Cyso Cloud vs Leafcloud Object Storage

Compare Cyso Cloud and Leafcloud Object Storage on capabilities, jurisdiction, assurance, and fit for European buyers.

Logo: Cyso Cloud

Cyso Cloud

Netherlands· Cloud Computing

Needs review

Shortlist Cyso Cloud when you want Dutch-operated OpenStack IaaS and KCSP managed Kubernetes with AMS/FRA residency and engineer-to-engineer support. Skip when you need global hyperscaler regions or default encryption-at-rest object storage—consider OVHcloud or Scaleway for broader European multi-region IaaS, or keep a hyperscaler for worldwide PaaS depth.

EU-operated (NL)OpenStack IaaSManaged Kubernetes (KCSP)AMS + FRA regionsISO 27001 (claimed)NEN 7510 (claimed)
Logo: Leafcloud Object Storage

Leafcloud Object Storage

Netherlands· Cloud Computing

Needs review

Shortlist Leafcloud Object Storage when you want an S3-compatible Ceph bucket in Amsterdam under Leafcloud B.V., with a public ISO 27001 certificate and a downloadable DPA. Skip when you need object versioning, multi-region replication, or AWS-parity S3 features. Consider Cyso Cloud for Dutch OpenStack storage with versioning and a Frankfurt option, or OVHcloud / Scaleway for a wider EU region map.

S3-compatible (leafcloud.store)Amsterdam residencyCeph 3x replicationISO 27001 (public cert)Public DPANo object versioning
Cyso Cloud vs Leafcloud Object Storage: Snapshot
FeatureLogo: Cyso CloudCyso CloudLogo: Leafcloud Object StorageLeafcloud Object Storage
Country of originNetherlandsNetherlands
CategoryCloud ComputingCloud Computing
Open sourceYesNo
Self-hostedNoNo
HeadquartersNetherlandsNetherlands
Legal entityCyso B.V. (part of Cyso Group B.V.), Wognumsebuurt 3, 1817 BH Alkmaar; KVK 37133395Leafcloud B.V., Amsterdam (KvK 78564417). Site: Science Park 400. DPA/ISO: Overhoeksplein 2.
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencyPrimary public IaaS on Cyso-operated hardware in Tier 3 facilities in Amsterdam and Frankfurt (3 AZs per region); vendor states storage replicas/backups stay in the selected EU region. Not marketed as AWS/Azure/GCP-hosted IaaS. Ancillary tools disclosed at group level include website analytics (PostHog) and third parties for payments/support; status tooling has referenced Atlassian Statuspage. Full public customer-workload subprocessor list not found.Objects at Amsterdam Core (europe-nl-ams1), Ceph 3x. DPA (Jan 2026): no subprocessors for core compute/storage/networking; no third-country transfers unless customer-instructed. Terms mention EU partner data centres; Core operator unnamed. Privacy allows unnamed account-data suppliers (invoicing, messaging). Site analytics: self-hosted Matomo. Not AWS/GCP/Azure-hosted.
Summary

Dutch OpenStack IaaS from Cyso B.V. with AMS/FRA regions, managed Kubernetes (KCSP), S3-compatible object storage, and EU data residency for teams avoiding hyperscaler lock-in.

Dutch S3-compatible object storage from Leafcloud B.V. Ceph-backed buckets in Amsterdam via leafcloud.store, plus OpenStack Swift, for backups, app data, and public objects.

Tags
At a glance: Cyso Cloud vs Leafcloud Object Storage
At a glanceLogo: Cyso CloudCyso CloudLogo: Leafcloud Object StorageLeafcloud Object Storage
HQAlkmaar, NetherlandsNot listed
Legal entityCyso B.V. (Cyso Group)Leafcloud B.V., Amsterdam; KvK 78564417
Founded1997 (group); public OpenStack cloud since 2016 (Fuga); Cyso Cloud brand 2025Not listed
RegionsAmsterdam, Frankfurt (more under investigation)Not listed
StackOpenStack + managed Kubernetes (KCSP)Not listed
Commercial modelPay-as-you-go / hourly; optional trial via salesPay for stored capacity; B2B invoicing; vendor states no API request fees
S3 endpointNot listedhttps://leafcloud.store (region europe-nl-ams1, path-style)
BackendNot listedCeph; also OpenStack Swift / Horizon
ResidencyNot listedAmsterdam Core, Netherlands (single region)
Hard limitNot listedNo object versioning; max object 5 TB
Key capabilities: Cyso Cloud vs Leafcloud Object Storage
Key capabilitiesLogo: Cyso CloudCyso CloudLogo: Leafcloud Object StorageLeafcloud Object Storage
EU-operated (NL)YesNot listed
OpenStack IaaSYesNot listed
Managed Kubernetes (KCSP)YesNot listed
AMS + FRA regionsYesNot listed
ISO 27001 (claimed)YesYes
NEN 7510 (claimed)YesNot listed
S3-compatible (leafcloud.store)Not listedYes
Amsterdam residencyNot listedYes
Ceph 3x replicationNot listedYes
Public DPANot listedYes
No object versioningNot listedYes

Cyso Cloud

  • OpenStack public IaaS on EU hardware

    Vanilla OpenStack compute (roughly 2–64 vCPUs and up to 512 GB RAM flavors), NVMe-backed ephemeral and block volumes, dashboard plus OpenStack APIs/CLI. Deployed on Cyso-managed hardware in Amsterdam and Frankfurt with three availability zones per region so multi-AZ designs are first-class.

  • S3-compatible NVMe object storage

    Region-scoped object storage with triple-disk redundancy, versioning, lifecycle rules, object lock, pre-signed URLs, and standard S3 clients (AWS CLI, Rclone, MinIO mc, SDKs). Data and replicas stay in the selected AMS or FRA region; default server-side encryption at rest is not applied—plan client-side or customer-key approaches for sensitive objects.

  • Enterprise Managed Kubernetes (KCSP)

    CNCF Kubernetes Certified Service Provider managed control planes with multi-version support, automated upgrades, worker groups (including GPU/high-memory options), HPA/VPA/node autoscaling, Garden Linux workers, Terraform/kubectl/k9s workflows, and cluster hibernation to scale workers to zero on a schedule.

  • European networking and multi-AZ design

    VPC-style private networks, security groups as virtual firewalls, load balancers with health checks, floating/reserved IPs, Anycast DNS, IPv6 dual-stack, native edge DDoS mitigation, and Direct Connect-style private links. SLA text targets 99.99% monthly uptime for listed compute, volume, object, and networking services when multi-AZ conditions are met.

  • Private cloud and wholesale options

    Same OpenStack-based stack can be deployed as a private cloud on customer data-centre hardware (including VMware-alternative messaging) or white-label/wholesale models for partners—useful when public multi-tenant regions are not enough for isolation or residency policy.

Leafcloud Object Storage

  • S3 API at leafcloud.store (europe-nl-ams1)

    Path-style S3 endpoint https://leafcloud.store, region europe-nl-ams1. Works with AWS CLI, boto3, rclone, Cyberduck, MinIO mc, and other S3 SDKs. Documented features include public or private containers, bucket policies and ACLs, multipart uploads, and presigned URLs. Max object size is 5 TB via multipart. Authentication uses OpenStack EC2 credentials (openstack ec2 credentials create), not the dashboard password.

  • OpenStack Swift and Horizon dashboard

    The same store is reachable as OpenStack object storage (Swift). Create and browse containers at create.leaf.cloud under Object Store. Native CLI uses project-scoped OpenStack auth (openstack container create / object create). Container names must be unique across all Leafcloud users. Docs say there is a limit on how many containers you can create (the exact quota is not published).

  • Ceph cluster with 3x replication in Amsterdam

    The product page describes a Ceph backend (Apache 2.0 software) with triple replication across separate physical nodes in Amsterdam. Persistent objects sit at the Core facility. Compute Leaf sites are a different path and are not where object data is stored, according to the security pages. This is a single-region store, not a multi-region S3 deployment.

  • SSE-C plus TLS in transit

    Official docs show S3 server-side encryption with customer-provided keys (SSE-C, AES256). Leafcloud uses the key on each request and does not store it. Lose the key and you cannot read the object. The product table also lists encryption at rest and TLS in transit as supported. DPA language is TLS 1.2+. LUKS-by-default messaging on the security pages refers to block volumes, not this object API.

  • Terraform state, Velero, and Nextcloud recipes

    Leafcloud publishes working recipes for Terraform’s S3 backend (path-style, skip checksum/region checks, endpoint leafcloud.store), Velero Kubernetes backups (s3ForcePathStyle plus s3Url), and Nextcloud primary objectstore pointing at leafcloud.store:443. Useful if you already run those tools. Object versioning is not available, so state and backup designs must version keys themselves or copy out.

Assurance & compliance: Cyso Cloud vs Leafcloud Object Storage
Assurance & complianceLogo: Cyso CloudCyso CloudLogo: Leafcloud Object StorageLeafcloud Object Storage
Independent security / no-logs audit
Not found

Security measures and pen-testing philosophy are described; no public independent no-logs or IaaS audit report found beyond ISMS certs.

Not found

No public independent no-logs or object-store-specific audit PDF found. SOC 2 Type II is a separate row and is under NDA.

ISO 27001
Vendor claimed

Vendor publishes ISO/IEC 27001 certificate PDF via Trust Centre / certifications (listed expiry into 2028). Not re-checked on an independent registry for this draft.

Verified

Public ProCertify certificate 10112025.1 for LeafCloud B.V.: ISO/IEC 27001:2022 + Amd1:2024. Scope: information security for cloud services, infrastructure, and supporting processes. Valid 10 Nov 2025 to 10 Nov 2028. SoA v3.1 dated 5 Aug 2025. Read from the vendor-hosted PDF; not re-checked on an external accreditation database.

SOC 2 / SOC 3
Not found

Certifications page explains SOC 2 Type II generally; no clear statement that Cyso currently holds a published SOC 2 report.

On request / NDA

Vendor and DPA claim SOC 2 Type II (security, availability, confidentiality). Compliance page: request access by email. Report not reviewed for this draft.

GDPR / EU data protection
Vendor claimed

EU legal entity; AMS/FRA residency claims; Trust Centre GDPR section. Obtain DPA and TOMs for controller/processor mapping.

Vendor claimed

Dutch B.V.; public DPA under Dutch law; vendor states Amsterdam-only processing and no third-country transfers unless instructed. Confirm roles (controller/processor) for your workload.

US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: EU entity, no known US parent, primary IaaS claimed on self-operated NL/DE hardware (not AWS/GCP/Azure). Partial because no full public subprocessor schedule and ancillary SaaS (e.g. PostHog analytics, Atlassian-linked status) may involve non-EU providers. Not legal advice.

Partial

EuropeanStack assessment: EU entity, no known US parent, DPA says no core subprocessors and NL-only processing. Partial because ownership was not independently verified and terms/privacy still allow partner data centres plus unnamed account-data suppliers. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Marketing (e.g. Azure alternative pages) states Cyso signs a DPA under Dutch law; confirm current template and subprocessor annex in contracting.

Vendor claimed

Standard DPA dated January 2026 is public and states it applies automatically (no signature). Custom DPA on request. Governing law: Netherlands; courts of Amsterdam.

NEN 7510 (Dutch healthcare information security)
Vendor claimed

Vendor publishes NEN 7510 certificate PDF on certifications/Trust Centre pages.

Not listed
EU AI Act
Not applicable

IaaS/infrastructure platform, not an AI system product.

Not applicable

Object storage / IaaS SKU, not an AI system product.

HAVEN+ (Dutch public sector)Not listed
Not found

Security FAQ: HAVEN+ certification is in progress, not achieved. Do not treat as certified.

Considerations & known limitations: Cyso Cloud vs Leafcloud Object Storage
Considerations & known limitationsLogo: Cyso CloudCyso CloudLogo: Leafcloud Object StorageLeafcloud Object Storage
Only two live public regions
Medium

Production public cloud is AMS and FRA today. Multi-continent latency, in-country residency outside NL/DE, or extensive multi-region DR across Europe may require another provider or private cloud.

Not listed
No default object storage encryption at rest
Medium

Official FAQs state no standard server-side encryption at rest; TLS in transit and client-side/SSE-C patterns are recommended. Regulated designs must implement key management outside default storage behaviour.

Not listed
Incomplete public subprocessor inventory
Medium

Primary hosting path is vendor-operated EU hardware, but privacy materials list third parties without a dedicated live subprocessor register for all ancillary processing. Request the schedule under NDA or DPA annex.

Not listed
Certifications are vendor-published PDFs
Low

ISO 27001 and NEN 7510 are claimed with certificate PDFs on Cyso sites; this draft did not independently verify registry entries. Treat as claimed until audit pack is reviewed.

Not listed
Smaller ecosystem than hyperscalers
Low

Fewer managed PaaS services and marketplace options than AWS/Azure/GCP. Expect to run more of the stack yourself on OpenStack/Kubernetes.

Not listed
Object versioning disabledNot listed
High

The product table states versioning is not enabled. Overwrites and deletes are not recoverable via S3 versions. Unsafe as a sole Terraform-state or backup target unless you version keys yourself or replicate out.

Amsterdam-only regionNot listed
Medium

One S3 region (europe-nl-ams1). No documented cross-region replication. Multi-country DR or non-NL residency needs another provider.

Baseline SLA is a non-binding targetNot listed
Medium

Terms target more than 99.9% monthly availability without credits on the baseline SLA. Customers must keep their own backups. Premium SLA only if agreed in writing.

Core facility operator not namedNot listed
Medium

DPA says no core subprocessors. Terms mention partner data centres. Public pages do not name the Tier III Core operator. Request that name in contracting.

Incomplete S3 feature parityNot listed
Low

Custom domains are support-gated. Static hosting is basic. Do not assume lifecycle, object lock, or inventory APIs without a proof of concept.

Fit

Cyso Cloud

Best fit when

  • European product/SaaS teams that need VMs, volumes, and S3-compatible storage with explicit Amsterdam or Frankfurt residency
  • Organisations standardising on OpenStack APIs/CLI to reduce hyperscaler lock-in and support multi-cloud portability
  • Teams wanting CNCF KCSP managed Kubernetes with hibernation and pay-as-you-go worker nodes on EU infrastructure
  • Dutch healthcare-adjacent or regulated buyers who need NEN 7510 alongside ISO 27001 claims from a NL operator
  • Buyers evaluating a private OpenStack cloud or VMware alternative on their own data-centre hardware

Poor fit when

  • Workloads that require many global regions, edge PoPs, or a large marketplace of managed PaaS services
  • Storage designs that assume default server-side encryption at rest without customer-managed keys
  • Procurement that must rely only on a fully published subprocessor schedule without vendor engagement
  • Teams that need fully self-serve free tiers or only automated chat support with no human engineering contact

Consider instead when

  • When: You need many European (or global) regions and a broader product catalogue than two live IaaS regions

    Consider: OVHcloud or Scaleway

    Larger EU multi-region footprints; different APIs and commercial models.

  • When: You want Swiss multi-zone simplicity with strong managed Kubernetes emphasis

    Consider: Exoscale

    Swiss operator profile; fewer regions than hyperscalers but clear sovereignty messaging.

  • When: You need maximum global PaaS depth, AI services, and worldwide edge

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Trade EU ownership for ecosystem breadth; apply your own residency and CLOUD Act analysis.

  • When: You prioritise high-performance European VMs across more city locations than AMS/FRA only

    Consider: UpCloud

    Different stack; compare residency guarantees and support model side by side.

Leafcloud Object Storage

Best fit when

  • Teams that need an S3-compatible endpoint and OpenStack Swift in one Dutch account
  • Amsterdam-only residency designs that can live without bucket versioning
  • Velero, Terraform state, or Nextcloud setups that already use path-style S3 clients
  • Buyers who want a public ISO 27001 PDF and a standard DPA before a sales call
  • Organisations that may later add Leafcloud VMs or GPUs in the same jurisdiction

Poor fit when

  • Workloads that require S3 versioning, object lock, or cross-region replication
  • Multi-region or in-country-outside-NL residency (this store is Amsterdam only)
  • Procurement that needs a named Core colocation operator and a full ancillary subprocessor register on day one
  • Consumer or free-tier only use (terms position Leafcloud as B2B)
  • Designs that assume AWS IAM, KMS, or inventory/analytics feature parity

Consider instead when

  • When: You need Dutch or German OpenStack object storage with versioning and more than one EU region

    Consider: Cyso Cloud

    Cyso documents AMS and FRA and lists versioning, lifecycle, and object lock on object storage.

  • When: You need many European locations and a larger IaaS catalogue than a single Amsterdam Ceph cluster

    Consider: OVHcloud or Scaleway

    Broader region maps; different APIs, SLAs, and ownership stories.

  • When: German locations and a large self-serve European hosting catalogue matter more than OpenStack Swift

    Consider: Hetzner

    Compare object storage vs Storage Box features and residency independently.

  • When: Swiss multi-zone IaaS with S3-compatible storage is the sovereignty filter

    Consider: Exoscale

    Different legal seat (Switzerland) and product mix.

  • When: You depend on versioning, replication, IAM, and KMS that only the hyperscaler S3 estate provides

    Consider: Amazon S3 (or Google Cloud Storage)

    Trade EU ownership for feature depth. Apply your own CLOUD Act analysis.

Open questions for due diligence

Cyso Cloud

  • Can Cyso provide the current DPA, technical and organisational measures, and a dated subprocessor list covering payments, support, analytics, and status tooling?
  • What is the exact OpenStack release, upgrade cadence, and any divergences from upstream APIs that affect Terraform/automation?
  • For object storage and volumes, what encryption-at-rest or KMS options can be contractually committed for regulated data?
  • What are contractual 24/7 escalation SLAs for severity-1 incidents beyond office-hours tech-to-tech support?
  • Which additional EU regions (if any) have committed go-live dates versus community voting only?

Leafcloud Object Storage

  • What is the current registered office on the KvK extract (Science Park 400 vs Overhoeksplein 2)?
  • Who operates the Amsterdam Core / partner data centre, and is that party listed as a subprocessor for physical hosting?
  • Can Leafcloud provide a dated list of ancillary processors (billing, support, email) used for account data?
  • Is there a committed date or paid option to enable Ceph/S3 versioning?
  • What contractual availability, durability, and deletion timelines apply to object storage under a Premium SLA versus the baseline terms (14-day vs 90-day deletion language differs between T&Cs and DPA)?