Last Updated on August 25, 2026 by Mat Diekhake
Security overview
Scaleway Object Storage is part of Scaleway, a long‑established European cloud provider backed by the Iliad Group (one of Europe’s largest telecom operators). The platform has a strong security posture, including modern encryption, hardened EU‑based infrastructure, and transparent operational practices. As an S3‑compatible storage service, its protections are significantly more robust than typical consumer hosting.
SSL/TLS & encryption
The Scaleway Object Storage pages (scaleway.com/object-storage and related console/API endpoints) use HTTPS with a valid TLS certificate issued by a major certificate authority. Connections enforce modern TLS versions, strong cipher suites, and secure session handling.
Scaleway Object Storage supports:
- Encryption in transit (TLS 1.2/1.3)
- Encryption at rest
- Customer‑managed keys via Scaleway KMS
- S3‑compatible signed URLs
- Bucket‑level access controls and IAM policies
This ensures both web interactions and storage operations are protected from interception.
Hosting & infrastructure
Scaleway operates its own physical data centers across Europe, with a strong emphasis on transparency and sustainability:
- Paris (DC2, DC3, DC4)
- Amsterdam
- Warsaw
Infrastructure protections include:
- ISO‑aligned data‑center operations
- Redundant power and cooling
- Enterprise‑grade load balancing
- DDoS protection
- Hardened physical access controls
- 24/7 monitoring and incident response
Scaleway is known for publishing detailed information about its data centers and energy usage, which is rare among mid‑market cloud providers.
Malware & phishing scan
Reputation checks show:
- No malware detected
- No phishing flags
- No suspicious redirects
- No unauthorized third‑party scripts
Scaleway is not associated with malware distribution or phishing activity. The most common threat is fake Scaleway login pages created by attackers — not the real scaleway.com domain.
Privacy & data handling
Scaleway Object Storage collects:
- Account and identity information
- Billing and subscription data
- Usage analytics
- Storage metadata
- Device and browser information
Tracking is limited to:
- First‑party cookies
- Standard analytics
- Optional integrations with other Scaleway services
Scaleway does not sell user data and follows strict GDPR requirements, with all storage hosted in EU‑based facilities.
App permissions (if applicable)
Scaleway’s CLI and management tools may request:
- Network access (for cloud operations)
- File access (for configuration files and uploads)
- Notifications
Permissions match the intended functionality and are not excessive.
Breach history
Scaleway has no major public data breaches involving customer data. Minor service incidents have occurred historically, but none related to data exposure.
Its long operating history (since 1999, originally Online.net) and telecom‑grade backing contribute to its strong trust profile.
Security certifications
Scaleway’s certification footprint includes:
- GDPR compliance
- ISO‑aligned data‑center operations
- Regular third‑party security audits
- Transparent infrastructure documentation
While not as broad as hyperscale providers (AWS/Azure/GCP), Scaleway’s compliance posture is strong for an EU‑centric cloud platform.
Final safety verdict
Scaleway Object Storage is safe to use. It employs strong encryption, hardened EU‑based infrastructure, S3‑compatible access controls, and has no known breach history. For regulated workloads requiring strict certifications, hyperscale clouds may offer broader compliance; for mainstream storage needs, Scaleway Object Storage’s security posture is robust, transparent, and trustworthy.
