FEATURES / Object Lock

/// Object Lock

Make objects truly immutable. Point-and-click WORM.

Apply Legal Hold, GOVERNANCE retention, and irreversible COMPLIANCE mode to your S3 objects from a visual UI. Lock backups against ransomware and hold records for as long as the rules require — on AWS S3, Backblaze B2, Wasabi, and MinIO.

Start for free

/// How it works

01

Create a bucket with Object Lock on

Object Lock has to be enabled when the bucket is created — it can't be turned on later. Storafleet sets the precondition for you at creation time on AWS S3, Backblaze B2, Wasabi, or MinIO. No aws s3api flags to remember.

02

Apply a hold or a retention period

Pick any object and toggle a Legal Hold, or set a Retention period in GOVERNANCE mode. Set a bucket default retention so every new upload is locked automatically. All from a visual panel — no CLI.

03

Escalate to COMPLIANCE when it must be permanent

When a record genuinely cannot be touched, switch its retention to COMPLIANCE mode. Storafleet requires a type-to-confirm step first, because once it's set, nobody — including the root account — can delete or shorten it until it expires.

Per-object Legal Hold, on or off

Toggle a Legal Hold on any object with one switch. While it's on, the object can't be deleted or overwritten — no matter what retention it has. Flip it off to release. Simple, immediate, and visible in the object view.

GOVERNANCE retention you can adjust

Set a retention period in GOVERNANCE mode and the object is protected until that date. It stays reversible: a privileged user can shorten or remove it, and you can always extend it. The right default for most teams.

Bucket default retention

Set a default retention period on the bucket and every new object is auto-locked the moment it's uploaded — no per-object step, nothing to forget. Configure it once from the bucket settings.

COMPLIANCE mode, truly irreversible

COMPLIANCE mode means the object cannot be deleted or its retention shortened by anyone — including the root user — until it expires. Storafleet gates it behind a type-to-confirm step so it's never set by accident.

WORM immutability without the CLI

Legal Hold, GOVERNANCE, COMPLIANCE, and bucket defaults are all exposed in one visual UI. No aws s3api put-object-retention, no put-object-legal-hold, no guessing which provider expects which flag.

See exactly what's locked

Every object shows its lock state at a glance — Legal Hold status, retention mode, and the date it unlocks. No more wondering whether protection is actually in place across AWS S3, Backblaze B2, Wasabi, or MinIO.

/// Without Storafleet

Object Lock is powerful but hidden behind aws s3api and a bucket precondition that's easy to miss. One wrong flag and your data is either unprotected or locked forever by mistake.

  • Object Lock must be enabled at bucket creation — forget it and you can't add it later
  • Setting retention means aws s3api put-object-retention with the exact mode and date format
  • Legal Hold is a separate put-object-legal-hold call most people never learn
  • COMPLIANCE mode is irreversible — setting it by accident locks the object until it expires, even for root
  • No single view of which objects are locked, in which mode, and until when

/// With Storafleet

A visual panel for every lock control. Enable Object Lock at creation, apply holds and retention per object or per bucket, and escalate to COMPLIANCE with a deliberate confirm step.

  • Storafleet sets the Object Lock precondition for you at bucket creation
  • GOVERNANCE retention set, extended, shortened, or removed from a visual panel
  • Legal Hold is a single toggle — on blocks deletion and overwrite, off releases it
  • COMPLIANCE mode is gated behind a type-to-confirm step so it's never set by accident
  • Every object shows its Legal Hold status, retention mode, and unlock date at a glance

/// When you'll use this

Platform Engineer01

Making backups ransomware-proof

Your nightly backups land in an S3 bucket. If ransomware or a leaked key reaches that bucket, plain objects get encrypted or deleted. You enable Object Lock at bucket creation and set a 30-day default retention in COMPLIANCE mode. Now every backup is immutable for 30 days — an attacker with full credentials still can't delete or overwrite a single object.

Key featureBucket default retention + COMPLIANCE mode

Compliance Lead02

Keeping financial records for the required term

Finance records have to be retained for years and provably not altered. You set a bucket default retention covering the mandated term, so every statement is locked on upload. For the records that must never be touched, you escalate to COMPLIANCE mode — the control regulators expect, enforced by the storage layer, not a policy doc.

Key featureBucket default retention with GOVERNANCE and COMPLIANCE

Legal Operations03

Placing a litigation hold on evidence

Litigation is incoming and a set of documents must be preserved exactly as they are, indefinitely, until counsel says otherwise. You toggle a Legal Hold on each object. Deletion and overwrite are blocked with no fixed expiry — the hold simply stays on until you remove it once the matter closes.

Key featurePer-object Legal Hold (on/off, no expiry)

Your storage estate deserves a control plane.

Join the DevOps teams and founders who run every cloud's buckets from one control plane.

Free plan  ·  No credit card  ·  50+ cloud providers  ·  Cancel any time