Contabo Object Storage vs Hetzner Object Storage

Comparez Contabo Object Storage et Hetzner Object Storage sur les capacités, la juridiction, les garanties et l'adéquation pour les acheteurs européens.

Tous deux listés comme alternatives à: Amazon S3, Google Cloud Storage

Logo: Contabo Object Storage

Contabo Object Storage

Germany· Cloud Computing

Needs review

Shortlist when you want a Ceph S3 bucket next to Contabo VPS or VDS, can use path-style endpoints, and can live without S3 logging. Skip when you need Amazon-complete S3, a first-party custom TLS hostname, company-wide ISO 27001 or SOC 2, or a store with no US parent and no US region. Consider Hetzner Object Storage or OVHcloud Object Storage instead.

S3-compatible (partial)Ceph backendEU region availableGerman GmbHIn-panel DPA
Logo: Hetzner Object Storage

Hetzner Object Storage

Germany· Cloud Computing

Needs review

Shortlist when you want S3-compatible buckets in Falkenstein, Nuremberg, or Helsinki under Hetzner Online GmbH, especially if you already run Hetzner compute. Skip when you need AWS-parity features, flash tiers, a CDN, or default KMS at-rest encryption. Prefer Amazon S3 for full feature depth; prefer Scaleway or OVHcloud if you want another European S3 SKU without a Hetzner compute relationship.

S3-compatible APIEU-only locationsSingle-DC residencyObject lock + versioningSSE-C (opt-in)ISO 27001 (company)
Contabo Object Storage vs Hetzner Object Storage: Aperçu
CaractéristiqueLogo: Contabo Object StorageContabo Object StorageLogo: Hetzner Object StorageHetzner Object Storage
Pays d'origineGermanyGermany
CatégorieCloud ComputingCloud Computing
Open sourceNonNon
Auto-hébergéNonNon
SiègeGermanyGermany
Entité légaleContabo GmbH (Welfenstrasse 22, 81541 Munich; AG Munich HRB 180722; VAT DE267602842)Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen (HRB 6089 Ansbach)
Maison mère / contrôle USMaison mère ou contrôle USAucune maison mère US connue
Exposition CLOUD Act (indicative)ÉlevéFaible
Hébergement / résidenceObject storage sold in the EU (eu2.contabostorage.com), United States (usc1.contabostorage.com), and Singapore (sin1.contabostorage.com). Contabo operates its own data centers. No public object-storage subprocessor list. Management API auth is at auth.contabo.com. Official custom-domain docs use Cloudflare as an optional customer-side proxy, not as the S3 data plane.Object Storage only in Falkenstein, Nuremberg (company-operated DE parks) and Helsinki (Hetzner Finland Oy for building rental and technical support). Entire bucket stays in the selected single data center on Hetzner Ceph. No US or Singapore object-storage region. Group still has Hetzner US LLC, Hetzner Singapore Pte. Ltd., and US/SG colocation partners for other Cloud server products. Customer master data stays in the EU per Hetzner docs.
Résumé

S3-compatible object storage from Munich-based Contabo GmbH, running on Ceph with EU, US, and Singapore endpoints.

German S3-compatible object storage from Hetzner Online GmbH: buckets in Falkenstein, Nuremberg, and Helsinki with location-specific endpoints.

Tags
En un coup d'œil: Contabo Object Storage vs Hetzner Object Storage
En un coup d'œilLogo: Contabo Object StorageContabo Object StorageLogo: Hetzner Object StorageHetzner Object Storage
HQMunich, Germany (Contabo GmbH, HRB 180722)Gunzenhausen, Germany
ProductHosted Ceph S3 object storageNon indiqué
S3 regionsEU (eu2), United States (usc1), Singapore (sin1)Non indiqué
AddressingPath-style; HTTPS onlyNon indiqué
Commercial modelPurchased capacity with optional auto-scale; no per-GB egress on Contabo's stated modelHourly base fee with included storage and egress quota, then pay-as-you-go
OwnershipKKR majority (2022), Oakley Capital Fund V minorityNon indiqué
Legal entityNon indiquéHetzner Online GmbH (HRB 6089 Ansbach)
LocationsNon indiquéFSN1 Falkenstein, NBG1 Nuremberg, HEL1 Helsinki
APINon indiquéS3-compatible, AWS Signature Version 4
Storage backendNon indiquéCeph on HDD (standard tier only)
EncryptionNon indiquéNo default at-rest; optional SSE-C
Key capabilities: Contabo Object Storage vs Hetzner Object Storage
Key capabilitiesLogo: Contabo Object StorageContabo Object StorageLogo: Hetzner Object StorageHetzner Object Storage
S3-compatible (partial)OuiNon indiqué
Ceph backendOuiNon indiqué
EU region availableOuiNon indiqué
German GmbHOuiNon indiqué
In-panel DPAOuiNon indiqué
S3-compatible APINon indiquéOui
EU-only locationsNon indiquéOui
Single-DC residencyNon indiquéOui
Object lock + versioningNon indiquéOui
SSE-C (opt-in)Non indiquéOui
ISO 27001 (company)Non indiquéOui

Contabo Object Storage

  • Ceph S3 API with path-style buckets

    Contabo states the store is Ceph-based and largely S3 compatible, not fully equivalent to Amazon S3. Logging is not supported. Official tool notes require Contabo S3 URLs, path-style buckets, and access_key/secret_key mapped to aws_access_key_id/aws_secret_access_key.

  • EU, US, and Singapore S3 endpoints

    Documented base URLs are eu2.contabostorage.com (European Union), usc1.contabostorage.com (United States), and sin1.contabostorage.com (Singapore). The management API allows one object-storage purchase per location. All locations on an account share the same S3 credentials.

  • Bucket versioning and Object Lock

    Versioning is enabled per bucket via s3api put-bucket-versioning on the regional endpoint. Suspending versioning stops new versions but does not delete old ones. Object Lock can be turned on at bucket creation (example uses GOVERNANCE mode) so objects cannot be overwritten or deleted for a retention period.

  • Capacity auto-scale via management API

    The Contabo API (not the S3 API) orders, upgrades, cancels, and auto-scales purchased space up to a monthly size limit. Usage statistics are exposed there. The open-source cntb CLI (GPL-3.0) wraps the same management API. S3 keys come from the User Management API or the Object Storage panel.

  • Published client list and hard limits

    Documented working tools include cntb, aws cli, rclone, Cyberduck, goofys, s3fs-fuse, s3cmd, WinSCP, Cloudberry Explorer, BucketAnywhere, Virtualmin, Velero, and Plesk. FileZilla Pro is listed as incompatible. Defaults include 5 TB max object size, 100 buckets, 3 million objects (increasable on request), 250 requests per second, and 10 MByte/s default bandwidth.

Hetzner Object Storage

  • S3 API with FSN1, NBG1, and HEL1 endpoints

    Amazon S3 compatible API using AWS Signature Version 4. Location endpoints are fsn1.your-objectstorage.com, nbg1.your-objectstorage.com, and hel1.your-objectstorage.com. AWS CLI and common SDKs work when pointed at the Hetzner endpoint. Console covers bucket create and credentials; almost all object operations go through the S3 API.

  • Single-location EU bucket residency on Ceph

    A bucket is stored entirely in the location you pick (Falkenstein, Nuremberg, or Helsinki), in one data center. Docs describe a Ceph cluster with erasure coding that can keep data intact if up to three storage servers fail. There is no US or Singapore object-storage region and no built-in cross-location replication.

  • Object lock, versioning, and lifecycle expiry

    Object Lock can be enabled at bucket create (legal hold and retention). Versioning and lifecycle rules are documented, including NoncurrentDays expiry. Pre-signed URLs give time-limited access. Object lock cannot be turned on later for a bucket created without it.

  • SSE-C encryption (no default at-rest, no SSE-KMS)

    There is no default data-at-rest encryption. Optional SSE-C encrypts object bytes with a customer-provided key that Hetzner says it discards after use. Metadata is not encrypted. Losing the key means losing access. SSE-C object copy is listed as unsupported.

  • Project-wide keys, documented S3 gaps, and hard limits

    By default each key pair can read and write every bucket in the same project unless you add bucket policies or split projects. Account limits include 100 buckets, 100 TB and 50 million objects per bucket, 5 TB max object, 5 GB per single PUT, 750 requests per second per bucket, and 10 Gbit/s per bucket. Notifications, website hosting, inventory, replication, and custom domains are not supported.

Assurance & compliance: Contabo Object Storage vs Hetzner Object Storage
Assurance & complianceLogo: Contabo Object StorageContabo Object StorageLogo: Hetzner Object StorageHetzner Object Storage
Independent security / no-logs audit
Not found

Searched About, help, and product docs. No public independent audit PDF for Object Storage.

Not applicable

IaaS object store, not a no-logs VPN. Company publishes ISO 27001, BSI C5 Type 2, and annual TOM review instead.

ISO 27001
Partial

Some Contabo location marketing pages list colocation-facility ISO 27001 (for example Singapore). No company-wide Contabo ISO 27001 certificate found.

Verified

Public ISO/IEC 27001:2022 certificate (SOCOTEC) for the ISMS covering Nuremberg, Falkenstein, and Helsinki parks. Confirm attested scope includes this SKU with your auditor.

SOC 2 / SOC 3
Not found

No Contabo-issued SOC 2 or SOC 3 report found. Facility-level SOC marks on some non-EU location pages are not treated as a Contabo attestation.

Not found

Hetzner states it focuses on ISO 27001 rather than SOC 2.

GDPR / EU data protection
Vendor claimed

EU legal entity; DPA available in the Customer Control Panel and listed as covering Object Storage. EU region is optional, not exclusive.

Vendor claimed

German entity; public privacy policy, Art. 28 DPA, TOMs, subprocessor list. Customer remains controller for data stored in buckets.

US CLOUD Act exposure (indicative)
Partial

Contabo GmbH is German, but KKR (US) has been the majority investor since June 2022 and Contabo sells a US object-storage region. Not legal advice.

Partial

EU entity, no known US parent, Object Storage has no US region and no US-group storage backend. Group still includes Hetzner US LLC for other products. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Customer Control Panel wizard. Object Storage is an explicit covered service. Review the generated PDF.

Vendor claimed

Standard DPA accept-in-console; sample PDF published; no custom wet-ink DPAs per vendor docs.

EU AI Act
Not applicable

Object storage IaaS, not an AI system.

Not applicable

Object storage infrastructure, not an AI system product.

BSI C5 (cloud)Non indiqué
Verified

Vendor publishes a BSI C5 Type 2 attestation PDF for cloud services. Confirm whether Object Storage is inside the attested cloud-service scope.

Considerations & known limitations: Contabo Object Storage vs Hetzner Object Storage
Considerations & known limitationsLogo: Contabo Object StorageContabo Object StorageLogo: Hetzner Object StorageHetzner Object Storage
US private-equity majority owner
High

Oakley Capital announced in June 2022 that KKR would be majority investor, with Oakley Fund V retaining a minority stake. Treat CLOUD Act exposure as high at the ownership layer even when objects sit on eu2.contabostorage.com.

Non indiqué
Optional United States object region
Medium

usc1.contabostorage.com is a first-party SKU. Shared credentials across locations make it easy to point a client at the US endpoint by mistake. Pin the EU URL if residency is a hard requirement.

Non indiqué
Partial S3 compatibility
Medium

Contabo states the Ceph API is not fully compatible with AWS S3. Logging is unsupported. Path-style addressing is required. FileZilla Pro does not work. Test SDK features before migrating production.

Medium

Supported-actions list omits website hosting, notifications, inventory, replication, custom domains, SSE-KMS, and more. CopyObject may fail even in one location. Apps that assume full AWS S3 will break.

Default request and bandwidth caps
Medium

Published defaults include 250 API requests per second, 10 MByte/s bandwidth, 100 buckets, and 3 million objects. Auto-scale increases purchased terabytes, not those caps.

Non indiqué
No public company-wide audit
Medium

No independent Object Storage audit, Contabo-issued ISO 27001, or SOC 2 report was found. Facility ISO/SOC marks on some location pages are not a substitute.

Non indiqué
No first-party custom TLS hostname
Low

HTTPS-only S3 endpoints reject a simple CNAME. Public websites need a customer-operated reverse proxy. Public-to-private ACL changes may remain cached for up to one hour.

Non indiqué
HDD tier, not a CDNNon indiqué
Medium

Standard HDD only, no archive or flash classes. Hetzner says it is a poor fit for high-frequency small objects, low-latency apps, and large-scale public HTTP. Plan a CDN or different storage for those cases.

No default at-rest encryptionNon indiqué
Medium

Objects are not encrypted at rest unless you use SSE-C and keep the key. Lost keys are unrecoverable. SSE-C copy is unsupported.

Single data center, no built-in replicationNon indiqué
Medium

A bucket lives in one DC. There is no first-party cross-location replication. You must build DR yourself if one park outage is unacceptable.

Shared-cluster load and 503sNon indiqué
Medium

Vendor docs describe cluster growth, bucket migrations, and temporary concurrency or upload limits (including 503 in Nuremberg under load). Shared tenancy can affect latency.

Group US and Singapore entitiesNon indiqué
Low

This SKU is EU-only, but Hetzner Online GmbH has US and Singapore subsidiaries for other Cloud locations. Zero-US-footprint procurement may still reject the vendor.

Adéquation

Contabo Object Storage

Best fit when

  • Teams already on Contabo Cloud VPS or VDS that need a same-account backup or media bucket
  • Workloads that speak standard S3 via rclone, aws cli, Velero, Plesk, or s3cmd and can use path-style URLs
  • Buyers who want capacity-tier billing without per-gigabyte egress modelling
  • Operators who can pin eu2.contabostorage.com and sign the in-panel DPA
  • Buckets that need versioning or Object Lock but not S3 server access logging

Poor fit when

  • Applications that require full Amazon S3 feature parity, especially server access logging or virtual-hosted bucket names
  • Public websites that need a first-party custom hostname and TLS without a reverse proxy
  • Procurement that requires company-wide ISO 27001 or SOC 2, or a vendor with no US private-equity majority owner
  • Strict EU-only policies if anyone on the account might create a US or Singapore store
  • High-QPS or multi-gigabit pipelines that will hit the documented 250 rps or 10 MByte/s defaults

Consider instead when

  • When: You want a German hoster's object store with an EU-concentrated footprint and no US majority PE owner

    Consider: Hetzner Object Storage

    Contabo's own comparison places Hetzner object storage in European data centers and notes a thinner APAC story.

  • When: You need a broader EU compliance portfolio (ISO 27001, SecNumCloud) more than a simple capacity bill

    Consider: OVHcloud Object Storage

    Billing and product surface are more complex than Contabo's single-account IaaS stack.

  • When: You need managed Kubernetes or managed Postgres next to S3, not just raw buckets

    Consider: Scaleway Object Storage

    France-first footprint. Contabo does not sell first-party managed databases or Kubernetes.

  • When: You need Amazon-complete S3 (logging, IAM, global regions) and will accept a US cloud

    Consider: Amazon S3

    Use Contabo only after you have tested the Ceph compatibility gaps against your SDK.

Hetzner Object Storage

Best fit when

  • Teams already on Hetzner Cloud or dedicated servers that want an S3 endpoint under the same German contract
  • Backups, archives, dumps, and warm or cold blobs that fit write-once, read-many access
  • Workloads that can pin a bucket to Falkenstein, Nuremberg, or Helsinki and accept a single data center
  • Backup tools and apps that speak generic S3 (AWS CLI, rclone, MinIO client, Synology Hyper Backup)
  • Buyers who need object lock, versioning, or lifecycle expiry without US object-storage regions

Poor fit when

  • Apps that need Amazon S3 feature parity (events, website hosting, inventory, KMS, replication, storage classes)
  • CDN-style public delivery or high-frequency tiny-object / low-latency database use
  • Policies that require default provider-managed at-rest encryption (SSE-S3 or SSE-KMS)
  • Orgs that forbid any US subsidiary at group level even when this SKU stays in the EU
  • Buyers who need more than 100 buckets or first-party cross-location DR

Consider instead when

  • When: You need the full Amazon S3 feature set, storage classes, KMS, events, or global regions

    Consider: Amazon S3

    Accept US-group jurisdiction in exchange for catalog depth.

  • When: You want another European S3-compatible cloud without a Hetzner compute relationship

    Consider: Scaleway or OVHcloud

    Compare their object-storage regions, S3 gaps, and contract entities separately.

  • When: You are evaluating Hetzner VMs, bare metal, or the company as a whole

    Consider: Hetzner

    The company page covers IaaS and parks; this page is the bucket SKU only.

  • When: You want a smaller EU cloud with S3-oriented positioning

    Consider: Cyso Cloud

    Verify current regions and S3 compatibility on that product page.

Open questions for due diligence

Contabo Object Storage

  • Is there a current company-wide ISO 27001 or SOC 2 for Contabo GmbH (not a colocation-facility mark)?
  • Where is the public subprocessor list for Object Storage, backups, support tooling, and the Customer Control Panel?
  • Does Contabo offer server-side encryption at rest and customer-managed keys for objects? Not documented on the pages reviewed.
  • What is the Ceph replication factor / durability target for each object-storage region?
  • The marketing URL https://contabo.com/en/object-storage/ returned Storage VPS content when fetched during research. Confirm the SKU is still sold and the product page has not been retired.

Hetzner Object Storage

  • Does your auditor accept Hetzner's park-level ISO 27001 and cloud C5 Type 2 for this object-storage SKU without a SKU-specific statement of applicability?
  • Can your application live with the documented S3 gaps (no events, website, KMS, replication, custom domain)?
  • Is a single data center per bucket acceptable, or do you need first-party multi-site replication?
  • Will you operate SSE-C key management yourself, or do you require provider-managed at-rest encryption?
  • Does group presence of Hetzner US LLC block you even if buckets stay in DE/FI?