Leafcloud Object Storage vs Scaleway

Compare Leafcloud Object Storage and Scaleway on capabilities, jurisdiction, assurance, and fit for European buyers.

Logo: Leafcloud Object Storage

Leafcloud Object Storage

Netherlands· Cloud Computing

Needs review

Shortlist Leafcloud Object Storage when you want an S3-compatible Ceph bucket in Amsterdam under Leafcloud B.V., with a public ISO 27001 certificate and a downloadable DPA. Skip when you need object versioning, multi-region replication, or AWS-parity S3 features. Consider Cyso Cloud for Dutch OpenStack storage with versioning and a Frankfurt option, or OVHcloud / Scaleway for a wider EU region map.

S3-compatible (leafcloud.store)Amsterdam residencyCeph 3x replicationISO 27001 (public cert)Public DPANo object versioning
Logo: Scaleway

Scaleway

France· Cloud Computing

Needs review

Shortlist Scaleway for French-owned multi-AZ IaaS (Paris/Amsterdam/Warsaw) with bare metal, EU-resident GPUs and Kapsule Kubernetes—especially HDS/sovereignty-sensitive stacks. Skip if you need completed SecNumCloud today or hyperscaler global depth; consider OVHcloud, Exoscale/UpCloud, or AWS/Azure/GCP instead.

EU-operated regionsBare metal + Elastic MetalEU GPU for AIKapsule KubernetesISO 27001 (certified)HDS (claimed)
Leafcloud Object Storage vs Scaleway: Snapshot
FeatureLogo: Leafcloud Object StorageLeafcloud Object StorageLogo: ScalewayScaleway
Country of originNetherlandsFrance
CategoryCloud ComputingCloud Computing
Open sourceNoNo
Self-hostedNoNo
HeadquartersNetherlandsFrance
Legal entityLeafcloud B.V., Amsterdam (KvK 78564417). Site: Science Park 400. DPA/ISO: Overhoeksplein 2.SCALEWAY SAS (R.C.S. Paris 433 115 904), 8 rue de la Ville l'Évêque, 75008 Paris
Governing lawNot listedFrench law (General Terms of Services)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencyObjects at Amsterdam Core (europe-nl-ams1), Ceph 3x. DPA (Jan 2026): no subprocessors for core compute/storage/networking; no third-country transfers unless customer-instructed. Terms mention EU partner data centres; Core operator unnamed. Privacy allows unnamed account-data suppliers (invoicing, messaging). Site analytics: self-hosted Matomo. Not AWS/GCP/Azure-hosted.Customer cloud workloads on Scaleway-operated European multi-AZ infrastructure (Paris, Amsterdam, Warsaw; Milan listed in availability docs)—not primary hosting on AWS/GCP/Azure. Account/controller activities use processors; privacy policy allows some non-EU transfers under SCCs. Full named subprocessor table is via Trust Center/contracts rather than a fully public marketing page.
Summary

Dutch S3-compatible object storage from Leafcloud B.V. Ceph-backed buckets in Amsterdam via leafcloud.store, plus OpenStack Swift, for backups, app data, and public objects.

French iliad-group cloud platform: bare metal, virtual instances, EU-resident GPU for AI, managed Kubernetes, serverless, storage and databases on Scaleway-operated multi-AZ regions in Europe.

Tags
At a glance: Leafcloud Object Storage vs Scaleway
At a glanceLogo: Leafcloud Object StorageLeafcloud Object StorageLogo: ScalewayScaleway
Legal entityLeafcloud B.V., Amsterdam; KvK 78564417Not listed
S3 endpointhttps://leafcloud.store (region europe-nl-ams1, path-style)Not listed
BackendCeph; also OpenStack Swift / HorizonNot listed
ResidencyAmsterdam Core, Netherlands (single region)Not listed
Commercial modelPay for stored capacity; B2B invoicing; vendor states no API request feesPay-as-you-go; compute Savings Plans (GPU rules differ)
Hard limitNo object versioning; max object 5 TBNot listed
HQNot listedParis, France (SCALEWAY SAS)
GroupNot listediliad Group subsidiary
RegionsNot listedParis, Amsterdam, Warsaw multi-AZ (+ Milan listed)
ModelNot listedPublic cloud IaaS/PaaS (not self-hosted)
Open sourceNot listedPlatform proprietary; open standards (K8s, S3 API, Terraform)
Key capabilities: Leafcloud Object Storage vs Scaleway
Key capabilitiesLogo: Leafcloud Object StorageLeafcloud Object StorageLogo: ScalewayScaleway
S3-compatible (leafcloud.store)YesNot listed
Amsterdam residencyYesNot listed
Ceph 3x replicationYesNot listed
ISO 27001 (public cert)YesYes
Public DPAYesNot listed
No object versioningYesNot listed
EU-operated regionsNot listedYes
Bare metal + Elastic MetalNot listedYes
EU GPU for AINot listedYes
Kapsule KubernetesNot listedYes
HDS (claimed)Not listedYes

Leafcloud Object Storage

  • S3 API at leafcloud.store (europe-nl-ams1)

    Path-style S3 endpoint https://leafcloud.store, region europe-nl-ams1. Works with AWS CLI, boto3, rclone, Cyberduck, MinIO mc, and other S3 SDKs. Documented features include public or private containers, bucket policies and ACLs, multipart uploads, and presigned URLs. Max object size is 5 TB via multipart. Authentication uses OpenStack EC2 credentials (openstack ec2 credentials create), not the dashboard password.

  • OpenStack Swift and Horizon dashboard

    The same store is reachable as OpenStack object storage (Swift). Create and browse containers at create.leaf.cloud under Object Store. Native CLI uses project-scoped OpenStack auth (openstack container create / object create). Container names must be unique across all Leafcloud users. Docs say there is a limit on how many containers you can create (the exact quota is not published).

  • Ceph cluster with 3x replication in Amsterdam

    The product page describes a Ceph backend (Apache 2.0 software) with triple replication across separate physical nodes in Amsterdam. Persistent objects sit at the Core facility. Compute Leaf sites are a different path and are not where object data is stored, according to the security pages. This is a single-region store, not a multi-region S3 deployment.

  • SSE-C plus TLS in transit

    Official docs show S3 server-side encryption with customer-provided keys (SSE-C, AES256). Leafcloud uses the key on each request and does not store it. Lose the key and you cannot read the object. The product table also lists encryption at rest and TLS in transit as supported. DPA language is TLS 1.2+. LUKS-by-default messaging on the security pages refers to block volumes, not this object API.

  • Terraform state, Velero, and Nextcloud recipes

    Leafcloud publishes working recipes for Terraform’s S3 backend (path-style, skip checksum/region checks, endpoint leafcloud.store), Velero Kubernetes backups (s3ForcePathStyle plus s3Url), and Nextcloud primary objectstore pointing at leafcloud.store:443. Useful if you already run those tools. Object versioning is not available, so state and backup designs must version keys themselves or copy out.

Scaleway

  • Elastic Metal, Dedibox and Apple Silicon bare metal

    Single-tenant physical servers without a shared hypervisor layer: Dedibox for a wide dedicated catalogue, Elastic Metal for bare metal integrated with Scaleway VPC, load balancing, storage and Kubernetes, plus Apple Silicon Mac mini hosts for native macOS/iOS CI. Best when you need hardware isolation, custom kernels, or GPU bare metal without VM overhead—product lines are still converging, so compare availability zone coverage per SKU.

  • EU-resident GPU instances for AI training and inference

    On-demand GPU VMs with recent NVIDIA options (including L4, L40S, H100 PCIe/SXM and B300-SXM) aimed at LLM fine-tuning, inference and graphics/media acceleration, with data residency in European regions. Integrates with Kapsule via the NVIDIA GPU Operator; pay-as-you-go by the minute. GPU capacity and Savings Plan eligibility differ from general instances—validate stock and zone before committing multi-node jobs.

  • Kubernetes Kapsule and multi-cloud Kosmos

    Managed Kubernetes control planes on Scaleway nodes (Kapsule) with autoscaling-oriented operations, plus Kosmos for hybrid/multi-cloud worker pools including non-Scaleway infrastructure. Suits teams standardising on portable Kubernetes rather than proprietary orchestrators; external Kosmos pools remain your responsibility to patch and size.

  • Multi-AZ European regions with VPC networking

    Place compute and storage in Paris, Amsterdam and Warsaw multi-AZ regions (docs also reference Milan), using regional private networking, load balancers and related network services. Useful for EU latency and residency designs without a US region on the primary map—confirm each product’s AZ matrix in the product-availability guide before multi-region DR planning.

  • Managed storage and databases on open-ish APIs

    S3-compatible Object Storage (including multi-AZ class options), block volumes, and managed database engines (PostgreSQL, MySQL, Redis, MongoDB, ClickHouse-oriented analytics) plus serverless containers/functions/jobs. Reduces day-2 ops for common stack pieces while keeping export paths closer to open standards than pure proprietary PaaS—always check engine versions, HA options and backup retention for production.

  • API, CLI and Terraform-first operations

    Full console plus documented APIs, CLI and Infrastructure-as-Code workflows for provisioning instances, networks and managed services. Fits platform teams automating environments; IAM permissions and account Owner roles still need deliberate design for production orgs.

Assurance & compliance: Leafcloud Object Storage vs Scaleway
Assurance & complianceLogo: Leafcloud Object StorageLeafcloud Object StorageLogo: ScalewayScaleway
Independent security / no-logs audit
Not found

No public independent no-logs or object-store-specific audit PDF found. SOC 2 Type II is a separate row and is under NDA.

Not applicable

IaaS provider (not a no-logs VPN). Trust Center references penetration testing and security reports available on request; not a public no-logs audit product claim.

ISO 27001
Verified

Public ProCertify certificate 10112025.1 for LeafCloud B.V.: ISO/IEC 27001:2022 + Amd1:2024. Scope: information security for cloud services, infrastructure, and supporting processes. Valid 10 Nov 2025 to 10 Nov 2028. SoA v3.1 dated 5 Aug 2025. Read from the vendor-hosted PDF; not re-checked on an external accreditation database.

Verified

ISO/IEC 27001:2022 certificate documentation published (e.g. certificate IS 787020 for SCALEWAY, Paris). Confirm scope covers the services you buy.

SOC 2 / SOC 3
On request / NDA

Vendor and DPA claim SOC 2 Type II (security, availability, confidentiality). Compliance page: request access by email. Report not reviewed for this draft.

Not found

Not listed among public Trust Center compliance badges reviewed (GDPR, HDS, ISO 27001, CSA STAR L1).

GDPR / EU data protection
Vendor claimed

Dutch B.V.; public DPA under Dutch law; vendor states Amsterdam-only processing and no third-country transfers unless instructed. Confirm roles (controller/processor) for your workload.

Vendor claimed

EU controller/processor with published privacy policy and DPA; French entity. Not legal advice.

US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: EU entity, no known US parent, DPA says no core subprocessors and NL-only processing. Partial because ownership was not independently verified and terms/privacy still allow partner data centres plus unnamed account-data suppliers. Not legal advice.

Partial

French SAS / iliad Group; customer IaaS on self-operated EU regions; no US parent found. Controller-side processors and possible third-country transfers per privacy policy; SecNumCloud not complete. Assessment only—not a vendor “safe” claim.

Data processing agreement (B2B)
Vendor claimed

Standard DPA dated January 2026 is public and states it applies automatically (no signature). Custom DPA on request. Governing law: Netherlands; courts of Amsterdam.

Vendor claimed

DPA PDF downloadable on https://www.scaleway.com/en/contracts/ alongside TOMs.

HAVEN+ (Dutch public sector)
Not found

Security FAQ: HAVEN+ certification is in progress, not achieved. Do not treat as certified.

Not listed
EU AI Act
Not applicable

Object storage / IaaS SKU, not an AI system product.

Not applicable

Infrastructure/GPU host; customer models and apps drive AI Act roles. Not an AI Act conformity product claim.

HDS (French health data hosting)Not listed
Vendor claimed

Vendor security and healthcare pages claim HDS certification; Trust Center lists HDS. Confirm certified service scope for your architecture.

CSA STAR Level 1Not listed
Vendor claimed

Trust Center announces CSA STAR Level 1 (CCM self-assessment / CAIQ).

ANSSI SecNumCloudNot listed
Partial

Qualification process started (public news); security pages mark SecNumCloud as ongoing—not obtained as a finished qualification in sources reviewed.

Considerations & known limitations: Leafcloud Object Storage vs Scaleway
Considerations & known limitationsLogo: Leafcloud Object StorageLeafcloud Object StorageLogo: ScalewayScaleway
Object versioning disabled
High

The product table states versioning is not enabled. Overwrites and deletes are not recoverable via S3 versions. Unsafe as a sole Terraform-state or backup target unless you version keys yourself or replicate out.

Not listed
Amsterdam-only region
Medium

One S3 region (europe-nl-ams1). No documented cross-region replication. Multi-country DR or non-NL residency needs another provider.

Not listed
Baseline SLA is a non-binding target
Medium

Terms target more than 99.9% monthly availability without credits on the baseline SLA. Customers must keep their own backups. Premium SLA only if agreed in writing.

Not listed
Core facility operator not named
Medium

DPA says no core subprocessors. Terms mention partner data centres. Public pages do not name the Tier III Core operator. Request that name in contracting.

Not listed
Incomplete S3 feature parity
Low

Custom domains are support-gated. Static hosting is basic. Do not assume lifecycle, object lock, or inventory APIs without a proof of concept.

Not listed
SecNumCloud not yet obtainedNot listed
Medium

ANSSI SecNumCloud is in progress on public materials. Regulated French public-sector tenders that hard-require a qualified cloud today may need another SKU/provider or a delayed migration plan.

Smaller service catalogue than US hyperscalersNot listed
Medium

Expect fewer proprietary managed services and less global region density than AWS/Azure/GCP. Multi-cloud or complementary SaaS may still be required for parts of the estate.

Account-plane processors and possible non-EU transfersNot listed
Low

Even with EU workload regions, privacy policy allows processor use and SCC-backed transfers for some controller purposes (support, payments, marketing, etc.). Pull the live subprocessor list for DPIAs.

Shared responsibility for guest securityNot listed
Medium

Scaleway secures the platform; you own OS hardening, IAM, application security, encryption keys and backups. Recent Trust Center advisories on kernel issues illustrate customer patching duties on instances and Kapsule nodes.

Dedibox vs Elastic Metal product splitNot listed
Low

Two bare-metal experiences still coexist while Scaleway documents convergence. Mis-choosing the line can affect API integration, networking features and migration effort.

Fit

Leafcloud Object Storage

Best fit when

  • Teams that need an S3-compatible endpoint and OpenStack Swift in one Dutch account
  • Amsterdam-only residency designs that can live without bucket versioning
  • Velero, Terraform state, or Nextcloud setups that already use path-style S3 clients
  • Buyers who want a public ISO 27001 PDF and a standard DPA before a sales call
  • Organisations that may later add Leafcloud VMs or GPUs in the same jurisdiction

Poor fit when

  • Workloads that require S3 versioning, object lock, or cross-region replication
  • Multi-region or in-country-outside-NL residency (this store is Amsterdam only)
  • Procurement that needs a named Core colocation operator and a full ancillary subprocessor register on day one
  • Consumer or free-tier only use (terms position Leafcloud as B2B)
  • Designs that assume AWS IAM, KMS, or inventory/analytics feature parity

Consider instead when

  • When: You need Dutch or German OpenStack object storage with versioning and more than one EU region

    Consider: Cyso Cloud

    Cyso documents AMS and FRA and lists versioning, lifecycle, and object lock on object storage.

  • When: You need many European locations and a larger IaaS catalogue than a single Amsterdam Ceph cluster

    Consider: OVHcloud or Scaleway

    Broader region maps; different APIs, SLAs, and ownership stories.

  • When: German locations and a large self-serve European hosting catalogue matter more than OpenStack Swift

    Consider: Hetzner

    Compare object storage vs Storage Box features and residency independently.

  • When: Swiss multi-zone IaaS with S3-compatible storage is the sovereignty filter

    Consider: Exoscale

    Different legal seat (Switzerland) and product mix.

  • When: You depend on versioning, replication, IAM, and KMS that only the hyperscaler S3 estate provides

    Consider: Amazon S3 (or Google Cloud Storage)

    Trade EU ownership for feature depth. Apply your own CLOUD Act analysis.

Scaleway

Best fit when

  • Teams that need compute, storage, networking and managed Kubernetes in documented EU multi-AZ regions under a French legal entity
  • AI/ML workloads that require NVIDIA GPUs with European data residency rather than US-region training defaults
  • Workloads that benefit from single-tenant bare metal (Elastic Metal or Dedibox) alongside cloud APIs
  • Healthtech or French-market buyers that need HDS-oriented hosting signals plus a published B2B DPA
  • Platform engineers standardising on Terraform/API-driven provisioning with S3-compatible storage and managed Postgres/MySQL

Poor fit when

  • Organisations that require a finished ANSSI SecNumCloud qualification on day one (process is ongoing, not completed on public pages)
  • Architectures that must run primary production in US or APAC regions on the same cloud account
  • Buyers that need the full hyperscaler catalogue (global edge, proprietary PaaS density, enterprise marketplace breadth)
  • Teams expecting a self-hosted “install Scaleway on your own DC” product rather than a managed cloud
  • Procurement processes that accept only SOC 2 Type II as the primary assurance artefact (not surfaced as a public Trust Center badge here)

Consider instead when

  • When: You need completed SecNumCloud-qualified private cloud or a larger non-EU region footprint under one European operator

    Consider: OVHcloud

    Compare exact qualified product SKUs and region maps; OVH and Scaleway are both French industrial clouds with different strengths.

  • When: You want simpler EU VPS/dedicated economics with a smaller product surface

    Consider: UpCloud, Exoscale, or Cyso Cloud

    Leaner catalogues; validate GPU, HDS and multi-AZ needs separately.

  • When: You need maximum global managed-service depth and partner ecosystem

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Accept US-parent CLOUD Act exposure and design residency/controls explicitly.

  • When: German SMB hosting plus EU cloud under a DE-centric brand is the priority

    Consider: IONOS

    Different product mix and market focus than Scaleway’s developer/AI-oriented public cloud.

Open questions for due diligence

Leafcloud Object Storage

  • What is the current registered office on the KvK extract (Science Park 400 vs Overhoeksplein 2)?
  • Who operates the Amsterdam Core / partner data centre, and is that party listed as a subprocessor for physical hosting?
  • Can Leafcloud provide a dated list of ancillary processors (billing, support, email) used for account data?
  • Is there a committed date or paid option to enable Ceph/S3 versioning?
  • What contractual availability, durability, and deletion timelines apply to object storage under a Premium SLA versus the baseline terms (14-day vs 90-day deletion language differs between T&Cs and DPA)?

Scaleway

  • What is the exact HDS certificate scope (services, regions, shared responsibility) for our architecture?
  • What is the current ANSSI SecNumCloud milestone and target date for the SKUs we would buy?
  • Which named subprocessors (including any non-EU) process account, billing, support or security telemetry data?
  • For multi-region DR, which products are GA in each AZ (including Milan) at contract time?
  • Are independent SOC 2 / C5 or other reports available under NDA if our assurance programme requires them?