covered locations, audit period, trust criteria, exceptions, and customer responsibilities. AWS, Azure, IDrive, Vultr, and Telnyx direct detailed reports through authenticated portals, support, or NDA workflows. [3] [5] [24] [43] [57]
Privacy-law claims and contractual tools are also not interchangeable with third-party attestations. A GDPR statement, HIPAA BAA, encryption feature, or immutability control can matter to the buyer without proving that the object-storage service has a current SOC or ISO assessment. [19] [9]
| Evidence shape | Vendors in this map | What the buyer can conclude | What still requires verification | Source ref |
|---|---|---|---|---|
| Storage service explicitly named in audit scope | Amazon S3, Azure Blob Storage, Google Cloud Storage, DigitalOcean Spaces, IDrive e2, OVHcloud Object Storage, and Akamai Object Storage [3] [5] [15] [27] [24] [35] [41] | A published certification or audit program names the storage service | Current report period, regions, exclusions, and customer controls | [3] [5] [15] [27] [24] [35] [41] |
| Provider or platform attestation without public storage-specific scope | Cloudflare, Vultr, Tigris, and Telnyx [17] [43] [52] [56] | The provider publishes an attestation or certification | Whether the selected object-storage product, region, and plan are in scope | [17] [43] [52] [56] |
| Facility-level certification or attestation | Wasabi's SOC and PCI statements and Storj Select's SOC 2 statement are facility-level claims [22] [8] | The hosting facility has the stated evidence | Whether the provider's service controls and customer-facing system are independently assessed | [22] [8] |
| Broad certificate scope | Hetzner's ISO/IEC 27001 certificate covers all hosting services and its named data-center locations [37] | The provider's hosting-service ISMS is certified | Object Storage-specific controls, exceptions, and customer responsibilities | [37] |
| Conditional regulated offer | Scaleway HDS includes Object and Block Storage only through the dedicated HDS commercial process in France [31] | The regulated offer has a published scope | That the buyer has contracted the qualifying offer rather than ordinary self-service storage | [31] |
| Attestation named nowhere on the checked public page | Filebase [9] | not published | Request the current report and scope directly; do not conclude that no compliance work exists | [9] |
Jurisdiction filters the vendors, then restore egress decides the recovery bill
No storage rate is recalculated on this page. After ineligible jurisdictions are removed, the restore receipt still needs retrieval, requests, temporary-copy storage, and egress. The B2, R2, and Wasabi rules below are copied from the 61-offer providers.json capture and cross-checked against its official source pages; no disagreement was found for these rules. [58] [59] [60] [61]
A read-only restore does not delete, overwrite, move, or transition the source object. It therefore never triggers early deletion by itself; early deletion becomes relevant only if a separate mutation occurs before the minimum duration. [10] [11]
| Provider or evidence gap | State | Verified rule | Rejected conclusion | Source ref |
|---|---|---|---|---|
| Backblaze B2 egress | conditional | Free egress is up to 3 times average monthly storage, then $0.01/GB [58] [59] | Treating every restore as free without calculating the proportional allowance | [58] [59] |
| Cloudflare R2 egress | not charged | Internet egress has no charge, while Class A and Class B operations remain billable and Infrequent Access retrieval is $0.01/GB [58] [60] | Treating free egress as a zero-cost restore | [58] [60] |
| Wasabi excess egress | not published | Free egress is governed by a fair-use policy tied to stored volume; Wasabi publishes a right to limit or suspend service but no per-GB overage rate [58] [61] | Converting excess egress to $0 | [58] [61] |
| Read-only restore | does not apply for early deletion | Retrieval, requests, restored-copy storage, and egress can apply, but merely reading the source does not trigger an early-deletion charge [10] [11] | Charging the remaining minimum duration merely because bytes were restored | [10] [11] |
| Storj EU residency | unknown | The compliance page advertises EU restriction, while current technical location constraints list only a US regional tier plus global tiers [8] [44] | Selecting either official statement silently | [8] [44] |
| Oracle OCI public SOC 3 period | needs re-checking | The located public report names Object Storage but covers April 1 through September 30, 2024 [48] | Presenting that period as a current 2026 attestation without obtaining the current report | [48] |
| Filebase compliance attestation | not published | The checked docs direct buyers to a security page or direct contact but publish no named certification on the page [9] | Reporting either compliant or noncompliant from missing public evidence | [9] |
| Telnyx Cloud Storage SOC scope | not published | Telnyx publishes platform certifications, but its public SOC explainer names Voice, Messaging, Wireless, and Video rather than Cloud Storage [56] [57] | Assuming every Telnyx product is inside the same report boundary | [56] [57] |
Sources
Every figure above comes from one of these pages, on the date shown. Each numbered reference in the text links to its entry here. Vendors change prices; if a date looks old, check the source. Three vendors publish a machine-readable feed and the rest are re-checked by hand, which is why the dates are not uniform.
The source ledger61 sources
- 1AWS documentation: S3docs.aws.amazon.com · checked 2026-07-26
- 2AWS documentation: UsingBucketdocs.aws.amazon.com · checked 2026-07-26
- 3AWS documentation: S3 compliancedocs.aws.amazon.com · checked 2026-07-26
- 4Microsoft Learn: Storage redundancylearn.microsoft.com · checked 2026-07-26
- 5Microsoft Learn: Storage compliance offeringslearn.microsoft.com · checked 2026-07-26
- 6Cloudflare developer docs: Data locationdevelopers.cloudflare.com · checked 2026-07-26
- 7Cloudflare: Iso certificationswww.cloudflare.com · checked 2026-07-26
- 8Storj: Compliancewww.storj.io · checked 2026-07-26
- 9Filebase: Encryptionfilebase.com · checked 2026-07-26
- 10Amazon Web Services: S3 pricingaws.amazon.com · checked 2026-07-26
- 11AWS documentation: Restoring objectsdocs.aws.amazon.com · checked 2026-07-26
- 12Microsoft Azure: Geographiesazure.microsoft.com · checked 2026-07-26
- 13Microsoft Learn: Storage account overviewlearn.microsoft.com · checked 2026-07-26
- 14Google Cloud documentation: Locationsdocs.cloud.google.com · checked 2026-07-26
- 15Google Cloud: Iso 27001cloud.google.com · checked 2026-07-26
- 16Google Cloud: Soc 3cloud.google.com · checked 2026-07-26
- 17Cloudflare: Trust hubwww.cloudflare.com · checked 2026-07-26
- 18Backblaze help centre: U S East Data Region FAQhelp.backblaze.com · checked 2026-07-26
- 19Backblaze: Compliancewww.backblaze.com · checked 2026-07-26
- 20Wasabi documentation: Service urls for wasabis storage regionsdocs.wasabi.com · checked 2026-07-26
- 21Wasabi: Securitywasabi.com · checked 2026-07-26
- 22Wasabi: Trust centerwasabi.com · checked 2026-07-26
- 23IDrive: Locationswww.idrive.com · checked 2026-07-26
- 24IDrive: Compliancewww.idrive.com · checked 2026-07-26
- 25DigitalOcean documentation: Availabilitydocs.digitalocean.com · checked 2026-07-26
- 26DigitalOcean documentation: Featuresdocs.digitalocean.com · checked 2026-07-26
- 27DigitalOcean: Shared responsibility model spaceswww.digitalocean.com · checked 2026-07-26
- 28Scaleway: Conceptswww.scaleway.com · checked 2026-07-26
- 29Scaleway: Product availability by regionwww.scaleway.com · checked 2026-07-26
- 30Scaleway: Object storage faqwww.scaleway.com · checked 2026-07-26
- 31Scaleway: Security and resiliencewww.scaleway.com · checked 2026-07-26
- 32OVHcloud: Regions availabilitywww.ovhcloud.com · checked 2026-07-26
- 33OVHcloud documentation: S3 locationdocs.ovhcloud.com · checked 2026-07-26
- 34OVHcloud: Classeswww.ovhcloud.com · checked 2026-07-26
- 35OVHcloud documentation: Security certificationsdocs.ovhcloud.com · checked 2026-07-26
- 36Hetzner documentation: Generaldocs.hetzner.com · checked 2026-07-26
- 37Hetzner: ISO Certificatewww.hetzner.com · checked 2026-07-26
- 38Akamai techdocs: Endpoint typestechdocs.akamai.com · checked 2026-07-26
- 39Akamai techdocs: Create and manage bucketstechdocs.akamai.com · checked 2026-07-26
- 40Akamai techdocstechdocs.akamai.com · checked 2026-07-26
- 41Akamai: Compliancewww.akamai.com · checked 2026-07-26
- 42Vultr documentation: Object storage faqdocs.vultr.com · checked 2026-07-26
- 43Vultr documentationdocs.vultr.com · checked 2026-07-26
- 44Storj developer docs: S3 compatibilitystorj.dev · checked 2026-07-26
- 45Oracle documentation: Regionsdocs.oracle.com · checked 2026-07-26
- 46Oracle documentation: Objectstorageoverviewdocs.oracle.com · checked 2026-07-26
- 47Oracle documentation: Eu sovereign clouddocs.oracle.com · checked 2026-07-26
- 48Oracle: Oci soc 3 reportwww.oracle.com · checked 2026-07-26
- 49Oracle: Cloud compliancewww.oracle.com · checked 2026-07-26
- 50Tigris: Pricingwww.tigrisdata.com · checked 2026-07-26
- 51dev.todev.to · checked 2026-07-26
- 52dev.todev.to · checked 2026-07-26
- 53Filebase: Account faqfilebase.com · checked 2026-07-26
- 54Filebasefilebase.com · checked 2026-07-26
- 55Telnyx developer docs: Api endpointsdevelopers.telnyx.com · checked 2026-07-26
- 56Telnyx: Securitytelnyx.com · checked 2026-07-26
- 57Telnyx supportsupport.telnyx.com · checked 2026-07-26
- 58This repository: providers.jsonrepository · checked 2026-07-26
- 59Backblaze: Transaction pricingwww.backblaze.com · checked 2026-07-26
- 60Cloudflare developer docs: R2 pricingdevelopers.cloudflare.com · checked 2026-07-26
- 61Wasabi: Faqwasabi.com · checked 2026-07-26