FEATURES / Compliance
/// Compliance
The controls auditors ask for. Enforced at the storage layer.
Object Lock / WORM, SSE-KMS with your own key, EU and FedRAMP data residency, explicit public-access control, and encrypted credentials — across every cloud Storafleet connects, surfaced in one console.
Start for free/// How it works
Lock what must not change
Turn on Object Lock / WORM for buckets that hold records or backups. Set a default retention so every new object is immutable on upload, and escalate to COMPLIANCE mode where it must be permanent. Works on AWS S3, Backblaze B2, Wasabi, and MinIO.
Hold your own keys
Switch AWS buckets to SSE-KMS with a key you control — rotation on your schedule and a CloudTrail audit of every decrypt. Across every provider, Storafleet shows you exactly what's encrypted at rest, so there are no blind spots.
Pin data to a jurisdiction
Need data to stay in the EU or meet FedRAMP residency? Create R2 buckets pinned to an EU or FedRAMP jurisdiction. The location is fixed at creation and Storafleet handles the endpoints — data physically stays where it must.
Object Lock / WORM immutability
Legal Hold, GOVERNANCE retention, bucket default retention, and irreversible COMPLIANCE mode — the same controls regulators ask for, enforced by the storage layer, not a policy document. AWS S3, Backblaze B2, Wasabi, MinIO.
Bring-your-own-key encryption (SSE-KMS)
On AWS, move from S3-managed keys to your own KMS key — you own rotation and get a CloudTrail audit trail of every decrypt. Optional S3 Bucket Key keeps KMS costs down. Other providers' at-rest status is shown so nothing is assumed.
EU & FedRAMP data residency
Pin Cloudflare R2 buckets to an EU or FedRAMP jurisdiction so data physically stays in-region. Immutable at creation. Helps you meet GDPR data-residency and US public-sector requirements — at the infrastructure level.
Public-access control, both ways
Block all public access on AWS with a one-click Public Access Block, or deliberately make a bucket public read-only on MinIO / Wasabi / DigitalOcean via a managed, merge-safe policy. Either way, exposure is explicit — never an accident.
Credentials encrypted, keys never stored
The credentials you give Storafleet are encrypted at rest with a per-user HKDF-derived AES-256-GCM key — never plaintext, never returned to the browser. Or connect AWS by IAM Role and Storafleet stores no long-lived keys at all.
See your posture across every cloud
Lock state, encryption method, public-access status, and policy risk flags are surfaced per bucket — across AWS, R2, B2, Wasabi, MinIO, and DigitalOcean — so an audit is a screen you read, not a week you dread.
/// Without Storafleet
Compliance controls are scattered across each provider's console, set by hand, and impossible to verify across a multi-cloud estate.
- Object Lock, SSE, and residency each configured differently in each provider's console
- No single view of which buckets are immutable, encrypted with which key, or publicly exposed
- Long-lived access keys sitting in env files because role-based access is fiddly to set up
- 'Prove it' audit requests mean screenshots from three or four different dashboards
- Public exposure happens by accident because the controls are buried and inconsistent
/// With Storafleet
One console for immutability, encryption, residency, access, and audit — applied consistently and visible at a glance, on every cloud.
- WORM (Legal Hold, retention, COMPLIANCE) applied from one visual UI across AWS/B2/Wasabi/MinIO
- SSE-KMS with your own key + at-rest status shown for every provider — no encryption blind spots
- EU/FedRAMP residency pinned at the infrastructure level on Cloudflare R2
- Keyless IAM-Role onboarding (no stored keys) + per-user AES-256-GCM credential encryption
- Posture — lock state, encryption, public access, policy risk — visible per bucket, every cloud
/// When you'll use this
Ransomware-proofing the backup estate
A leaked key shouldn't be able to wipe your backups. You enable Object Lock at bucket creation and set a COMPLIANCE-mode default retention. Now every backup is immutable for its retention window — an attacker with full credentials still can't delete or overwrite a single object. The control lives in the storage layer, where credentials can't override it.
Key featureObject Lock default retention + COMPLIANCE mode
Meeting EU data-residency for a SaaS
Your EU customers' data must never leave the EU. You store it in Cloudflare R2 buckets pinned to the EU jurisdiction — fixed at creation, enforced by the endpoint. Encryption uses your own KMS key with an audit trail. When the auditor asks, you show residency and key custody from one console instead of three provider dashboards.
Key featureR2 EU residency + SSE-KMS with customer-managed keys
Killing long-lived keys across the org
Security policy bans long-lived access keys. You connect every AWS account by IAM Role — Storafleet assumes a role scoped by a per-connection ExternalId and stores no keys. Revoking access is deleting a role, not hunting for a leaked secret. Non-AWS connections keep their keys encrypted with a per-user AES-256-GCM key.
Key featureKeyless IAM-Role/STS onboarding + encrypted credentials
Your storage estate deserves a control plane.
Join the DevOps teams and founders who run every cloud's buckets from one control plane.
Free plan · No credit card · 50+ cloud providers · Cancel any time