Hetzner Object Storage vs Leafcloud Object Storage

Compare Hetzner Object Storage and Leafcloud Object Storage on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Amazon S3, Google Cloud Storage

Logo: Hetzner Object Storage

Hetzner Object Storage

Germany· Cloud Computing

Needs review

Shortlist when you want S3-compatible buckets in Falkenstein, Nuremberg, or Helsinki under Hetzner Online GmbH, especially if you already run Hetzner compute. Skip when you need AWS-parity features, flash tiers, a CDN, or default KMS at-rest encryption. Prefer Amazon S3 for full feature depth; prefer Scaleway or OVHcloud if you want another European S3 SKU without a Hetzner compute relationship.

S3-compatible APIEU-only locationsSingle-DC residencyObject lock + versioningSSE-C (opt-in)ISO 27001 (company)
Logo: Leafcloud Object Storage

Leafcloud Object Storage

Netherlands· Cloud Computing

Needs review

Shortlist Leafcloud Object Storage when you want an S3-compatible Ceph bucket in Amsterdam under Leafcloud B.V., with a public ISO 27001 certificate and a downloadable DPA. Skip when you need object versioning, multi-region replication, or AWS-parity S3 features. Consider Cyso Cloud for Dutch OpenStack storage with versioning and a Frankfurt option, or OVHcloud / Scaleway for a wider EU region map.

S3-compatible (leafcloud.store)Amsterdam residencyCeph 3x replicationISO 27001 (public cert)Public DPANo object versioning
Hetzner Object Storage vs Leafcloud Object Storage: Snapshot
FeatureLogo: Hetzner Object StorageHetzner Object StorageLogo: Leafcloud Object StorageLeafcloud Object Storage
Country of originGermanyNetherlands
CategoryCloud ComputingCloud Computing
Open sourceNoNo
Self-hostedNoNo
HeadquartersGermanyNetherlands
Legal entityHetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen (HRB 6089 Ansbach)Leafcloud B.V., Amsterdam (KvK 78564417). Site: Science Park 400. DPA/ISO: Overhoeksplein 2.
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencyObject Storage only in Falkenstein, Nuremberg (company-operated DE parks) and Helsinki (Hetzner Finland Oy for building rental and technical support). Entire bucket stays in the selected single data center on Hetzner Ceph. No US or Singapore object-storage region. Group still has Hetzner US LLC, Hetzner Singapore Pte. Ltd., and US/SG colocation partners for other Cloud server products. Customer master data stays in the EU per Hetzner docs.Objects at Amsterdam Core (europe-nl-ams1), Ceph 3x. DPA (Jan 2026): no subprocessors for core compute/storage/networking; no third-country transfers unless customer-instructed. Terms mention EU partner data centres; Core operator unnamed. Privacy allows unnamed account-data suppliers (invoicing, messaging). Site analytics: self-hosted Matomo. Not AWS/GCP/Azure-hosted.
Summary

German S3-compatible object storage from Hetzner Online GmbH: buckets in Falkenstein, Nuremberg, and Helsinki with location-specific endpoints.

Dutch S3-compatible object storage from Leafcloud B.V. Ceph-backed buckets in Amsterdam via leafcloud.store, plus OpenStack Swift, for backups, app data, and public objects.

Tags
At a glance: Hetzner Object Storage vs Leafcloud Object Storage
At a glanceLogo: Hetzner Object StorageHetzner Object StorageLogo: Leafcloud Object StorageLeafcloud Object Storage
HQGunzenhausen, GermanyNot listed
Legal entityHetzner Online GmbH (HRB 6089 Ansbach)Leafcloud B.V., Amsterdam; KvK 78564417
LocationsFSN1 Falkenstein, NBG1 Nuremberg, HEL1 HelsinkiNot listed
APIS3-compatible, AWS Signature Version 4Not listed
Storage backendCeph on HDD (standard tier only)Not listed
EncryptionNo default at-rest; optional SSE-CNot listed
Commercial modelHourly base fee with included storage and egress quota, then pay-as-you-goPay for stored capacity; B2B invoicing; vendor states no API request fees
S3 endpointNot listedhttps://leafcloud.store (region europe-nl-ams1, path-style)
BackendNot listedCeph; also OpenStack Swift / Horizon
ResidencyNot listedAmsterdam Core, Netherlands (single region)
Hard limitNot listedNo object versioning; max object 5 TB
Key capabilities: Hetzner Object Storage vs Leafcloud Object Storage
Key capabilitiesLogo: Hetzner Object StorageHetzner Object StorageLogo: Leafcloud Object StorageLeafcloud Object Storage
S3-compatible APIYesNot listed
EU-only locationsYesNot listed
Single-DC residencyYesNot listed
Object lock + versioningYesNot listed
SSE-C (opt-in)YesNot listed
ISO 27001 (company)YesYes
S3-compatible (leafcloud.store)Not listedYes
Amsterdam residencyNot listedYes
Ceph 3x replicationNot listedYes
Public DPANot listedYes
No object versioningNot listedYes

Hetzner Object Storage

  • S3 API with FSN1, NBG1, and HEL1 endpoints

    Amazon S3 compatible API using AWS Signature Version 4. Location endpoints are fsn1.your-objectstorage.com, nbg1.your-objectstorage.com, and hel1.your-objectstorage.com. AWS CLI and common SDKs work when pointed at the Hetzner endpoint. Console covers bucket create and credentials; almost all object operations go through the S3 API.

  • Single-location EU bucket residency on Ceph

    A bucket is stored entirely in the location you pick (Falkenstein, Nuremberg, or Helsinki), in one data center. Docs describe a Ceph cluster with erasure coding that can keep data intact if up to three storage servers fail. There is no US or Singapore object-storage region and no built-in cross-location replication.

  • Object lock, versioning, and lifecycle expiry

    Object Lock can be enabled at bucket create (legal hold and retention). Versioning and lifecycle rules are documented, including NoncurrentDays expiry. Pre-signed URLs give time-limited access. Object lock cannot be turned on later for a bucket created without it.

  • SSE-C encryption (no default at-rest, no SSE-KMS)

    There is no default data-at-rest encryption. Optional SSE-C encrypts object bytes with a customer-provided key that Hetzner says it discards after use. Metadata is not encrypted. Losing the key means losing access. SSE-C object copy is listed as unsupported.

  • Project-wide keys, documented S3 gaps, and hard limits

    By default each key pair can read and write every bucket in the same project unless you add bucket policies or split projects. Account limits include 100 buckets, 100 TB and 50 million objects per bucket, 5 TB max object, 5 GB per single PUT, 750 requests per second per bucket, and 10 Gbit/s per bucket. Notifications, website hosting, inventory, replication, and custom domains are not supported.

Leafcloud Object Storage

  • S3 API at leafcloud.store (europe-nl-ams1)

    Path-style S3 endpoint https://leafcloud.store, region europe-nl-ams1. Works with AWS CLI, boto3, rclone, Cyberduck, MinIO mc, and other S3 SDKs. Documented features include public or private containers, bucket policies and ACLs, multipart uploads, and presigned URLs. Max object size is 5 TB via multipart. Authentication uses OpenStack EC2 credentials (openstack ec2 credentials create), not the dashboard password.

  • OpenStack Swift and Horizon dashboard

    The same store is reachable as OpenStack object storage (Swift). Create and browse containers at create.leaf.cloud under Object Store. Native CLI uses project-scoped OpenStack auth (openstack container create / object create). Container names must be unique across all Leafcloud users. Docs say there is a limit on how many containers you can create (the exact quota is not published).

  • Ceph cluster with 3x replication in Amsterdam

    The product page describes a Ceph backend (Apache 2.0 software) with triple replication across separate physical nodes in Amsterdam. Persistent objects sit at the Core facility. Compute Leaf sites are a different path and are not where object data is stored, according to the security pages. This is a single-region store, not a multi-region S3 deployment.

  • SSE-C plus TLS in transit

    Official docs show S3 server-side encryption with customer-provided keys (SSE-C, AES256). Leafcloud uses the key on each request and does not store it. Lose the key and you cannot read the object. The product table also lists encryption at rest and TLS in transit as supported. DPA language is TLS 1.2+. LUKS-by-default messaging on the security pages refers to block volumes, not this object API.

  • Terraform state, Velero, and Nextcloud recipes

    Leafcloud publishes working recipes for Terraform’s S3 backend (path-style, skip checksum/region checks, endpoint leafcloud.store), Velero Kubernetes backups (s3ForcePathStyle plus s3Url), and Nextcloud primary objectstore pointing at leafcloud.store:443. Useful if you already run those tools. Object versioning is not available, so state and backup designs must version keys themselves or copy out.

Assurance & compliance: Hetzner Object Storage vs Leafcloud Object Storage
Assurance & complianceLogo: Hetzner Object StorageHetzner Object StorageLogo: Leafcloud Object StorageLeafcloud Object Storage
Independent security / no-logs audit
Not applicable

IaaS object store, not a no-logs VPN. Company publishes ISO 27001, BSI C5 Type 2, and annual TOM review instead.

Not found

No public independent no-logs or object-store-specific audit PDF found. SOC 2 Type II is a separate row and is under NDA.

ISO 27001
Verified

Public ISO/IEC 27001:2022 certificate (SOCOTEC) for the ISMS covering Nuremberg, Falkenstein, and Helsinki parks. Confirm attested scope includes this SKU with your auditor.

Verified

Public ProCertify certificate 10112025.1 for LeafCloud B.V.: ISO/IEC 27001:2022 + Amd1:2024. Scope: information security for cloud services, infrastructure, and supporting processes. Valid 10 Nov 2025 to 10 Nov 2028. SoA v3.1 dated 5 Aug 2025. Read from the vendor-hosted PDF; not re-checked on an external accreditation database.

SOC 2 / SOC 3
Not found

Hetzner states it focuses on ISO 27001 rather than SOC 2.

On request / NDA

Vendor and DPA claim SOC 2 Type II (security, availability, confidentiality). Compliance page: request access by email. Report not reviewed for this draft.

GDPR / EU data protection
Vendor claimed

German entity; public privacy policy, Art. 28 DPA, TOMs, subprocessor list. Customer remains controller for data stored in buckets.

Vendor claimed

Dutch B.V.; public DPA under Dutch law; vendor states Amsterdam-only processing and no third-country transfers unless instructed. Confirm roles (controller/processor) for your workload.

US CLOUD Act exposure (indicative)
Partial

EU entity, no known US parent, Object Storage has no US region and no US-group storage backend. Group still includes Hetzner US LLC for other products. Not legal advice.

Partial

EuropeanStack assessment: EU entity, no known US parent, DPA says no core subprocessors and NL-only processing. Partial because ownership was not independently verified and terms/privacy still allow partner data centres plus unnamed account-data suppliers. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Standard DPA accept-in-console; sample PDF published; no custom wet-ink DPAs per vendor docs.

Vendor claimed

Standard DPA dated January 2026 is public and states it applies automatically (no signature). Custom DPA on request. Governing law: Netherlands; courts of Amsterdam.

EU AI Act
Not applicable

Object storage infrastructure, not an AI system product.

Not applicable

Object storage / IaaS SKU, not an AI system product.

BSI C5 (cloud)
Verified

Vendor publishes a BSI C5 Type 2 attestation PDF for cloud services. Confirm whether Object Storage is inside the attested cloud-service scope.

Not listed
HAVEN+ (Dutch public sector)Not listed
Not found

Security FAQ: HAVEN+ certification is in progress, not achieved. Do not treat as certified.

Considerations & known limitations: Hetzner Object Storage vs Leafcloud Object Storage
Considerations & known limitationsLogo: Hetzner Object StorageHetzner Object StorageLogo: Leafcloud Object StorageLeafcloud Object Storage
Partial S3 compatibility
Medium

Supported-actions list omits website hosting, notifications, inventory, replication, custom domains, SSE-KMS, and more. CopyObject may fail even in one location. Apps that assume full AWS S3 will break.

Not listed
HDD tier, not a CDN
Medium

Standard HDD only, no archive or flash classes. Hetzner says it is a poor fit for high-frequency small objects, low-latency apps, and large-scale public HTTP. Plan a CDN or different storage for those cases.

Not listed
No default at-rest encryption
Medium

Objects are not encrypted at rest unless you use SSE-C and keep the key. Lost keys are unrecoverable. SSE-C copy is unsupported.

Not listed
Single data center, no built-in replication
Medium

A bucket lives in one DC. There is no first-party cross-location replication. You must build DR yourself if one park outage is unacceptable.

Not listed
Shared-cluster load and 503s
Medium

Vendor docs describe cluster growth, bucket migrations, and temporary concurrency or upload limits (including 503 in Nuremberg under load). Shared tenancy can affect latency.

Not listed
Group US and Singapore entities
Low

This SKU is EU-only, but Hetzner Online GmbH has US and Singapore subsidiaries for other Cloud locations. Zero-US-footprint procurement may still reject the vendor.

Not listed
Object versioning disabledNot listed
High

The product table states versioning is not enabled. Overwrites and deletes are not recoverable via S3 versions. Unsafe as a sole Terraform-state or backup target unless you version keys yourself or replicate out.

Amsterdam-only regionNot listed
Medium

One S3 region (europe-nl-ams1). No documented cross-region replication. Multi-country DR or non-NL residency needs another provider.

Baseline SLA is a non-binding targetNot listed
Medium

Terms target more than 99.9% monthly availability without credits on the baseline SLA. Customers must keep their own backups. Premium SLA only if agreed in writing.

Core facility operator not namedNot listed
Medium

DPA says no core subprocessors. Terms mention partner data centres. Public pages do not name the Tier III Core operator. Request that name in contracting.

Incomplete S3 feature parityNot listed
Low

Custom domains are support-gated. Static hosting is basic. Do not assume lifecycle, object lock, or inventory APIs without a proof of concept.

Fit

Hetzner Object Storage

Best fit when

  • Teams already on Hetzner Cloud or dedicated servers that want an S3 endpoint under the same German contract
  • Backups, archives, dumps, and warm or cold blobs that fit write-once, read-many access
  • Workloads that can pin a bucket to Falkenstein, Nuremberg, or Helsinki and accept a single data center
  • Backup tools and apps that speak generic S3 (AWS CLI, rclone, MinIO client, Synology Hyper Backup)
  • Buyers who need object lock, versioning, or lifecycle expiry without US object-storage regions

Poor fit when

  • Apps that need Amazon S3 feature parity (events, website hosting, inventory, KMS, replication, storage classes)
  • CDN-style public delivery or high-frequency tiny-object / low-latency database use
  • Policies that require default provider-managed at-rest encryption (SSE-S3 or SSE-KMS)
  • Orgs that forbid any US subsidiary at group level even when this SKU stays in the EU
  • Buyers who need more than 100 buckets or first-party cross-location DR

Consider instead when

  • When: You need the full Amazon S3 feature set, storage classes, KMS, events, or global regions

    Consider: Amazon S3

    Accept US-group jurisdiction in exchange for catalog depth.

  • When: You want another European S3-compatible cloud without a Hetzner compute relationship

    Consider: Scaleway or OVHcloud

    Compare their object-storage regions, S3 gaps, and contract entities separately.

  • When: You are evaluating Hetzner VMs, bare metal, or the company as a whole

    Consider: Hetzner

    The company page covers IaaS and parks; this page is the bucket SKU only.

  • When: You want a smaller EU cloud with S3-oriented positioning

    Consider: Cyso Cloud

    Verify current regions and S3 compatibility on that product page.

Leafcloud Object Storage

Best fit when

  • Teams that need an S3-compatible endpoint and OpenStack Swift in one Dutch account
  • Amsterdam-only residency designs that can live without bucket versioning
  • Velero, Terraform state, or Nextcloud setups that already use path-style S3 clients
  • Buyers who want a public ISO 27001 PDF and a standard DPA before a sales call
  • Organisations that may later add Leafcloud VMs or GPUs in the same jurisdiction

Poor fit when

  • Workloads that require S3 versioning, object lock, or cross-region replication
  • Multi-region or in-country-outside-NL residency (this store is Amsterdam only)
  • Procurement that needs a named Core colocation operator and a full ancillary subprocessor register on day one
  • Consumer or free-tier only use (terms position Leafcloud as B2B)
  • Designs that assume AWS IAM, KMS, or inventory/analytics feature parity

Consider instead when

  • When: You need Dutch or German OpenStack object storage with versioning and more than one EU region

    Consider: Cyso Cloud

    Cyso documents AMS and FRA and lists versioning, lifecycle, and object lock on object storage.

  • When: You need many European locations and a larger IaaS catalogue than a single Amsterdam Ceph cluster

    Consider: OVHcloud or Scaleway

    Broader region maps; different APIs, SLAs, and ownership stories.

  • When: German locations and a large self-serve European hosting catalogue matter more than OpenStack Swift

    Consider: Hetzner

    Compare object storage vs Storage Box features and residency independently.

  • When: Swiss multi-zone IaaS with S3-compatible storage is the sovereignty filter

    Consider: Exoscale

    Different legal seat (Switzerland) and product mix.

  • When: You depend on versioning, replication, IAM, and KMS that only the hyperscaler S3 estate provides

    Consider: Amazon S3 (or Google Cloud Storage)

    Trade EU ownership for feature depth. Apply your own CLOUD Act analysis.

Open questions for due diligence

Hetzner Object Storage

  • Does your auditor accept Hetzner's park-level ISO 27001 and cloud C5 Type 2 for this object-storage SKU without a SKU-specific statement of applicability?
  • Can your application live with the documented S3 gaps (no events, website, KMS, replication, custom domain)?
  • Is a single data center per bucket acceptable, or do you need first-party multi-site replication?
  • Will you operate SSE-C key management yourself, or do you require provider-managed at-rest encryption?
  • Does group presence of Hetzner US LLC block you even if buckets stay in DE/FI?

Leafcloud Object Storage

  • What is the current registered office on the KvK extract (Science Park 400 vs Overhoeksplein 2)?
  • Who operates the Amsterdam Core / partner data centre, and is that party listed as a subprocessor for physical hosting?
  • Can Leafcloud provide a dated list of ancillary processors (billing, support, email) used for account data?
  • Is there a committed date or paid option to enable Ceph/S3 versioning?
  • What contractual availability, durability, and deletion timelines apply to object storage under a Premium SLA versus the baseline terms (14-day vs 90-day deletion language differs between T&Cs and DPA)?