StashFiles
Object lock and legal hold shipped in 2.9

A vault for the files you will still need in five years.

Contracts, masters, raw scans, the archive nobody can afford to lose. StashFiles encrypts them before they leave your machine, keeps every version, and refuses to delete anything that is under retention — including when we are the ones asked to.

Hosted on hardware we own, in Helsinki and Frankfurt. No hyperscaler underneath.

app.stashfiles.lol/vault/archive-2026

archive-2026

Filter Upload
NameSizeVersionsModified
PDF master-service-agreement.pdf held2.4 MB712 Aug
MOV gala-2026-master.mov184 GB209 Aug
TIF scans-folio-01..240.tif61.8 GB104 Aug
ZST pg-nightly-2026-08-14.zst9.1 GB3114 Aug
DIR raw-camera-cards/1.2 TB02 Aug
PDF insurance-schedule-2026.pdf held840 KB328 Jul
Platform

Storage that behaves like a filing cabinet, not a shoebox.

Every design decision here comes from the same question: in three years, when somebody asks for the version of this file that existed last Tuesday, can you produce it?

Versioning that is on by default

Overwrites never destroy. Every write creates a new version with its own hash, and you can restore or download any of them from the same URL with a query parameter.

Retention we cannot override

Object lock is enforced in the storage layer, below our own control plane. Once a file is under a compliance hold, no administrator account — ours included — can remove it before the window closes.

S3-compatible endpoint

Point rclone, restic, Veeam or the AWS SDK at s3.stashfiles.lol and it works. Multipart, presigned URLs, lifecycle rules and bucket policies all behave the way you expect.

Erasure coded, three sites

Objects are split 12+4 across independent racks in two data centres, with an asynchronous third copy on cold media. Losing a full site costs you nothing but a rebuild window.

An audit log you can export

Reads, writes, key rotations and share links, each with actor, address and object version. Streamed to your bucket or your SIEM as newline-delimited JSON.

Restores are rehearsed

A monthly job pulls a random sample of objects, verifies checksums against the manifest and mails you the report. Backups you have never restored are not backups.

Security

We would rather not be able to read your files.

Keys are generated in your browser or your client, wrapped with a passphrase we never receive, and stored only in wrapped form. A subpoena served on us produces ciphertext and metadata — which is exactly the point.

  • AES-256-GCM per object, with a fresh data key derived from your vault key on every write.
  • Argon2id for passphrase stretching, tuned to a second of work on a modern laptop.
  • Recovery you control. Print the recovery key at setup; lose it and nobody, us included, gets the vault back.
  • Warrant canary updated on the first working day of every month on our status page.
Your machine
passphrase → Argon2id → vault key
Object sealed locally
AES-256-GCM, fresh data key per write
Stored 12+4 erasure coded
Helsinki · Frankfurt · cold third copy
What we can see
object size, timestamps, version hash — nothing else
11 ninesDesigned object durability
99.99%Availability, trailing 12 months
2 DCOwned racks, EU only
0Objects lost since 2021
Pricing

One price per terabyte. Egress included.

No request charges, no retrieval tiers, no bill that triples the month you actually need your data back.

Personal

Keep

€4 / TB / month

One vault, one person, everything encrypted.

  • Unlimited versions, 90-day history
  • S3 endpoint and web access
  • Egress up to 2× stored volume
Request an account
Business

Hold

€9 / TB / month

Shared vaults, retention policy and audit export.

  • Object lock and legal hold
  • Unlimited seats and access keys
  • Audit log streaming and webhooks
  • Monthly restore verification report
Request an account
Regulated

Attest

Custom

Dedicated pool, signed reports, your auditors welcome.

  • Single-tenant storage pool
  • DPA, sub-processor list, SLA credits
  • On-site audit by arrangement
Talk to us
Questions

What people ask before signing up

Why can't I just sign up?

Accounts are opened by hand. We check that there is a real organisation behind the request, agree a retention posture, and only then issue credentials. It is slower, and it is the reason we have never had to run an abuse team.

What happens if I forget my passphrase?

Nothing good. The recovery key printed at setup is the only other way in, and we do not hold a copy. This is an unusual property for a cloud service and it is deliberate — but plan for it.

Can I migrate off?

Yes, and we will help. The endpoint is S3-compatible, so rclone sync is the whole migration. There is no egress charge for a documented exit, and we keep no copies once you confirm the move.

Who else touches the data?

Nobody. We rent rack space and transit; the servers, the disks and the keys to the cages are ours. The current sub-processor list is two companies — a payment processor and a transactional mail provider — and neither can see object data.

Do you respond to takedown requests?

We respond to lawful orders from Finnish and German authorities, and we publish counts in our transparency report. Because content is encrypted client side, what we can hand over is metadata: object sizes, timestamps and the account behind them.

Put it somewhere you trust.

Tell us what you need to keep and for how long. We will come back with a plan and a quote.

Sign in to open a vault

Vaults are unlocked with your passphrase in the browser. If you do not have an account yet, tell us about your use case and we will set one up.