Meter
Object Lock, native immutability, and the difference on the bill
Object Lock is an S3 retention control for protecting object versions with time-based retention or a legal hold. Native WORM and retention systems can solve a similar protection job without implementing the S3 Object Lock API, so they remain separate capability states.
Put your own numbers through the calculator to see what this meter does to a normal month and to the day you restore.
Object Lock protects object versions under retention or legal hold
Amazon S3 Object Lock is a WORM retention control for object versions. A time-based retention period or legal hold can prevent a protected version from being overwritten or deleted while the rule applies. [1]
Governance mode allows a specifically authorized identity to bypass retention. Compliance mode cannot be shortened or bypassed during the active period, including by the Amazon S3 account root. Versioning and exact API behavior are part of the eligibility contract. [1] [2]
Object Lock is not a synonym for every immutable-storage feature. Azure immutable Blob Storage, Google Cloud retention locks, Cloudflare R2 bucket locks, and Oracle retention rules use native controls with different APIs and bypass behavior. [3] [4] [5] [6]
| Control | Plain meaning | Compatibility consequence | Source ref |
|---|---|---|---|
| Governance mode | Ordinary deletion and retention changes are blocked, but an authorized bypass is possible [1] | A tool or threat model that requires non-bypassable retention cannot treat governance as compliance | [1] |
| Compliance mode | Retention cannot be shortened or bypassed during the active period [1] | Deletion waits until the rule permits it | [1] |
| Legal hold | Protection has no required fixed expiration and remains until an authorized removal [1] | Capacity can remain billable beyond an ordinary retention schedule | [1] |
| Native retention system | A vendor-specific WORM or retention control outside the S3 Object Lock API [3] [5] [6] | not comparable to S3 modes until the backup tool and required operations are checked | [3] [5] [6] |
The pricing dataset and feature documentation answer different Object Lock questions
The canonical dataset records 24 of 61 offers as true, 1 as false, and 36 as not published in its object_lock_immutability field. Many not published values came from pricing-page evidence, while separate current product documentation verifies native or S3 retention controls for some of those vendors. Both observations remain visible instead of silently replacing the dataset. [7] [1] [3]
Supported means the checked official documentation describes the required control at the stated offer scope. It does not prove every class, region, retention period, or backup tool works. not published does not mean false, and native controls remain not comparable to a tool that requires the S3 Object Lock API. [9] [29]
The pricing dataset and feature documentation answer different Object Lock questions18 rows
| Provider | Dataset field across offers | Current official evidence result | Limiting evidence | Source ref |
|---|---|---|---|---|
| Amazon S3 | 14 true; 1 false [7] | 14 supported; Express One Zone does not apply [1] [2] | Directory buckets are outside the general-purpose-bucket Object Lock scope | [7] [1] [2] |
| Azure Blob Storage | 8 not published [7] | 8 supported through native immutable Blob Storage [3] | Uses Azure WORM controls rather than S3 Object Lock naming | [7] [3] |
| Google Cloud Storage | 5 not published [7] | 5 supported through Object Retention Lock and Bucket Lock [4] [8] | Tool workflows and versioning requirements remain separate | [7] [4] [8] |
| Cloudflare R2 | 2 not published [7] | 2 not comparable [5] [9] | Native removable bucket locks exist, but S3 Object Lock APIs are not implemented | [7] [5] [9] |
| Backblaze B2 | 1 true [7] | 1 supported [10] | Each backup tool still needs its own qualification | [7] [10] |
| Wasabi | 1 not published [7] | 1 supported [11] | Documented Veeam integration requires vendor-specific configuration and Compliance mode | [7] [11] [12] |
| IDrive e2 | 1 not published [7] | 1 supported [13] | Numeric maximum retention remains not published in the checked evidence | [7] [13] |
| DigitalOcean Spaces | 2 not published [7] | 2 not published [14] [15] | Write headers are documented, but the bucket-level enforcement contract was not verified | [7] [14] [15] |
| Scaleway Object Storage | 3 true [7] | 3 supported [16] | A numeric maximum retention and named tool integration remain not published | [7] [16] |
| OVHcloud Object Storage | 5 true [7] | 4 supported; Cold Archive conditional [17] [18] [19] | Two current OVHcloud FAQ pages disagree on Cold Archive Object Lock support | [7] [17] [18] [19] |
| Hetzner Object Storage | 1 true [7] | 1 supported [20] | The documented Veeam path has configuration and license requirements | [7] [20] [21] |
| Akamai Cloud Object Storage | 1 not published [7] | 1 supported [22] | A named immutable-backup integration remains not published | [7] [22] |
| Vultr Object Storage | 5 not published [7] | 5 conditional [23] [24] [25] | Feature controls are published, but retention enforcement is incomplete and Archive conflicts with versioning | [7] [23] [24] [25] |
| Storj | 1 not published [7] | 1 supported [26] | Numeric maximum retention remains not published | [7] [26] |
| Oracle OCI Object Storage | 3 not published [7] | 3 not comparable [6] [27] | Native retention rules are incompatible with Object Versioning and are not the S3 Object Lock API | [7] [6] [27] |
| Tigris | 4 not published [7] | 4 not published [28] | Object Lock action names are visible, but retention enforcement was not verified | [7] [28] |
| Filebase | 1 not published [7] | 1 unsupported for the S3 Object Lock requirement [29] [30] | The published capability boundary omits required versioning and Object Lock operations | [7] [29] [30] |
| Telnyx Cloud Storage | 2 not published [7] | US supported; EU does not apply [31] | The current guide limits Object Lock to US buckets | [7] [31] |
Object Lock decides eligibility before price
A vendor without the required retention mode, region, and backup-tool workflow is unsupported or ineligible regardless of its storage rate. Protected versions can remain billable until retention permits removal, so the retention period belongs in capacity planning. [1] [32]
Reading protected data is allowed by the WORM model. A read-only restore can incur retrieval, requests, temporary-copy storage, and egress, but it does not trigger early deletion and does not remove the retained version. [1] [33]
| Decision order | Question | Failure treatment | Source ref |
|---|---|---|---|
| 1. Retention control | Does the exact offer enforce the required mode and duration? [1] | unsupported, not comparable, not published, or conditional | [1] |
| 2. Backup tool | Does the tool document the vendor's immutable workflow? [12] | Unsupported tools do not enter the price ranking | [12] |
| 3. Capacity | How long do protected versions remain billable? [32] | Unknown retained capacity prevents a complete normal-month estimate | [32] |
| 4. Recovery | What retrieval, request, temporary-copy, and egress meters apply? [33] | Early deletion: does not apply for the read-only restore | [33] |
Sources
Every figure above comes from one of these pages, on the date shown. Each numbered reference in the text links to its entry here. Vendors change prices; if a date looks old, check the source. Three vendors publish a machine-readable feed and the rest are re-checked by hand, which is why the dates are not uniform.
The source ledger33 sources
- 1AWS documentation: Object lockdocs.aws.amazon.com · checked 2026-07-26
- 2AWS documentation: Object lock configuredocs.aws.amazon.com · checked 2026-07-26
- 3Microsoft Learn: Immutable storage overviewlearn.microsoft.com · checked 2026-07-26
- 4Google Cloud documentation: Object lockdocs.cloud.google.com · checked 2026-07-26
- 5Cloudflare developer docs: Bucket locksdevelopers.cloudflare.com · checked 2026-07-26
- 6Oracle documentationdocs.oracle.com · checked 2026-07-26
- 7This repository: providers.jsonrepository · checked 2026-07-25T15:34:44Z
- 8Google Cloud documentation: Bucket lockdocs.cloud.google.com · checked 2026-07-26
- 9Cloudflare developer docs: Apidevelopers.cloudflare.com · checked 2026-07-26
- 10Backblaze: Cloud storage object lockwww.backblaze.com · checked 2026-07-26
- 11Wasabi documentation: Object lockingdocs.wasabi.com · checked 2026-07-26
- 12Wasabi documentation: Wasabi veeam object lock integrationdocs.wasabi.com · checked 2026-07-26
- 13IDrive: Object lockwww.idrive.com · checked 2026-07-26
- 14DigitalOcean documentation: S3 compatibilitydocs.digitalocean.com · checked 2026-07-26
- 15DigitalOcean documentation: Spacesdocs.digitalocean.com · checked 2026-07-26
- 16Scaleway: Use object lockwww.scaleway.com · checked 2026-07-26
- 17OVHcloud help centrehelp.ovhcloud.com · checked 2026-07-26
- 18OVHcloud help centrehelp.ovhcloud.com · checked 2026-07-26
- 19OVHcloud help centrehelp.ovhcloud.com · checked 2026-07-26
- 20Hetzner documentation: Protect object lock retentiondocs.hetzner.com · checked 2026-07-26
- 21Hetzner documentation: Veeamdocs.hetzner.com · checked 2026-07-26
- 22Akamai techdocs: Protect data with object locktechdocs.akamai.com · checked 2026-07-26
- 23Vultr documentation: Manage bucketsdocs.vultr.com · checked 2026-07-26
- 24Vultr documentation: Storage actionsdocs.vultr.com · checked 2026-07-26
- 25Vultr documentation: Limitsdocs.vultr.com · checked 2026-07-26
- 26Storj developer docs: Object lockstorj.dev · checked 2026-07-26
- 27Oracle documentation: Usingversioningdocs.oracle.com · checked 2026-07-26
- 28Tigris: Authnzwww.tigrisdata.com · checked 2026-07-26
- 29Filebase: Compatibility matrixfilebase.com · checked 2026-07-26
- 30Filebase: Buckets and objectsfilebase.com · checked 2026-07-26
- 31Telnyx developer docs: Lock and retentiondevelopers.telnyx.com · checked 2026-07-26
- 32Amazon Web Services: S3 pricingaws.amazon.com · checked 2026-07-26
- 33AWS documentation: Restoring objectsdocs.aws.amazon.com · checked 2026-07-26