Cyso Cloud vs Hetzner Object Storage

Compare Cyso Cloud and Hetzner Object Storage on capabilities, jurisdiction, assurance, and fit for European buyers.

Logo: Cyso Cloud

Cyso Cloud

Netherlands· Cloud Computing

Needs review

Shortlist Cyso Cloud when you want Dutch-operated OpenStack IaaS and KCSP managed Kubernetes with AMS/FRA residency and engineer-to-engineer support. Skip when you need global hyperscaler regions or default encryption-at-rest object storage—consider OVHcloud or Scaleway for broader European multi-region IaaS, or keep a hyperscaler for worldwide PaaS depth.

EU-operated (NL)OpenStack IaaSManaged Kubernetes (KCSP)AMS + FRA regionsISO 27001 (claimed)NEN 7510 (claimed)
Logo: Hetzner Object Storage

Hetzner Object Storage

Germany· Cloud Computing

Needs review

Shortlist when you want S3-compatible buckets in Falkenstein, Nuremberg, or Helsinki under Hetzner Online GmbH, especially if you already run Hetzner compute. Skip when you need AWS-parity features, flash tiers, a CDN, or default KMS at-rest encryption. Prefer Amazon S3 for full feature depth; prefer Scaleway or OVHcloud if you want another European S3 SKU without a Hetzner compute relationship.

S3-compatible APIEU-only locationsSingle-DC residencyObject lock + versioningSSE-C (opt-in)ISO 27001 (company)
Cyso Cloud vs Hetzner Object Storage: Snapshot
FeatureLogo: Cyso CloudCyso CloudLogo: Hetzner Object StorageHetzner Object Storage
Country of originNetherlandsGermany
CategoryCloud ComputingCloud Computing
Open sourceYesNo
Self-hostedNoNo
HeadquartersNetherlandsGermany
Legal entityCyso B.V. (part of Cyso Group B.V.), Wognumsebuurt 3, 1817 BH Alkmaar; KVK 37133395Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen (HRB 6089 Ansbach)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencyPrimary public IaaS on Cyso-operated hardware in Tier 3 facilities in Amsterdam and Frankfurt (3 AZs per region); vendor states storage replicas/backups stay in the selected EU region. Not marketed as AWS/Azure/GCP-hosted IaaS. Ancillary tools disclosed at group level include website analytics (PostHog) and third parties for payments/support; status tooling has referenced Atlassian Statuspage. Full public customer-workload subprocessor list not found.Object Storage only in Falkenstein, Nuremberg (company-operated DE parks) and Helsinki (Hetzner Finland Oy for building rental and technical support). Entire bucket stays in the selected single data center on Hetzner Ceph. No US or Singapore object-storage region. Group still has Hetzner US LLC, Hetzner Singapore Pte. Ltd., and US/SG colocation partners for other Cloud server products. Customer master data stays in the EU per Hetzner docs.
Summary

Dutch OpenStack IaaS from Cyso B.V. with AMS/FRA regions, managed Kubernetes (KCSP), S3-compatible object storage, and EU data residency for teams avoiding hyperscaler lock-in.

German S3-compatible object storage from Hetzner Online GmbH: buckets in Falkenstein, Nuremberg, and Helsinki with location-specific endpoints.

Tags
At a glance: Cyso Cloud vs Hetzner Object Storage
At a glanceLogo: Cyso CloudCyso CloudLogo: Hetzner Object StorageHetzner Object Storage
HQAlkmaar, NetherlandsGunzenhausen, Germany
Legal entityCyso B.V. (Cyso Group)Hetzner Online GmbH (HRB 6089 Ansbach)
Founded1997 (group); public OpenStack cloud since 2016 (Fuga); Cyso Cloud brand 2025Not listed
RegionsAmsterdam, Frankfurt (more under investigation)Not listed
StackOpenStack + managed Kubernetes (KCSP)Not listed
Commercial modelPay-as-you-go / hourly; optional trial via salesHourly base fee with included storage and egress quota, then pay-as-you-go
LocationsNot listedFSN1 Falkenstein, NBG1 Nuremberg, HEL1 Helsinki
APINot listedS3-compatible, AWS Signature Version 4
Storage backendNot listedCeph on HDD (standard tier only)
EncryptionNot listedNo default at-rest; optional SSE-C
Key capabilities: Cyso Cloud vs Hetzner Object Storage
Key capabilitiesLogo: Cyso CloudCyso CloudLogo: Hetzner Object StorageHetzner Object Storage
EU-operated (NL)YesNot listed
OpenStack IaaSYesNot listed
Managed Kubernetes (KCSP)YesNot listed
AMS + FRA regionsYesNot listed
ISO 27001 (claimed)YesYes
NEN 7510 (claimed)YesNot listed
S3-compatible APINot listedYes
EU-only locationsNot listedYes
Single-DC residencyNot listedYes
Object lock + versioningNot listedYes
SSE-C (opt-in)Not listedYes

Cyso Cloud

  • OpenStack public IaaS on EU hardware

    Vanilla OpenStack compute (roughly 2–64 vCPUs and up to 512 GB RAM flavors), NVMe-backed ephemeral and block volumes, dashboard plus OpenStack APIs/CLI. Deployed on Cyso-managed hardware in Amsterdam and Frankfurt with three availability zones per region so multi-AZ designs are first-class.

  • S3-compatible NVMe object storage

    Region-scoped object storage with triple-disk redundancy, versioning, lifecycle rules, object lock, pre-signed URLs, and standard S3 clients (AWS CLI, Rclone, MinIO mc, SDKs). Data and replicas stay in the selected AMS or FRA region; default server-side encryption at rest is not applied—plan client-side or customer-key approaches for sensitive objects.

  • Enterprise Managed Kubernetes (KCSP)

    CNCF Kubernetes Certified Service Provider managed control planes with multi-version support, automated upgrades, worker groups (including GPU/high-memory options), HPA/VPA/node autoscaling, Garden Linux workers, Terraform/kubectl/k9s workflows, and cluster hibernation to scale workers to zero on a schedule.

  • European networking and multi-AZ design

    VPC-style private networks, security groups as virtual firewalls, load balancers with health checks, floating/reserved IPs, Anycast DNS, IPv6 dual-stack, native edge DDoS mitigation, and Direct Connect-style private links. SLA text targets 99.99% monthly uptime for listed compute, volume, object, and networking services when multi-AZ conditions are met.

  • Private cloud and wholesale options

    Same OpenStack-based stack can be deployed as a private cloud on customer data-centre hardware (including VMware-alternative messaging) or white-label/wholesale models for partners—useful when public multi-tenant regions are not enough for isolation or residency policy.

Hetzner Object Storage

  • S3 API with FSN1, NBG1, and HEL1 endpoints

    Amazon S3 compatible API using AWS Signature Version 4. Location endpoints are fsn1.your-objectstorage.com, nbg1.your-objectstorage.com, and hel1.your-objectstorage.com. AWS CLI and common SDKs work when pointed at the Hetzner endpoint. Console covers bucket create and credentials; almost all object operations go through the S3 API.

  • Single-location EU bucket residency on Ceph

    A bucket is stored entirely in the location you pick (Falkenstein, Nuremberg, or Helsinki), in one data center. Docs describe a Ceph cluster with erasure coding that can keep data intact if up to three storage servers fail. There is no US or Singapore object-storage region and no built-in cross-location replication.

  • Object lock, versioning, and lifecycle expiry

    Object Lock can be enabled at bucket create (legal hold and retention). Versioning and lifecycle rules are documented, including NoncurrentDays expiry. Pre-signed URLs give time-limited access. Object lock cannot be turned on later for a bucket created without it.

  • SSE-C encryption (no default at-rest, no SSE-KMS)

    There is no default data-at-rest encryption. Optional SSE-C encrypts object bytes with a customer-provided key that Hetzner says it discards after use. Metadata is not encrypted. Losing the key means losing access. SSE-C object copy is listed as unsupported.

  • Project-wide keys, documented S3 gaps, and hard limits

    By default each key pair can read and write every bucket in the same project unless you add bucket policies or split projects. Account limits include 100 buckets, 100 TB and 50 million objects per bucket, 5 TB max object, 5 GB per single PUT, 750 requests per second per bucket, and 10 Gbit/s per bucket. Notifications, website hosting, inventory, replication, and custom domains are not supported.

Assurance & compliance: Cyso Cloud vs Hetzner Object Storage
Assurance & complianceLogo: Cyso CloudCyso CloudLogo: Hetzner Object StorageHetzner Object Storage
Independent security / no-logs audit
Not found

Security measures and pen-testing philosophy are described; no public independent no-logs or IaaS audit report found beyond ISMS certs.

Not applicable

IaaS object store, not a no-logs VPN. Company publishes ISO 27001, BSI C5 Type 2, and annual TOM review instead.

ISO 27001
Vendor claimed

Vendor publishes ISO/IEC 27001 certificate PDF via Trust Centre / certifications (listed expiry into 2028). Not re-checked on an independent registry for this draft.

Verified

Public ISO/IEC 27001:2022 certificate (SOCOTEC) for the ISMS covering Nuremberg, Falkenstein, and Helsinki parks. Confirm attested scope includes this SKU with your auditor.

SOC 2 / SOC 3
Not found

Certifications page explains SOC 2 Type II generally; no clear statement that Cyso currently holds a published SOC 2 report.

Not found

Hetzner states it focuses on ISO 27001 rather than SOC 2.

GDPR / EU data protection
Vendor claimed

EU legal entity; AMS/FRA residency claims; Trust Centre GDPR section. Obtain DPA and TOMs for controller/processor mapping.

Vendor claimed

German entity; public privacy policy, Art. 28 DPA, TOMs, subprocessor list. Customer remains controller for data stored in buckets.

US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: EU entity, no known US parent, primary IaaS claimed on self-operated NL/DE hardware (not AWS/GCP/Azure). Partial because no full public subprocessor schedule and ancillary SaaS (e.g. PostHog analytics, Atlassian-linked status) may involve non-EU providers. Not legal advice.

Partial

EU entity, no known US parent, Object Storage has no US region and no US-group storage backend. Group still includes Hetzner US LLC for other products. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Marketing (e.g. Azure alternative pages) states Cyso signs a DPA under Dutch law; confirm current template and subprocessor annex in contracting.

Vendor claimed

Standard DPA accept-in-console; sample PDF published; no custom wet-ink DPAs per vendor docs.

NEN 7510 (Dutch healthcare information security)
Vendor claimed

Vendor publishes NEN 7510 certificate PDF on certifications/Trust Centre pages.

Not listed
EU AI Act
Not applicable

IaaS/infrastructure platform, not an AI system product.

Not applicable

Object storage infrastructure, not an AI system product.

BSI C5 (cloud)Not listed
Verified

Vendor publishes a BSI C5 Type 2 attestation PDF for cloud services. Confirm whether Object Storage is inside the attested cloud-service scope.

Considerations & known limitations: Cyso Cloud vs Hetzner Object Storage
Considerations & known limitationsLogo: Cyso CloudCyso CloudLogo: Hetzner Object StorageHetzner Object Storage
Only two live public regions
Medium

Production public cloud is AMS and FRA today. Multi-continent latency, in-country residency outside NL/DE, or extensive multi-region DR across Europe may require another provider or private cloud.

Not listed
No default object storage encryption at rest
Medium

Official FAQs state no standard server-side encryption at rest; TLS in transit and client-side/SSE-C patterns are recommended. Regulated designs must implement key management outside default storage behaviour.

Not listed
Incomplete public subprocessor inventory
Medium

Primary hosting path is vendor-operated EU hardware, but privacy materials list third parties without a dedicated live subprocessor register for all ancillary processing. Request the schedule under NDA or DPA annex.

Not listed
Certifications are vendor-published PDFs
Low

ISO 27001 and NEN 7510 are claimed with certificate PDFs on Cyso sites; this draft did not independently verify registry entries. Treat as claimed until audit pack is reviewed.

Not listed
Smaller ecosystem than hyperscalers
Low

Fewer managed PaaS services and marketplace options than AWS/Azure/GCP. Expect to run more of the stack yourself on OpenStack/Kubernetes.

Not listed
Partial S3 compatibilityNot listed
Medium

Supported-actions list omits website hosting, notifications, inventory, replication, custom domains, SSE-KMS, and more. CopyObject may fail even in one location. Apps that assume full AWS S3 will break.

HDD tier, not a CDNNot listed
Medium

Standard HDD only, no archive or flash classes. Hetzner says it is a poor fit for high-frequency small objects, low-latency apps, and large-scale public HTTP. Plan a CDN or different storage for those cases.

No default at-rest encryptionNot listed
Medium

Objects are not encrypted at rest unless you use SSE-C and keep the key. Lost keys are unrecoverable. SSE-C copy is unsupported.

Single data center, no built-in replicationNot listed
Medium

A bucket lives in one DC. There is no first-party cross-location replication. You must build DR yourself if one park outage is unacceptable.

Shared-cluster load and 503sNot listed
Medium

Vendor docs describe cluster growth, bucket migrations, and temporary concurrency or upload limits (including 503 in Nuremberg under load). Shared tenancy can affect latency.

Group US and Singapore entitiesNot listed
Low

This SKU is EU-only, but Hetzner Online GmbH has US and Singapore subsidiaries for other Cloud locations. Zero-US-footprint procurement may still reject the vendor.

Fit

Cyso Cloud

Best fit when

  • European product/SaaS teams that need VMs, volumes, and S3-compatible storage with explicit Amsterdam or Frankfurt residency
  • Organisations standardising on OpenStack APIs/CLI to reduce hyperscaler lock-in and support multi-cloud portability
  • Teams wanting CNCF KCSP managed Kubernetes with hibernation and pay-as-you-go worker nodes on EU infrastructure
  • Dutch healthcare-adjacent or regulated buyers who need NEN 7510 alongside ISO 27001 claims from a NL operator
  • Buyers evaluating a private OpenStack cloud or VMware alternative on their own data-centre hardware

Poor fit when

  • Workloads that require many global regions, edge PoPs, or a large marketplace of managed PaaS services
  • Storage designs that assume default server-side encryption at rest without customer-managed keys
  • Procurement that must rely only on a fully published subprocessor schedule without vendor engagement
  • Teams that need fully self-serve free tiers or only automated chat support with no human engineering contact

Consider instead when

  • When: You need many European (or global) regions and a broader product catalogue than two live IaaS regions

    Consider: OVHcloud or Scaleway

    Larger EU multi-region footprints; different APIs and commercial models.

  • When: You want Swiss multi-zone simplicity with strong managed Kubernetes emphasis

    Consider: Exoscale

    Swiss operator profile; fewer regions than hyperscalers but clear sovereignty messaging.

  • When: You need maximum global PaaS depth, AI services, and worldwide edge

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Trade EU ownership for ecosystem breadth; apply your own residency and CLOUD Act analysis.

  • When: You prioritise high-performance European VMs across more city locations than AMS/FRA only

    Consider: UpCloud

    Different stack; compare residency guarantees and support model side by side.

Hetzner Object Storage

Best fit when

  • Teams already on Hetzner Cloud or dedicated servers that want an S3 endpoint under the same German contract
  • Backups, archives, dumps, and warm or cold blobs that fit write-once, read-many access
  • Workloads that can pin a bucket to Falkenstein, Nuremberg, or Helsinki and accept a single data center
  • Backup tools and apps that speak generic S3 (AWS CLI, rclone, MinIO client, Synology Hyper Backup)
  • Buyers who need object lock, versioning, or lifecycle expiry without US object-storage regions

Poor fit when

  • Apps that need Amazon S3 feature parity (events, website hosting, inventory, KMS, replication, storage classes)
  • CDN-style public delivery or high-frequency tiny-object / low-latency database use
  • Policies that require default provider-managed at-rest encryption (SSE-S3 or SSE-KMS)
  • Orgs that forbid any US subsidiary at group level even when this SKU stays in the EU
  • Buyers who need more than 100 buckets or first-party cross-location DR

Consider instead when

  • When: You need the full Amazon S3 feature set, storage classes, KMS, events, or global regions

    Consider: Amazon S3

    Accept US-group jurisdiction in exchange for catalog depth.

  • When: You want another European S3-compatible cloud without a Hetzner compute relationship

    Consider: Scaleway or OVHcloud

    Compare their object-storage regions, S3 gaps, and contract entities separately.

  • When: You are evaluating Hetzner VMs, bare metal, or the company as a whole

    Consider: Hetzner

    The company page covers IaaS and parks; this page is the bucket SKU only.

  • When: You want a smaller EU cloud with S3-oriented positioning

    Consider: Cyso Cloud

    Verify current regions and S3 compatibility on that product page.

Open questions for due diligence

Cyso Cloud

  • Can Cyso provide the current DPA, technical and organisational measures, and a dated subprocessor list covering payments, support, analytics, and status tooling?
  • What is the exact OpenStack release, upgrade cadence, and any divergences from upstream APIs that affect Terraform/automation?
  • For object storage and volumes, what encryption-at-rest or KMS options can be contractually committed for regulated data?
  • What are contractual 24/7 escalation SLAs for severity-1 incidents beyond office-hours tech-to-tech support?
  • Which additional EU regions (if any) have committed go-live dates versus community voting only?

Hetzner Object Storage

  • Does your auditor accept Hetzner's park-level ISO 27001 and cloud C5 Type 2 for this object-storage SKU without a SKU-specific statement of applicability?
  • Can your application live with the documented S3 gaps (no events, website, KMS, replication, custom domain)?
  • Is a single data center per bucket acceptable, or do you need first-party multi-site replication?
  • Will you operate SSE-C key management yourself, or do you require provider-managed at-rest encryption?
  • Does group presence of Hetzner US LLC block you even if buckets stay in DE/FI?