Logo: Leafcloud Object Storage

Leafcloud Object Storage

Dutch S3-compatible object storage from Leafcloud B.V. Ceph-backed buckets in Amsterdam via leafcloud.store, plus OpenStack Swift, for backups, app data, and public objects.

Leafcloud Object Storage is the S3-compatible object store of Leafcloud B.V., a Dutch public-cloud operator in Amsterdam. It is a managed bucket service for files, backups, logs, and application objects. You reach it at https://leafcloud.store with region europe-nl-ams1 (path-style URLs), or through the native OpenStack Swift API and the create.leaf.cloud dashboard.

The product exists for teams that want a familiar S3 client path without putting buckets under a US hyperscaler account. Persistent objects stay in the Netherlands at what Leafcloud calls its Amsterdam Core facility. Compute on the same platform may run at distributed Leaf sites that reuse server heat in buildings. The vendor states that object data is not stored at those sites.

The concrete differentiator is a Ceph-backed store with 3x replication, documented S3 compatibility (including SSE-C), a public ISO/IEC 27001:2022 certificate, and a standard DPA that says Leafcloud does not use subprocessors for customer data in core compute, storage, and networking. Object versioning is not enabled on the cluster today.

S3-compatible (leafcloud.store)Amsterdam residencyCeph 3x replicationISO 27001 (public cert)Public DPANo object versioning

Shortlist Leafcloud Object Storage when you want an S3-compatible Ceph bucket in Amsterdam under Leafcloud B.V., with a public ISO 27001 certificate and a downloadable DPA. Skip when you need object versioning, multi-region replication, or AWS-parity S3 features. Consider Cyso Cloud for Dutch OpenStack storage with versioning and a Frankfurt option, or OVHcloud / Scaleway for a wider EU region map.

Key capabilities

Path-style S3 endpoint https://leafcloud.store, region europe-nl-ams1. Works with AWS CLI, boto3, rclone, Cyberduck, MinIO mc, and other S3 SDKs. Documented features include public or private containers, bucket policies and ACLs, multipart uploads, and presigned URLs. Max object size is 5 TB via multipart. Authentication uses OpenStack EC2 credentials (openstack ec2 credentials create), not the dashboard password.

The same store is reachable as OpenStack object storage (Swift). Create and browse containers at create.leaf.cloud under Object Store. Native CLI uses project-scoped OpenStack auth (openstack container create / object create). Container names must be unique across all Leafcloud users. Docs say there is a limit on how many containers you can create (the exact quota is not published).

The product page describes a Ceph backend (Apache 2.0 software) with triple replication across separate physical nodes in Amsterdam. Persistent objects sit at the Core facility. Compute Leaf sites are a different path and are not where object data is stored, according to the security pages. This is a single-region store, not a multi-region S3 deployment.

Official docs show S3 server-side encryption with customer-provided keys (SSE-C, AES256). Leafcloud uses the key on each request and does not store it. Lose the key and you cannot read the object. The product table also lists encryption at rest and TLS in transit as supported. DPA language is TLS 1.2+. LUKS-by-default messaging on the security pages refers to block volumes, not this object API.

Leafcloud publishes working recipes for Terraform’s S3 backend (path-style, skip checksum/region checks, endpoint leafcloud.store), Velero Kubernetes backups (s3ForcePathStyle plus s3Url), and Nextcloud primary objectstore pointing at leafcloud.store:443. Useful if you already run those tools. Object versioning is not available, so state and backup designs must version keys themselves or copy out.

A colpo d'occhio

Legal entity
Leafcloud B.V., Amsterdam; KvK 78564417
S3 endpoint
https://leafcloud.store (region europe-nl-ams1, path-style)
Backend
Ceph; also OpenStack Swift / Horizon
Residency
Amsterdam Core, Netherlands (single region)
Commercial model
Pay for stored capacity; B2B invoicing; vendor states no API request fees
Hard limit
No object versioning; max object 5 TB

Best fit when

  • Teams that need an S3-compatible endpoint and OpenStack Swift in one Dutch account
  • Amsterdam-only residency designs that can live without bucket versioning
  • Velero, Terraform state, or Nextcloud setups that already use path-style S3 clients
  • Buyers who want a public ISO 27001 PDF and a standard DPA before a sales call
  • Organisations that may later add Leafcloud VMs or GPUs in the same jurisdiction

Poor fit when

  • Workloads that require S3 versioning, object lock, or cross-region replication
  • Multi-region or in-country-outside-NL residency (this store is Amsterdam only)
  • Procurement that needs a named Core colocation operator and a full ancillary subprocessor register on day one
  • Consumer or free-tier only use (terms position Leafcloud as B2B)
  • Designs that assume AWS IAM, KMS, or inventory/analytics feature parity

Consider instead when

  • When: You need Dutch or German OpenStack object storage with versioning and more than one EU region

    Consider: Cyso Cloud

    Cyso documents AMS and FRA and lists versioning, lifecycle, and object lock on object storage.

  • When: You need many European locations and a larger IaaS catalogue than a single Amsterdam Ceph cluster

    Consider: OVHcloud or Scaleway

    Broader region maps; different APIs, SLAs, and ownership stories.

  • When: German locations and a large self-serve European hosting catalogue matter more than OpenStack Swift

    Consider: Hetzner

    Compare object storage vs Storage Box features and residency independently.

  • When: Swiss multi-zone IaaS with S3-compatible storage is the sovereignty filter

    Consider: Exoscale

    Different legal seat (Switzerland) and product mix.

  • When: You depend on versioning, replication, IAM, and KMS that only the hyperscaler S3 estate provides

    Consider: Amazon S3 (or Google Cloud Storage)

    Trade EU ownership for feature depth. Apply your own CLOUD Act analysis.

Giurisdizione e proprietà

Soggetto giuridico
Leafcloud B.V., Amsterdam (KvK 78564417). Site: Science Park 400. DPA/ISO: Overhoeksplein 2.
Capogruppo / controllo USA
Nessuna capogruppo USA nota
Esposizione CLOUD Act (indicativa)
Low
Hosting / residenza
Objects at Amsterdam Core (europe-nl-ams1), Ceph 3x. DPA (Jan 2026): no subprocessors for core compute/storage/networking; no third-country transfers unless customer-instructed. Terms mention EU partner data centres; Core operator unnamed. Privacy allows unnamed account-data suppliers (invoicing, messaging). Site analytics: self-hosted Matomo. Not AWS/GCP/Azure-hosted.

Vendor states Dutch ownership, European investors, and no US parent. Not independently verified against a shareholder register. CLOUD Act row is a EuropeanStack assessment, not a vendor certification. Indicative only, not legal advice.

  • Independent security / no-logs auditNot found
  • ISO 27001Verified
  • SOC 2 / SOC 3On request / NDA
  • GDPR / EU data protectionVendor claimed
  • +4

Considerations & known limitations

  • HighObject versioning disabled

    The product table states versioning is not enabled. Overwrites and deletes are not recoverable via S3 versions. Unsafe as a sole Terraform-state or backup target unless you version keys yourself or replicate out.

  • MediumAmsterdam-only region

    One S3 region (europe-nl-ams1). No documented cross-region replication. Multi-country DR or non-NL residency needs another provider.

  • MediumBaseline SLA is a non-binding target

    Terms target more than 99.9% monthly availability without credits on the baseline SLA. Customers must keep their own backups. Premium SLA only if agreed in writing.

  • MediumCore facility operator not named

    DPA says no core subprocessors. Terms mention partner data centres. Public pages do not name the Tier III Core operator. Request that name in contracting.

  • LowIncomplete S3 feature parity

    Custom domains are support-gated. Static hosting is basic. Do not assume lifecycle, object lock, or inventory APIs without a proof of concept.

Open questions for due diligence

  • What is the current registered office on the KvK extract (Science Park 400 vs Overhoeksplein 2)?
  • Who operates the Amsterdam Core / partner data centre, and is that party listed as a subprocessor for physical hosting?
  • Can Leafcloud provide a dated list of ancillary processors (billing, support, email) used for account data?
  • Is there a committed date or paid option to enable Ceph/S3 versioning?
  • What contractual availability, durability, and deletion timelines apply to object storage under a Premium SLA versus the baseline terms (14-day vs 90-day deletion language differs between T&Cs and DPA)?

Domande Frequenti

The product feature table states versioning is not currently enabled on the Ceph cluster. Enabling it is described as an infrastructure change that typically takes 4 to 8 weeks if they agree to do it. The same table lists custom domains as contact support, and static website hosting as basic support. Bucket policies, ACLs, multipart uploads, and presigned URLs are listed as supported. Do not assume AWS-parity lifecycle, object lock, or inventory features unless you have tested them on a trial bucket.

Objects are stored in the Netherlands at Leafcloud’s Amsterdam Core (S3 region europe-nl-ams1). The January 2026 DPA says Leafcloud does not use subprocessors for customer data inside core compute, storage, and networking, and that it does not transfer personal data outside the EEA unless you instruct it or law requires it. Terms still mention partner data centres in the EU and subcontractors. The Core colocation operator is not named. The privacy policy also allows unnamed suppliers for invoicing, messaging, and similar account processing. Ask for a dated annex if you need a full inventory.

Dashboard credentials and S3 credentials are different. Horizon login will not authenticate the S3 API. Create EC2-style keys with openstack ec2 credentials create, then set the access key, secret, endpoint https://leafcloud.store, region europe-nl-ams1, and path-style addressing. The secret is shown once. This split is the most common integration failure called out on the product FAQ.

Capacity is metered. You pay for what you store. The vendor states there is no minimum commitment, that PUT/GET style API calls are included, and that data transfer inside Leafcloud infrastructure is not charged as egress. A Fair Use Policy in the terms can still throttle or restrict use that harms the platform. Billing is B2B (invoices, VAT extra, 30-day payment terms in the T&Cs). Confirm current rates and any FUP thresholds on the official pricing page before procurement.

Object storage is a standalone product SKU with its own endpoint. You do not have to run VMs on Leafcloud to use buckets. The same legal entity also sells OpenStack VMs, GPUs, Kubernetes, networking, and block storage if you want compute in the same jurisdiction. This catalog page evaluates the object store, not the full IaaS catalogue.

A standard DPA is published as a PDF and, according to that PDF, applies automatically (custom terms on request). A public ISO/IEC 27001:2022 certificate from ProCertify is downloadable from the compliance page. SOC 2 Type II is claimed; the report is request-under-NDA via hello@leaf.cloud. HAVEN+ is in progress, not certified. Treat CLOUD Act statements on the marketing site as vendor position, not an independent legal opinion.