FEATURES / How it works

/// How it works

Your files never live with us.

Storafleet is a control plane for the buckets you already own — not a copy of your data. Browse, share, and move objects across 50+ clouds from one console, while your file contents stay in your buckets and never come to rest on our servers.

Start for free
PRESIGNED · DIRECTBrowse · Upload · Download · Share
Your browser
signed, expiring URL
Your bucket
Storafleet
hands you a signed key, then steps out of the path

Your files go straight between your browser and your bucket. We never see the bytes.

STREAMING · IN-FLIGHTMigrate & Copy — across accounts and clouds
Source bucket
Storafleet enginestreams through · nothing written to disk
Destination bucket

Bytes pass through in-flight and are discarded as they flow — never buffered, never persisted. A same-cloud copy stays inside the provider and never touches us at all.

What we keep
  • Your credentials — encrypted at rest with AES-256-GCM, per-user derived key
  • Metadata — bucket & object listings, sizes, configuration
What we never store
  • Your file contents — never written to our disks, never retained

Read the exact request flow in the docs

One console. Your data stays yours.

/// How it works

01

Browse & search

We call the S3 API with your credentials to list buckets and objects — names, sizes, timestamps, configuration. The objects themselves never move; we only read metadata.

02

Upload & download

Storafleet mints a short-lived presigned URL and your browser transfers the file directly to or from your bucket. The bytes never pass through our servers.

03

Share & collect

A share link or file-request link is a presigned URL too. Your recipient's browser talks straight to your bucket — no public access, and we never proxy the file.

04

Migrate & copy

Cross-cloud transfers stream through our engine — read from source, written to destination — in-flight, checkpointed and resumable, and never written to disk. A same-cloud copy uses the provider's own server-side copy and never leaves it.

Credentials, encrypted

Your access keys are sealed at rest with AES-256-GCM using a per-user derived key, and decrypted only in memory to sign a request. Never stored in plaintext, never shared.

Metadata, not contents

We index listings, sizes, and configuration so search and dashboards are instant. Your file contents are never copied into our systems.

Direct by default

Everyday reads and writes are presigned — the transfer is browser to bucket. Storafleet hands out the signed URL and stays out of the data path entirely.

Streamed, never stored

When a migration has to move bytes between clouds, they stream through our engine and are discarded as they flow. Nothing is buffered to disk, and there's no object-size cap.

Your storage, your control

Files live in buckets you own, under your provider's IAM and encryption. Disconnect Storafleet and your data is exactly where it was — nothing to export, nothing left behind.

Auditable & honest

We're upfront about the one path that transits our engine — migration. Everything else is direct. Hand this page to a security reviewer, or read the technical deep-dive.

/// Without Storafleet

“Where does my data actually go when I use a third-party tool?” — on most security reviews, that question has no clear answer.

  • SaaS tools that copy your files onto their servers to “process” them
  • No clear answer to “do you store or read our data?” on a security questionnaire
  • Credentials pasted into tools with opaque handling
  • Migration tools that route terabytes through a black box
  • Sharing a file means making a bucket public — permanently

/// With Storafleet

Every byte's path is documented. Your files stay in your buckets; only metadata and encrypted keys ever reach us.

  • Presigned, direct browser-to-bucket transfers — we never see the bytes
  • A public page (this one) you can hand to a security reviewer
  • Credentials sealed with AES-256-GCM, decrypted only in memory to sign
  • Migrations stream in-flight and are never written to disk
  • Share with time-limited presigned links — no public buckets

/// When you'll use this

Security Reviewer01

Answering “do you store our data?”

A prospect's security team asks where files actually go. You send them this page: everyday actions are presigned and direct, migration streams in-flight and is never persisted, and only encrypted credentials plus metadata ever reach Storafleet.

Key featureDocumented, honest data-flow

Platform Engineer02

Moving 40 TB off AWS without a black box

You cut over from S3 to R2. The transfer streams source to destination through the engine — checkpointed and resumable — with no object buffered to disk and no per-object size cap. You watch it in the Transfers tab.

Key featureStreaming migration engine

Founder03

Sharing a deliverable without exposing a bucket

A client needs one file. You send a presigned link with a 24-hour expiry; their browser pulls it straight from your bucket. No public access, no IAM user created, nothing routed through us.

Key featurePresigned share links

Your storage estate deserves a control plane.

Join the DevOps teams and founders who run every cloud's buckets from one control plane.

Free plan  ·  No credit card  ·  50+ cloud providers  ·  Cancel any time