Restore and planning
Which vendors document an immutable backup target
A source-dated matrix across all 18 vendors and 61 offers in the provider dataset. Native retention systems remain distinct from S3 Object Lock, class and region limits stay visible, and a missing retention limit or backup-tool integration remains not published.
Put your own numbers through the calculator to see what this meter does to a normal month and to the day you restore.
Object Lock support is necessary, but the backup tool decides eligibility
An immutable target must prevent deletion or overwrite for the required retention period and must be configurable by the selected backup tool. S3 compatibility alone is not enough: the storage API must expose the exact retention operations the tool uses, and the tool must support the vendor's mode and bucket configuration. [1] [9]
Governance mode is bypassable by a specifically authorized identity. Compliance mode cannot be shortened or bypassed during retention, including by the account root in Amazon S3. Native systems such as Azure immutable Blob Storage, Cloudflare R2 bucket locks, Google Cloud locks, and Oracle retention rules use different controls, so their rows explain the mapping instead of forcing S3 labels onto them. [1] [4] [5] [6] [7]
A named tool in this matrix means the vendor or tool documentation explicitly describes immutable use. It is not a test result. not published means the checked official documentation did not verify that cell; it never means false or zero. No provider receives a score or best label. [3] [10] [11]
| Decision gate | Required evidence | Failure state | Source ref |
|---|---|---|---|
| Immutable storage control | Documented WORM, Object Lock, or native retention control that blocks deletion or overwrite | not published, not comparable, or false | [1] [4] [5] |
| Retention mode | Governance bypass behavior and compliance non-bypass behavior, or a precise native equivalent | not published or not comparable | [1] [4] [6] |
| Versioning prerequisite | Required, automatic, conditional, incompatible, or explicitly not required | not published | [1] [4] [8] |
| Retention limit | Published minimum and maximum, or an explicit not published boundary | not published | [2] [4] [10] |
| Backup-tool compatibility | Named immutable integration and its mode or configuration constraints | not published or false | [3] [10] [11] [12] |
Every provider stays visible, including incomplete and non-comparable implementations
The matrix represents all 61 dataset offers through 18 provider rows. Provider-level documentation applies only to the offer scope stated in each row. Amazon S3 Express One Zone, Telnyx's EU location, and any other documented exception remain outside a broad supported label. [13] [43]
A true support value means official documentation describes the storage control. It does not prove that every backup tool works. A false value is used only where the published capability boundary rules out the required control. Native retention systems receive not comparable when governance and compliance are not the vendor's actual modes. [18] [41] [7]
Retention ranges show only published limits. When a vendor accepts days or years but does not publish the maximum in the checked documentation, the cell states maximum not published rather than assuming the Amazon S3 limit. [19] [25] [29]
Every provider stays visible, including incomplete and non-comparable implementations18 rows
| Provider | Dataset offers | Offer-level evidence result | Limiting evidence | Source ref |
|---|---|---|---|---|
| Amazon S3 | 15 | 14 supported; 1 does not apply | Express One Zone directory buckets are outside the general-purpose-bucket Object Lock scope | [1] [13] |
| Azure Blob Storage | 8 | 8 supported | Uses Azure container-level or version-level WORM controls rather than S3 naming | [4] |
| Google Cloud Storage | 5 | 5 supported | Uses Object Retention Lock and Bucket Lock; tool workflows can add versioning requirements | [6] [16] [17] |
| Cloudflare R2 | 2 | 2 not comparable | Native bucket locks exist, but S3 Object Lock APIs are not implemented and native rules are removable | [5] [18] |
| Backblaze B2 | 1 | 1 supported | Veeam compatibility is documented, but another tool still requires its own qualification | [10] |
| Wasabi | 1 | 1 supported | Veeam requires Compliance mode and vendor-specific bucket configuration | [19] [11] |
| IDrive e2 | 1 | 1 supported | Numeric retention limits and a separate versioning prerequisite are not published | [20] [21] [12] |
| DigitalOcean Spaces | 2 | 2 not published | Write headers are documented, but the bucket-level Object Lock enforcement contract is not | [23] [22] [24] |
| Scaleway Object Storage | 3 | 3 supported | A numeric maximum retention and named immutable-backup integration are not published | [25] |
| OVHcloud Object Storage | 5 | 4 supported; 1 conditional | Current OVHcloud pages disagree about Object Lock support for Cold Archive | [26] [27] [28] |
| Hetzner Object Storage | 1 | 1 supported | The Veeam path has vendor-stated configuration and license requirements | [29] [31] |
| Akamai Cloud Object Storage | 1 | 1 supported | Object Lock is documented on all E0 through E3 endpoint types; named backup-tool qualification is not published | [32] |
| Vultr Object Storage | 5 | 5 conditional | The feature toggle and IAM actions are published, but retention-mode enforcement is not; Archive also conflicts with versioning | [34] [35] [36] |
| Storj | 1 | 1 supported | A separate versioning prerequisite and numeric maximum retention are not published | [37] [38] |
| Oracle OCI Object Storage | 3 | 3 not comparable | OCI uses native retention rules that are incompatible with Object Versioning, not the S3 Object Lock API | [7] [8] |
| Tigris | 4 | 4 not published | Object Lock IAM actions and request names are visible, but retention-mode enforcement is not documented | [40] [39] |
| Filebase | 1 | 1 unsupported | The published S3 capability boundary does not provide the required versioning and Object Lock operations | [41] [42] [13] |
| Telnyx Cloud Storage | 2 | 1 supported; 1 does not apply | The current Object Lock guide limits support to US buckets, excluding the dataset's EU offer | [43] |
The matrix narrows eligibility but does not choose a winner
Amazon S3, Azure Blob Storage, Google Cloud Storage, Backblaze B2, Wasabi, IDrive e2, Scaleway, OVHcloud, Hetzner, Akamai, Storj, and US-region Telnyx publish an immutable storage control in the checked official documentation. Their retention modes, limits, region scope, and named backup-tool evidence are not interchangeable. [1] [4] [6] [10] [19] [20] [25] [26] [29] [32] [37] [43]
Cloudflare R2 and Oracle OCI publish native retention controls that are not comparable to a full S3 governance/compliance implementation. DigitalOcean, Vultr, and Tigris remain not published where official material did not verify the required contract. Filebase is false for the current S3 Object Lock target requirement because its published matrix does not support the required write-side versioning boundary. [18] [7] [22] [33] [39] [41]
Price cannot resolve the remaining choice. The buyer must first name the backup tool, required immutable mode, retention period, region, workload type, restore destination, and recovery volume. Only vendors whose documented controls and tool workflow satisfy all of those gates are comparable, and egress belongs in the final recovery receipt. [3] [11] [12] [10]
| Published evidence group | Providers | What the label does not prove | Source ref |
|---|---|---|---|
| Immutable control published | Amazon S3, Azure Blob Storage, Google Cloud Storage, Backblaze B2, Wasabi, IDrive e2, Scaleway, OVHcloud, Hetzner, Akamai, Storj, Telnyx US | It does not prove every class, region, backup tool, or retention period is eligible | [1] [4] [6] [10] [19] [20] [25] [26] [29] [32] [37] [43] |
| Native control, not S3 governance/compliance | Cloudflare R2, Oracle OCI Object Storage | It does not prove compatibility with a tool that requires the S3 Object Lock API | [5] [18] [7] |
| Required contract not published | DigitalOcean Spaces, Vultr Object Storage, Tigris | It does not mean unsupported; it prevents a sourced eligibility claim | [22] [33] [39] |
| Current published capability rules out S3 Object Lock target | Filebase | It does not make a claim about future support or a non-S3 retention product | [41] [42] |
Sources
Every figure above comes from one of these pages, on the date shown. Each numbered reference in the text links to its entry here. Vendors change prices; if a date looks old, check the source. Three vendors publish a machine-readable feed and the rest are re-checked by hand, which is why the dates are not uniform.
The source ledger43 sources
- 1AWS documentation: Object lockdocs.aws.amazon.com · checked 2026-07-26
- 2AWS documentation: Object lock managingdocs.aws.amazon.com · checked 2026-07-26
- 3Amazon Web Services: Object lockaws.amazon.com · checked 2026-07-26
- 4Microsoft Learn: Immutable storage overviewlearn.microsoft.com · checked 2026-07-26
- 5Cloudflare developer docs: Bucket locksdevelopers.cloudflare.com · checked 2026-07-26
- 6Google Cloud documentation: Object lockdocs.cloud.google.com · checked 2026-07-26
- 7Oracle documentationdocs.oracle.com · checked 2026-07-26
- 8Oracle documentation: Usingversioningdocs.oracle.com · checked 2026-07-26
- 9Veeam help centre: Immutabilityhelpcenter.veeam.com · checked 2026-07-26
- 10Backblaze: Cloud storage object lockwww.backblaze.com · checked 2026-07-26
- 11Wasabi documentation: Wasabi veeam object lock integrationdocs.wasabi.com · checked 2026-07-26
- 12IDrive: Veeam objectlock guidewww.idrive.com · checked 2026-07-26
- 13AWS documentation: Object lock configuredocs.aws.amazon.com · checked 2026-07-26
- 14Veeam help centre: Immutabilityhelpcenter.veeam.com · checked 2026-07-26
- 15Veeam: Kb4241www.veeam.com · checked 2026-07-26
- 16Google Cloud documentation: Bucket lockdocs.cloud.google.com · checked 2026-07-26
- 17Veeam help centre: Plugins mssql object storage immutablehelpcenter.veeam.com · checked 2026-07-26
- 18Cloudflare developer docs: Apidevelopers.cloudflare.com · checked 2026-07-26
- 19Wasabi documentation: Object lockingdocs.wasabi.com · checked 2026-07-26
- 20IDrive: Object lockwww.idrive.com · checked 2026-07-26
- 21IDrive: Faq objectswww.idrive.com · checked 2026-07-26
- 22DigitalOcean documentation: S3 compatibilitydocs.digitalocean.com · checked 2026-07-26
- 23DigitalOcean documentation: Spacesdocs.digitalocean.com · checked 2026-07-26
- 24DigitalOcean documentation: Enable versioningdocs.digitalocean.com · checked 2026-07-26
- 25Scaleway: Use object lockwww.scaleway.com · checked 2026-07-26
- 26OVHcloud help centrehelp.ovhcloud.com · checked 2026-07-26
- 27OVHcloud help centrehelp.ovhcloud.com · checked 2026-07-26
- 28OVHcloud help centrehelp.ovhcloud.com · checked 2026-07-26
- 29Hetzner documentation: Protect object lock retentiondocs.hetzner.com · checked 2026-07-26
- 30Hetzner documentation: Buckets objectsdocs.hetzner.com · checked 2026-07-26
- 31Hetzner documentation: Veeamdocs.hetzner.com · checked 2026-07-26
- 32Akamai techdocs: Protect data with object locktechdocs.akamai.com · checked 2026-07-26
- 33Vultr documentation: S3 compatibility matrixdocs.vultr.com · checked 2026-07-26
- 34Vultr documentation: Manage bucketsdocs.vultr.com · checked 2026-07-26
- 35Vultr documentation: Storage actionsdocs.vultr.com · checked 2026-07-26
- 36Vultr documentation: Limitsdocs.vultr.com · checked 2026-07-26
- 37Storj developer docs: Object lockstorj.dev · checked 2026-07-26
- 38Storj: Securitywww.storj.io · checked 2026-07-26
- 39Tigris: Pricingwww.tigrisdata.com · checked 2026-07-26
- 40Tigris: Authnzwww.tigrisdata.com · checked 2026-07-26
- 41Filebase: Compatibility matrixfilebase.com · checked 2026-07-26
- 42Filebase: Buckets and objectsfilebase.com · checked 2026-07-26
- 43Telnyx developer docs: Lock and retentiondevelopers.telnyx.com · checked 2026-07-26