Logo: Hetzner Object Storage

Hetzner Object Storage

German S3-compatible object storage from Hetzner Online GmbH: buckets in Falkenstein, Nuremberg, and Helsinki with location-specific endpoints.

Hetzner Object Storage is the S3-compatible bucket product from Hetzner Online GmbH, the German data center operator already listed in this directory for cloud VMs and dedicated servers. It is a stand-alone storage SKU: you create buckets in Hetzner Console without attaching a virtual machine.

It exists for teams that want object storage under the same German contract and European parks as their Hetzner compute, instead of sending backups and unstructured files to Amazon S3. Official docs list three locations only: Falkenstein (fsn1), Nuremberg (nbg1), and Helsinki (hel1), each with a dedicated endpoint on your-objectstorage.com.

The concrete differentiator is an Amazon S3 compatible API (Signature Version 4) with bucket contents stored in a single chosen European data center on Hetzner's own Ceph clusters. Unlike Hetzner Cloud VMs, this SKU has no United States or Singapore location.

S3-compatible APIEU-only locationsSingle-DC residencyObject lock + versioningSSE-C (opt-in)ISO 27001 (company)

Shortlist when you want S3-compatible buckets in Falkenstein, Nuremberg, or Helsinki under Hetzner Online GmbH, especially if you already run Hetzner compute. Skip when you need AWS-parity features, flash tiers, a CDN, or default KMS at-rest encryption. Prefer Amazon S3 for full feature depth; prefer Scaleway or OVHcloud if you want another European S3 SKU without a Hetzner compute relationship.

Key capabilities

Amazon S3 compatible API using AWS Signature Version 4. Location endpoints are fsn1.your-objectstorage.com, nbg1.your-objectstorage.com, and hel1.your-objectstorage.com. AWS CLI and common SDKs work when pointed at the Hetzner endpoint. Console covers bucket create and credentials; almost all object operations go through the S3 API.

A bucket is stored entirely in the location you pick (Falkenstein, Nuremberg, or Helsinki), in one data center. Docs describe a Ceph cluster with erasure coding that can keep data intact if up to three storage servers fail. There is no US or Singapore object-storage region and no built-in cross-location replication.

Object Lock can be enabled at bucket create (legal hold and retention). Versioning and lifecycle rules are documented, including NoncurrentDays expiry. Pre-signed URLs give time-limited access. Object lock cannot be turned on later for a bucket created without it.

There is no default data-at-rest encryption. Optional SSE-C encrypts object bytes with a customer-provided key that Hetzner says it discards after use. Metadata is not encrypted. Losing the key means losing access. SSE-C object copy is listed as unsupported.

By default each key pair can read and write every bucket in the same project unless you add bucket policies or split projects. Account limits include 100 buckets, 100 TB and 50 million objects per bucket, 5 TB max object, 5 GB per single PUT, 750 requests per second per bucket, and 10 Gbit/s per bucket. Notifications, website hosting, inventory, replication, and custom domains are not supported.

En un coup d'œil

HQ
Gunzenhausen, Germany
Legal entity
Hetzner Online GmbH (HRB 6089 Ansbach)
Locations
FSN1 Falkenstein, NBG1 Nuremberg, HEL1 Helsinki
API
S3-compatible, AWS Signature Version 4
Storage backend
Ceph on HDD (standard tier only)
Encryption
No default at-rest; optional SSE-C
Commercial model
Hourly base fee with included storage and egress quota, then pay-as-you-go

Best fit when

  • Teams already on Hetzner Cloud or dedicated servers that want an S3 endpoint under the same German contract
  • Backups, archives, dumps, and warm or cold blobs that fit write-once, read-many access
  • Workloads that can pin a bucket to Falkenstein, Nuremberg, or Helsinki and accept a single data center
  • Backup tools and apps that speak generic S3 (AWS CLI, rclone, MinIO client, Synology Hyper Backup)
  • Buyers who need object lock, versioning, or lifecycle expiry without US object-storage regions

Poor fit when

  • Apps that need Amazon S3 feature parity (events, website hosting, inventory, KMS, replication, storage classes)
  • CDN-style public delivery or high-frequency tiny-object / low-latency database use
  • Policies that require default provider-managed at-rest encryption (SSE-S3 or SSE-KMS)
  • Orgs that forbid any US subsidiary at group level even when this SKU stays in the EU
  • Buyers who need more than 100 buckets or first-party cross-location DR

Consider instead when

  • When: You need the full Amazon S3 feature set, storage classes, KMS, events, or global regions

    Consider: Amazon S3

    Accept US-group jurisdiction in exchange for catalog depth.

  • When: You want another European S3-compatible cloud without a Hetzner compute relationship

    Consider: Scaleway or OVHcloud

    Compare their object-storage regions, S3 gaps, and contract entities separately.

  • When: You are evaluating Hetzner VMs, bare metal, or the company as a whole

    Consider: Hetzner

    The company page covers IaaS and parks; this page is the bucket SKU only.

  • When: You want a smaller EU cloud with S3-oriented positioning

    Consider: Cyso Cloud

    Verify current regions and S3 compatibility on that product page.

Juridiction et propriété

Entité légale
Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen (HRB 6089 Ansbach)
Maison mère / contrôle US
Aucune maison mère US connue
Exposition CLOUD Act (indicative)
Low
Hébergement / résidence
Object Storage only in Falkenstein, Nuremberg (company-operated DE parks) and Helsinki (Hetzner Finland Oy for building rental and technical support). Entire bucket stays in the selected single data center on Hetzner Ceph. No US or Singapore object-storage region. Group still has Hetzner US LLC, Hetzner Singapore Pte. Ltd., and US/SG colocation partners for other Cloud server products. Customer master data stays in the EU per Hetzner docs.

No known US parent. Exposure scored low for this SKU because object data has no US-group storage backend and no US region. Score is still not a clean bill: Hetzner publishes US/SG subsidiaries for other products and says a zero-US-connection buyer should look elsewhere. CLOUD Act row is partial. Indicative only, not legal advice.

  • Independent security / no-logs auditNot applicable
  • ISO 27001Verified
  • SOC 2 / SOC 3Not found
  • GDPR / EU data protectionVendor claimed
  • +4

Considerations & known limitations

  • MediumPartial S3 compatibility

    Supported-actions list omits website hosting, notifications, inventory, replication, custom domains, SSE-KMS, and more. CopyObject may fail even in one location. Apps that assume full AWS S3 will break.

  • MediumHDD tier, not a CDN

    Standard HDD only, no archive or flash classes. Hetzner says it is a poor fit for high-frequency small objects, low-latency apps, and large-scale public HTTP. Plan a CDN or different storage for those cases.

  • MediumNo default at-rest encryption

    Objects are not encrypted at rest unless you use SSE-C and keep the key. Lost keys are unrecoverable. SSE-C copy is unsupported.

  • MediumSingle data center, no built-in replication

    A bucket lives in one DC. There is no first-party cross-location replication. You must build DR yourself if one park outage is unacceptable.

  • MediumShared-cluster load and 503s

    Vendor docs describe cluster growth, bucket migrations, and temporary concurrency or upload limits (including 503 in Nuremberg under load). Shared tenancy can affect latency.

  • LowGroup US and Singapore entities

    This SKU is EU-only, but Hetzner Online GmbH has US and Singapore subsidiaries for other Cloud locations. Zero-US-footprint procurement may still reject the vendor.

Open questions for due diligence

  • Does your auditor accept Hetzner's park-level ISO 27001 and cloud C5 Type 2 for this object-storage SKU without a SKU-specific statement of applicability?
  • Can your application live with the documented S3 gaps (no events, website, KMS, replication, custom domain)?
  • Is a single data center per bucket acceptable, or do you need first-party multi-site replication?
  • Will you operate SSE-C key management yourself, or do you require provider-managed at-rest encryption?
  • Does group presence of Hetzner US LLC block you even if buckets stay in DE/FI?

Questions Fréquemment Posées

It is marketed as S3-compatible with Signature Version 4 and works with AWS CLI, boto3, and similar tools when you set the Hetzner endpoint and region (fsn1, nbg1, or hel1). The supported-actions list documents material gaps: no bucket website, notifications, inventory, analytics, intelligent tiering, logging, metrics, tagging, replication, request payment, custom domains, CreateSession, or Restore/Select. Encryption is SSE-C only. CopyObject can fail even inside one location. Treat it as basic S3 for backups and blobs, not a drop-in for every AWS S3 feature.

Yes for placement: choose Falkenstein (fsn1) or Nuremberg (nbg1). Helsinki (hel1) is in Finland (EU/EEA). Docs say the entire bucket is stored in the selected location in a single data center. There is no built-in replication to another location; you would sync yourself with a tool such as rclone. Bucket names are unique across all Hetzner Object Storage locations. Helsinki uses Hetzner Finland Oy as a published subprocessor for building rental and support.

No, according to Hetzner. The FAQ says the product is HDD-backed, optimized for objects around 1 MB and larger, and is not a CDN. Direct public HTTP to thousands of clients, high-frequency tiny files, and latency-sensitive databases are called out as poor fits. Use block volumes or a dedicated database for those, and put a third-party CDN in front if you must serve a large audience. Shared clusters can return 503 under heavy concurrent uploads.

Create HMAC access and secret keys in Hetzner Console. Keys are valid for every bucket in the project unless you restrict them with bucket policies or separate projects. There is no default at-rest encryption. SSE-C requires you to supply and retain a 32-byte key; Hetzner says it does not store that key. Object lock must be enabled when the bucket is created. Public buckets allow anonymous reads; writes still need keys.

The contract partner is still Hetzner Online GmbH. Accept the standard Art. 28 DPA in the customer account (no custom wet-ink DPA). ISO/IEC 27001:2022 and BSI C5 Type 2 are published at company and cloud-service level for the DE/FI parks; confirm the current certificate scope with your auditor for this SKU. The approved-subcontractor PDF lists Hetzner Finland Oy for Finland and US/Singapore entities that apply to other products, not to this EU-only object store.