Contabo Object Storage vs STACKIT

Compare Contabo Object Storage and STACKIT on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: DigitalOcean

Logo: Contabo Object Storage

Contabo Object Storage

Germany· Cloud Computing

Needs review

Shortlist when you want a Ceph S3 bucket next to Contabo VPS or VDS, can use path-style endpoints, and can live without S3 logging. Skip when you need Amazon-complete S3, a first-party custom TLS hostname, company-wide ISO 27001 or SOC 2, or a store with no US parent and no US region. Consider Hetzner Object Storage or OVHcloud Object Storage instead.

S3-compatible (partial)Ceph backendEU region availableGerman GmbHIn-panel DPA
Logo: STACKIT

STACKIT

Germany· Cloud Computing

Needs review

Shortlist STACKIT when you want German-entity IaaS/PaaS on Schwarz Group–owned DE/AT infrastructure with managed Kubernetes, scoped BSI C5 Type 2 claims, and optional same-campus colocation. Skip when you need global multi-region hyperscaler breadth or a fully self-hosted control plane—consider OVHcloud or Scaleway for multi-country EU clouds, or AWS/Azure when worldwide services dominate the architecture.

EU-operatedGerman legal entityGroup-owned DE/AT DCsBSI C5 Type 2 (claimed)Managed Kubernetes (SKE)EU colocation + hybrid
Contabo Object Storage vs STACKIT: Snapshot
FeatureLogo: Contabo Object StorageContabo Object StorageLogo: STACKITSTACKIT
Country of originGermanyGermany
CategoryCloud ComputingCloud Computing
Open sourceNoNo
Self-hostedNoNo
HeadquartersGermanyGermany
Legal entityContabo GmbH (Welfenstrasse 22, 81541 Munich; AG Munich HRB 180722; VAT DE267602842)Schwarz Digits Cloud GmbH & Co. KG (Am Campus 1, 74177 Bad Friedrichshall; imprint lists STACKIT Beteiligungs-GmbH as general partner vehicle in Neckarsulm)
Governing lawNot listedGermany (imprint also notes ICT infrastructure jurisdiction Germany and Austria)
US parent / controlUS parent or controlNo known US parent
CLOUD Act exposure (indicative)HighLow
Hosting / residencyObject storage sold in the EU (eu2.contabostorage.com), United States (usc1.contabostorage.com), and Singapore (sin1.contabostorage.com). Contabo operates its own data centers. No public object-storage subprocessor list. Management API auth is at auth.contabo.com. Official custom-domain docs use Cloudflare as an optional customer-side proxy, not as the S3 data plane.Vendor claims STACKIT Cloud runs in group-owned ISO 27001 data centers in Germany and Austria (sites publicly named include Neckarsulm DC01, Ellhofen DC08, Ostermiething DC10; additional EU sites claimed). Cloud regions include EU01 (Germany) and EU02 (Austria). No public evidence found that customer data-plane hosting is on AWS/GCP/Azure. A detailed third-party subprocessor list for all support/analytics tooling was not found on marketing pages—confirm in the AVV.
Summary

S3-compatible object storage from Munich-based Contabo GmbH, running on Ceph with EU, US, and Singapore endpoints.

German sovereign cloud from Schwarz Digits (Schwarz Group): IaaS, managed Kubernetes, databases, and colocation on group-owned data centers in Germany and Austria.

Tags
At a glance: Contabo Object Storage vs STACKIT
At a glanceLogo: Contabo Object StorageContabo Object StorageLogo: STACKITSTACKIT
HQMunich, Germany (Contabo GmbH, HRB 180722)Not listed
ProductHosted Ceph S3 object storageNot listed
S3 regionsEU (eu2), United States (usc1), Singapore (sin1)Not listed
AddressingPath-style; HTTPS onlyNot listed
Commercial modelPurchased capacity with optional auto-scale; no per-GB egress on Contabo's stated modelNot listed
OwnershipKKR majority (2022), Oakley Capital Fund V minorityNot listed
HQ / legal entityNot listedBad Friedrichshall / Neckarsulm area, Germany — Schwarz Digits Cloud GmbH & Co. KG
ParentNot listedSchwarz Digits (Schwarz Group — Lidl/Kaufland)
HostingNot listedGroup-owned data centers in Germany & Austria (e.g. EU01/EU02); not marketed as AWS/Azure reseller
ModelNot listedConsumption-based public cloud + quote-based colocation
Open sourceNot listedUses open-source components; platform itself is managed, not self-hosted
External marketNot listedPublic offering from 2022 (internal roots from 2018)
Key capabilities: Contabo Object Storage vs STACKIT
Key capabilitiesLogo: Contabo Object StorageContabo Object StorageLogo: STACKITSTACKIT
S3-compatible (partial)YesNot listed
Ceph backendYesNot listed
EU region availableYesNot listed
German GmbHYesNot listed
In-panel DPAYesNot listed
EU-operatedNot listedYes
German legal entityNot listedYes
Group-owned DE/AT DCsNot listedYes
BSI C5 Type 2 (claimed)Not listedYes
Managed Kubernetes (SKE)Not listedYes
EU colocation + hybridNot listedYes

Contabo Object Storage

  • Ceph S3 API with path-style buckets

    Contabo states the store is Ceph-based and largely S3 compatible, not fully equivalent to Amazon S3. Logging is not supported. Official tool notes require Contabo S3 URLs, path-style buckets, and access_key/secret_key mapped to aws_access_key_id/aws_secret_access_key.

  • EU, US, and Singapore S3 endpoints

    Documented base URLs are eu2.contabostorage.com (European Union), usc1.contabostorage.com (United States), and sin1.contabostorage.com (Singapore). The management API allows one object-storage purchase per location. All locations on an account share the same S3 credentials.

  • Bucket versioning and Object Lock

    Versioning is enabled per bucket via s3api put-bucket-versioning on the regional endpoint. Suspending versioning stops new versions but does not delete old ones. Object Lock can be turned on at bucket creation (example uses GOVERNANCE mode) so objects cannot be overwritten or deleted for a retention period.

  • Capacity auto-scale via management API

    The Contabo API (not the S3 API) orders, upgrades, cancels, and auto-scales purchased space up to a monthly size limit. Usage statistics are exposed there. The open-source cntb CLI (GPL-3.0) wraps the same management API. S3 keys come from the User Management API or the Object Storage panel.

  • Published client list and hard limits

    Documented working tools include cntb, aws cli, rclone, Cyberduck, goofys, s3fs-fuse, s3cmd, WinSCP, Cloudberry Explorer, BucketAnywhere, Virtualmin, Velero, and Plesk. FileZilla Pro is listed as incompatible. Defaults include 5 TB max object size, 100 buckets, 3 million objects (increasable on request), 250 requests per second, and 10 MByte/s default bandwidth.

STACKIT

  • Compute Engine VMs and GPUs in group-owned EU regions

    Provision Linux and Windows virtual machines, GPU-backed instances, automated server backup and OS update management from the STACKIT portal, CLI, API, or Terraform. Workloads land in European cloud regions such as EU01 (Germany) and EU02 (Austria) on Schwarz Group–operated infrastructure rather than rented hyperscaler bare metal. Best for teams that need predictable EU residency for general compute and AI/ML training or inference on GPU shapes—confirm available instance families per region before migration.

  • STACKIT Kubernetes Engine (SKE)

    Managed, CNCF-compliant Kubernetes with a highly available control plane, automated Kubernetes/OS upgrades, repair functions, pod and node autoscaling, optional temporary cluster shutdown, and automation via Terraform, SKE API, and CLI. Suited to cloud-native apps, stateful workloads on block storage, and ML pipelines that must stay in European regions. Not a self-hosted kubeadm replacement—you consume a managed service with STACKIT-controlled plane components.

  • Managed databases, messaging, and observability

    Fully managed PostgreSQL Flex, MongoDB Flex, SQL Server Flex, MariaDB, Redis, OpenSearch, and RabbitMQ plus LogMe, Logs, and Observability stacks reduce ops load for application teams. Flex models emphasize automated maintenance, backups, and scaling inside the STACKIT cloud. Ideal when you want PaaS data services under the same German operator as your VMs/K8s—validate HA topology, backup retention, and region pairing for each service.

  • Confidential computing and key/secrets control

    Confidential Server and Confidential Kubernetes options aim to protect data in use with hardware-backed isolation; Secrets Manager and Key Management Service handle secret storage/rotation and cryptographic operations. Useful for regulated or multi-tenant sensitive workloads beyond disk encryption alone. Confirm attestation models, supported node types, and which compliance reports cover these products.

  • EU colocation with hybrid path to public cloud

    Racks, cages, and private rooms in Neckarsulm, Ellhofen, and Ostermiething facilities—with remote hands, carrier connectivity, and hybrid designs that keep non-migratable hardware next to STACKIT public cloud. Positions STACKIT for gradual cloud adoption without a pure forklift. Colocation is quote-driven and site certifications can vary by facility; request site data sheets early.

  • Object, block, file, backup, and archiving storage

    S3-compatible object storage, high-performance block volumes, NFS file storage, backup storage, and audit-oriented archiving for retention workloads. Supports application data, VM disks, and compliance archives inside the same European footprint as compute. Check durability/replication claims and cross-region options against your RPO/RTO rather than assuming hyperscaler multi-region defaults.

Assurance & compliance: Contabo Object Storage vs STACKIT
Assurance & complianceLogo: Contabo Object StorageContabo Object StorageLogo: STACKITSTACKIT
Independent security / no-logs audit
Not found

Searched About, help, and product docs. No public independent audit PDF for Object Storage.

Vendor claimed

Vendor claims BSI C5 Type 2 for a listed IaaS/storage product set; reports available on request (iso@digits.schwarz). Not a VPN-style no-logs audit.

ISO 27001
Partial

Some Contabo location marketing pages list colocation-facility ISO 27001 (for example Singapore). No company-wide Contabo ISO 27001 certificate found.

Vendor claimed

Certificates page claims ISO/IEC 27001 ISMS (with downloadable cert links) plus ISO 27017 and ISO 27018; also ISO 27001 based on IT baseline protection for named IaaS components.

SOC 2 / SOC 3
Not found

No Contabo-issued SOC 2 or SOC 3 report found. Facility-level SOC marks on some non-EU location pages are not treated as a Contabo attestation.

Vendor claimed

Vendor states ISAE 3000 (SOC 2) and ISAE 3402 in addition to C5 Type 2; obtain current reports under NDA/request.

GDPR / EU data protection
Vendor claimed

EU legal entity; DPA available in the Customer Control Panel and listed as covering Object Storage. EU region is optional, not exclusive.

Vendor claimed

EU legal entity; vendor claims GDPR-aligned operation with processing in own DE/AT data centers and ISO 27018 claims for PII in the cloud.

US CLOUD Act exposure (indicative)
Partial

Contabo GmbH is German, but KKR (US) has been the majority investor since June 2022 and Contabo sells a US object-storage region. Not legal advice.

Partial

German operator under Schwarz Digits / Schwarz Group; no known US parent; customer cloud claimed on group-owned EU DCs without named AWS/GCP/Azure data-plane hosts. Partial (not a clean bill): confirm AVV subprocessors and any non-EU support tools. Indicative only—not legal advice.

Data processing agreement (B2B)
Vendor claimed

Customer Control Panel wizard. Object Storage is an explicit covered service. Review the generated PDF.

Not found

No self-serve public AVV/DPA URL confirmed during research; expect contract packaging—request AVV, TOMs, and subprocessor list in procurement.

EU AI Act
Not applicable

Object storage IaaS, not an AI system.

Not applicable

Primary offering is IaaS/PaaS infrastructure; optional AI Model Serving and related data/AI products may need separate AI Act analysis if you deploy high-risk AI systems.

BSI C5 Type 2Not listed
Vendor claimed

C5 Type 2 claimed for Compute Engine (incl. GPU), Windows/RHEL, server backup/update management, block/object/backup/file storage, archiving—not automatically every PaaS product.

TISAX Level 3Not listed
Vendor claimed

Vendor claims TISAX Level 3; verification via ENX portal (assessment ID ATA163-1 / scope ID SH938N per certificates page).

Considerations & known limitations: Contabo Object Storage vs STACKIT
Considerations & known limitationsLogo: Contabo Object StorageContabo Object StorageLogo: STACKITSTACKIT
US private-equity majority owner
High

Oakley Capital announced in June 2022 that KKR would be majority investor, with Oakley Fund V retaining a minority stake. Treat CLOUD Act exposure as high at the ownership layer even when objects sit on eu2.contabostorage.com.

Not listed
Optional United States object region
Medium

usc1.contabostorage.com is a first-party SKU. Shared credentials across locations make it easy to point a client at the US endpoint by mistake. Pin the EU URL if residency is a hard requirement.

Not listed
Partial S3 compatibility
Medium

Contabo states the Ceph API is not fully compatible with AWS S3. Logging is unsupported. Path-style addressing is required. FileZilla Pro does not work. Test SDK features before migrating production.

Not listed
Default request and bandwidth caps
Medium

Published defaults include 250 API requests per second, 10 MByte/s bandwidth, 100 buckets, and 3 million objects. Auto-scale increases purchased terabytes, not those caps.

Not listed
No public company-wide audit
Medium

No independent Object Storage audit, Contabo-issued ISO 27001, or SOC 2 report was found. Facility ISO/SOC marks on some location pages are not a substitute.

Not listed
No first-party custom TLS hostname
Low

HTTPS-only S3 endpoints reject a simple CNAME. Public websites need a customer-operated reverse proxy. Public-to-private ACL changes may remain cached for up to one hour.

Not listed
Narrower service map than US hyperscalersNot listed
Medium

STACKIT covers core compute, K8s, databases, and storage, but global specialty services and third-party marketplace depth lag AWS/Azure/GCP. Practical impact: multi-cloud or lift-and-shift of complex hyperscaler architectures may need redesign.

C5 Type 2 is product-scopedNot listed
Medium

Attestation tables list specific IaaS/storage products. Teams assuming every managed database or PaaS SKU is C5 Type 2 covered without reading the scope can mis-state compliance. Practical impact: map each in-scope service before audits.

Limited public subprocessor inventoryNot listed
Low

Marketing asserts own data centers and EU processing; a complete public subprocessor/support-tool list was not found on the pages reviewed. Practical impact: force AVV + subprocessor exhibits before production personal data.

Retail-group operator concentrationNot listed
Low

Economic stability is a stated strength of Schwarz Group ownership, but roadmap and commercial leverage differ from pure-play clouds. Practical impact: negotiate exit, data export, and roadmap commitments explicitly.

Fit

Contabo Object Storage

Best fit when

  • Teams already on Contabo Cloud VPS or VDS that need a same-account backup or media bucket
  • Workloads that speak standard S3 via rclone, aws cli, Velero, Plesk, or s3cmd and can use path-style URLs
  • Buyers who want capacity-tier billing without per-gigabyte egress modelling
  • Operators who can pin eu2.contabostorage.com and sign the in-panel DPA
  • Buckets that need versioning or Object Lock but not S3 server access logging

Poor fit when

  • Applications that require full Amazon S3 feature parity, especially server access logging or virtual-hosted bucket names
  • Public websites that need a first-party custom hostname and TLS without a reverse proxy
  • Procurement that requires company-wide ISO 27001 or SOC 2, or a vendor with no US private-equity majority owner
  • Strict EU-only policies if anyone on the account might create a US or Singapore store
  • High-QPS or multi-gigabit pipelines that will hit the documented 250 rps or 10 MByte/s defaults

Consider instead when

  • When: You want a German hoster's object store with an EU-concentrated footprint and no US majority PE owner

    Consider: Hetzner Object Storage

    Contabo's own comparison places Hetzner object storage in European data centers and notes a thinner APAC story.

  • When: You need a broader EU compliance portfolio (ISO 27001, SecNumCloud) more than a simple capacity bill

    Consider: OVHcloud Object Storage

    Billing and product surface are more complex than Contabo's single-account IaaS stack.

  • When: You need managed Kubernetes or managed Postgres next to S3, not just raw buckets

    Consider: Scaleway Object Storage

    France-first footprint. Contabo does not sell first-party managed databases or Kubernetes.

  • When: You need Amazon-complete S3 (logging, IAM, global regions) and will accept a US cloud

    Consider: Amazon S3

    Use Contabo only after you have tested the Ceph compatibility gaps against your SDK.

STACKIT

Best fit when

  • Public-sector, healthcare, finance, or retail teams that require EU residency under a German operator with dual DE/AT regions
  • Platform teams standardizing on managed Kubernetes (SKE) plus VMs and managed databases in one European cloud
  • Organizations migrating gradually via colocation racks/cages in STACKIT facilities next to public cloud projects
  • Buyers that prioritize BSI C5 Type 2 and ISO 27001 family claims on core compute/storage over hyperscaler marketplace depth
  • Workloads that benefit from GPU compute, confidential computing options, or AI model serving inside the same sovereign stack

Poor fit when

  • Architectures that depend on many specialized AWS/Azure/GCP managed services or global multi-continent regions
  • Teams that must self-host the full cloud control plane rather than consume a managed public cloud
  • Simple single-VM or low-ops hobby hosting where a basic VPS provider is enough
  • Procurement that needs every PaaS product under the same C5 Type 2 table without reviewing scope gaps
  • Use cases requiring non-European data residency as a primary requirement

Consider instead when

  • When: You need a wider multi-country European region map and a large independent cloud portfolio

    Consider: OVHcloud or Scaleway

    Different ownership and product cultures; still not US hyperscaler breadth

  • When: Your workload is mainly simple German VMs/web hosting without managed K8s/PaaS depth

    Consider: IONOS (or similar DE hosts)

    Often simpler packaging for commodity compute

  • When: You require global regions, the largest third-party marketplace, or existing multi-cloud tooling locked to hyperscaler APIs

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Trade EU ownership of the operator for ecosystem scale; apply your own CLOUD Act / transfer analysis

  • When: Swiss or other non-DE sovereignty framing matters more than Schwarz Group scale

    Consider: Exoscale

    Smaller portfolio; different jurisdiction story

Open questions for due diligence

Contabo Object Storage

  • Is there a current company-wide ISO 27001 or SOC 2 for Contabo GmbH (not a colocation-facility mark)?
  • Where is the public subprocessor list for Object Storage, backups, support tooling, and the Customer Control Panel?
  • Does Contabo offer server-side encryption at rest and customer-managed keys for objects? Not documented on the pages reviewed.
  • What is the Ceph replication factor / durability target for each object-storage region?
  • The marketing URL https://contabo.com/en/object-storage/ returned Storage VPS content when fetched during research. Confirm the SKU is still sold and the product page has not been retired.

STACKIT

  • Will STACKIT provide a signed AVV/DPA, current TOMs, and a full subprocessor list covering support, monitoring, and marketplace components?
  • Which of our target services (SKE, PostgreSQL Flex, Confidential Kubernetes, etc.) fall inside the latest C5 Type 2 and ISO reports?
  • What are the exact region availability, geo-redundancy options, and SLA credits for our workloads across EU01/EU02 (and any additional regions)?
  • What are exit, data export, and termination assistance terms for large object stores and managed databases?
  • For public-sector or KRITIS use cases: which additional attestations, clearance processes, or reference architectures are required?