Cyso Cloud vs Leafcloud Object Storage

Vergleichen Sie Cyso Cloud und Leafcloud Object Storage nach Funktionen, Rechtsraum, Nachweisen und Einsatzpassung.

Logo: Leafcloud Object Storage

Leafcloud Object Storage

Netherlands· Cloud Computing

Needs review

Shortlist Leafcloud Object Storage when you want an S3-compatible Ceph bucket in Amsterdam under Leafcloud B.V., with a public ISO 27001 certificate and a downloadable DPA. Skip when you need object versioning, multi-region replication, or AWS-parity S3 features. Consider Cyso Cloud for Dutch OpenStack storage with versioning and a Frankfurt option, or OVHcloud / Scaleway for a wider EU region map.

S3-compatible (leafcloud.store)Amsterdam residencyCeph 3x replicationISO 27001 (public cert)Public DPANo object versioning
Cyso Cloud vs Leafcloud Object Storage: Überblick
MerkmalLogo: Cyso CloudCyso CloudLogo: Leafcloud Object StorageLeafcloud Object Storage
HerkunftslandNetherlandsNetherlands
KategorieCloud ComputingCloud Computing
Open SourceJaNein
Self-HostedNeinNein
HauptsitzNicht angegebenNetherlands
RechtsträgerNicht angegebenLeafcloud B.V., Amsterdam (KvK 78564417). Site: Science Park 400. DPA/ISO: Overhoeksplein 2.
US-Mutter / KontrolleNicht angegebenKeine bekannte US-Mutter
CLOUD-Act-Exposition (indikativ)Nicht angegebenNiedrig
Hosting / ResidenzNicht angegebenObjects at Amsterdam Core (europe-nl-ams1), Ceph 3x. DPA (Jan 2026): no subprocessors for core compute/storage/networking; no third-country transfers unless customer-instructed. Terms mention EU partner data centres; Core operator unnamed. Privacy allows unnamed account-data suppliers (invoicing, messaging). Site analytics: self-hosted Matomo. Not AWS/GCP/Azure-hosted.
Zusammenfassung

Dutch OpenStack IaaS from Cyso B.V. with AMS/FRA regions, managed Kubernetes (KCSP), S3-compatible object storage, and EU data residency for teams avoiding hyperscaler lock-in.

Dutch S3-compatible object storage from Leafcloud B.V. Ceph-backed buckets in Amsterdam via leafcloud.store, plus OpenStack Swift, for backups, app data, and public objects.

Tags
Auf einen Blick: Cyso Cloud vs Leafcloud Object Storage
Auf einen BlickLogo: Cyso CloudCyso CloudLogo: Leafcloud Object StorageLeafcloud Object Storage
Legal entityNicht angegebenLeafcloud B.V., Amsterdam; KvK 78564417
S3 endpointNicht angegebenhttps://leafcloud.store (region europe-nl-ams1, path-style)
BackendNicht angegebenCeph; also OpenStack Swift / Horizon
ResidencyNicht angegebenAmsterdam Core, Netherlands (single region)
Commercial modelNicht angegebenPay for stored capacity; B2B invoicing; vendor states no API request fees
Hard limitNicht angegebenNo object versioning; max object 5 TB
Key capabilities: Cyso Cloud vs Leafcloud Object Storage
Key capabilitiesLogo: Cyso CloudCyso CloudLogo: Leafcloud Object StorageLeafcloud Object Storage
S3-compatible (leafcloud.store)Nicht angegebenJa
Amsterdam residencyNicht angegebenJa
Ceph 3x replicationNicht angegebenJa
ISO 27001 (public cert)Nicht angegebenJa
Public DPANicht angegebenJa
No object versioningNicht angegebenJa

Cyso Cloud

  • Skalierbare Compute-Instanzen

    Instanzen in Sekunden mit Flavors für Workloads: Standard (balanced), CPU-optimiert (bis 64 vCPUs), Memory-optimiert (bis 512 GB RAM). Ephemeral Storage an Instanz-Lebenszyklus gebunden; persistente Volumes mit Dreifach-Replikation und IOPS-Skalierung (5–25 pro GB). Stundensätze ab 0,026 € für Einstieg – präzise Kosten ohne Überprovisionierung.

  • S3-kompatibler Object Storage

    Für Backups und große Datensätze: unbegrenzte Kapazität, 99,99 % Uptime-SLA. NVMe-Laufwerke für niedrige Latenz; Daten in gewählten EU-Regionen. Preise: 0,055 €/GB Storage, gratis Ingress, 0,055 €/GB Egress. Operationen 0,055 € pro 10.000 PUT/LIST-Requests, REST-API-Zugang.

  • Managed Kubernetes

    Enterprise Managed Kubernetes (EMK): Control Plane 29,99 €/Monat (HA 59,99 €), automatische Updates und Hibernation für Kosteneinsparung. 99,9 % SLA für HA-Cluster. Deployment via Dashboard; Autoscaling für variable Lasten. Setup in Minuten laut Dokumentation.

Leafcloud Object Storage

  • S3 API at leafcloud.store (europe-nl-ams1)

    Path-style S3 endpoint https://leafcloud.store, region europe-nl-ams1. Works with AWS CLI, boto3, rclone, Cyberduck, MinIO mc, and other S3 SDKs. Documented features include public or private containers, bucket policies and ACLs, multipart uploads, and presigned URLs. Max object size is 5 TB via multipart. Authentication uses OpenStack EC2 credentials (openstack ec2 credentials create), not the dashboard password.

  • OpenStack Swift and Horizon dashboard

    The same store is reachable as OpenStack object storage (Swift). Create and browse containers at create.leaf.cloud under Object Store. Native CLI uses project-scoped OpenStack auth (openstack container create / object create). Container names must be unique across all Leafcloud users. Docs say there is a limit on how many containers you can create (the exact quota is not published).

  • Ceph cluster with 3x replication in Amsterdam

    The product page describes a Ceph backend (Apache 2.0 software) with triple replication across separate physical nodes in Amsterdam. Persistent objects sit at the Core facility. Compute Leaf sites are a different path and are not where object data is stored, according to the security pages. This is a single-region store, not a multi-region S3 deployment.

  • SSE-C plus TLS in transit

    Official docs show S3 server-side encryption with customer-provided keys (SSE-C, AES256). Leafcloud uses the key on each request and does not store it. Lose the key and you cannot read the object. The product table also lists encryption at rest and TLS in transit as supported. DPA language is TLS 1.2+. LUKS-by-default messaging on the security pages refers to block volumes, not this object API.

  • Terraform state, Velero, and Nextcloud recipes

    Leafcloud publishes working recipes for Terraform’s S3 backend (path-style, skip checksum/region checks, endpoint leafcloud.store), Velero Kubernetes backups (s3ForcePathStyle plus s3Url), and Nextcloud primary objectstore pointing at leafcloud.store:443. Useful if you already run those tools. Object versioning is not available, so state and backup designs must version keys themselves or copy out.

Assurance & compliance: Cyso Cloud vs Leafcloud Object Storage
Assurance & complianceLogo: Cyso CloudCyso CloudLogo: Leafcloud Object StorageLeafcloud Object Storage
Independent security / no-logs auditNicht angegeben
Not found

No public independent no-logs or object-store-specific audit PDF found. SOC 2 Type II is a separate row and is under NDA.

ISO 27001Nicht angegeben
Verified

Public ProCertify certificate 10112025.1 for LeafCloud B.V.: ISO/IEC 27001:2022 + Amd1:2024. Scope: information security for cloud services, infrastructure, and supporting processes. Valid 10 Nov 2025 to 10 Nov 2028. SoA v3.1 dated 5 Aug 2025. Read from the vendor-hosted PDF; not re-checked on an external accreditation database.

SOC 2 / SOC 3Nicht angegeben
On request / NDA

Vendor and DPA claim SOC 2 Type II (security, availability, confidentiality). Compliance page: request access by email. Report not reviewed for this draft.

GDPR / EU data protectionNicht angegeben
Vendor claimed

Dutch B.V.; public DPA under Dutch law; vendor states Amsterdam-only processing and no third-country transfers unless instructed. Confirm roles (controller/processor) for your workload.

US CLOUD Act exposure (indicative)Nicht angegeben
Partial

EuropeanStack assessment: EU entity, no known US parent, DPA says no core subprocessors and NL-only processing. Partial because ownership was not independently verified and terms/privacy still allow partner data centres plus unnamed account-data suppliers. Not legal advice.

Data processing agreement (B2B)Nicht angegeben
Vendor claimed

Standard DPA dated January 2026 is public and states it applies automatically (no signature). Custom DPA on request. Governing law: Netherlands; courts of Amsterdam.

HAVEN+ (Dutch public sector)Nicht angegeben
Not found

Security FAQ: HAVEN+ certification is in progress, not achieved. Do not treat as certified.

EU AI ActNicht angegeben
Not applicable

Object storage / IaaS SKU, not an AI system product.

Considerations & known limitations: Cyso Cloud vs Leafcloud Object Storage
Considerations & known limitationsLogo: Cyso CloudCyso CloudLogo: Leafcloud Object StorageLeafcloud Object Storage
Object versioning disabledNicht angegeben
High

The product table states versioning is not enabled. Overwrites and deletes are not recoverable via S3 versions. Unsafe as a sole Terraform-state or backup target unless you version keys yourself or replicate out.

Amsterdam-only regionNicht angegeben
Medium

One S3 region (europe-nl-ams1). No documented cross-region replication. Multi-country DR or non-NL residency needs another provider.

Baseline SLA is a non-binding targetNicht angegeben
Medium

Terms target more than 99.9% monthly availability without credits on the baseline SLA. Customers must keep their own backups. Premium SLA only if agreed in writing.

Core facility operator not namedNicht angegeben
Medium

DPA says no core subprocessors. Terms mention partner data centres. Public pages do not name the Tier III Core operator. Request that name in contracting.

Incomplete S3 feature parityNicht angegeben
Low

Custom domains are support-gated. Static hosting is basic. Do not assume lifecycle, object lock, or inventory APIs without a proof of concept.

Passung

Cyso Cloud

Best fit when

Nicht angegeben

Poor fit when

Nicht angegeben

Leafcloud Object Storage

Best fit when

  • Teams that need an S3-compatible endpoint and OpenStack Swift in one Dutch account
  • Amsterdam-only residency designs that can live without bucket versioning
  • Velero, Terraform state, or Nextcloud setups that already use path-style S3 clients
  • Buyers who want a public ISO 27001 PDF and a standard DPA before a sales call
  • Organisations that may later add Leafcloud VMs or GPUs in the same jurisdiction

Poor fit when

  • Workloads that require S3 versioning, object lock, or cross-region replication
  • Multi-region or in-country-outside-NL residency (this store is Amsterdam only)
  • Procurement that needs a named Core colocation operator and a full ancillary subprocessor register on day one
  • Consumer or free-tier only use (terms position Leafcloud as B2B)
  • Designs that assume AWS IAM, KMS, or inventory/analytics feature parity

Consider instead when

  • When: You need Dutch or German OpenStack object storage with versioning and more than one EU region

    Consider: Cyso Cloud

    Cyso documents AMS and FRA and lists versioning, lifecycle, and object lock on object storage.

  • When: You need many European locations and a larger IaaS catalogue than a single Amsterdam Ceph cluster

    Consider: OVHcloud or Scaleway

    Broader region maps; different APIs, SLAs, and ownership stories.

  • When: German locations and a large self-serve European hosting catalogue matter more than OpenStack Swift

    Consider: Hetzner

    Compare object storage vs Storage Box features and residency independently.

  • When: Swiss multi-zone IaaS with S3-compatible storage is the sovereignty filter

    Consider: Exoscale

    Different legal seat (Switzerland) and product mix.

  • When: You depend on versioning, replication, IAM, and KMS that only the hyperscaler S3 estate provides

    Consider: Amazon S3 (or Google Cloud Storage)

    Trade EU ownership for feature depth. Apply your own CLOUD Act analysis.

Open questions for due diligence

Cyso Cloud

Nicht angegeben

Leafcloud Object Storage

  • What is the current registered office on the KvK extract (Science Park 400 vs Overhoeksplein 2)?
  • Who operates the Amsterdam Core / partner data centre, and is that party listed as a subprocessor for physical hosting?
  • Can Leafcloud provide a dated list of ancillary processors (billing, support, email) used for account data?
  • Is there a committed date or paid option to enable Ceph/S3 versioning?
  • What contractual availability, durability, and deletion timelines apply to object storage under a Premium SLA versus the baseline terms (14-day vs 90-day deletion language differs between T&Cs and DPA)?