A vault for the files you will still need in five years.
Contracts, masters, raw scans, the archive nobody can afford to lose. StashFiles encrypts them before they leave your machine, keeps every version, and refuses to delete anything that is under retention — including when we are the ones asked to.
Hosted on hardware we own, in Helsinki and Frankfurt. No hyperscaler underneath.
archive-2026
| Name | Size | Versions | Modified |
|---|---|---|---|
| PDF master-service-agreement.pdf held | 2.4 MB | 7 | 12 Aug |
| MOV gala-2026-master.mov | 184 GB | 2 | 09 Aug |
| TIF scans-folio-01..240.tif | 61.8 GB | 1 | 04 Aug |
| ZST pg-nightly-2026-08-14.zst | 9.1 GB | 31 | 14 Aug |
| DIR raw-camera-cards/ | 1.2 TB | — | 02 Aug |
| PDF insurance-schedule-2026.pdf held | 840 KB | 3 | 28 Jul |
Storage that behaves like a filing cabinet, not a shoebox.
Every design decision here comes from the same question: in three years, when somebody asks for the version of this file that existed last Tuesday, can you produce it?
Versioning that is on by default
Overwrites never destroy. Every write creates a new version with its own hash, and you can restore or download any of them from the same URL with a query parameter.
Retention we cannot override
Object lock is enforced in the storage layer, below our own control plane. Once a file is under a compliance hold, no administrator account — ours included — can remove it before the window closes.
S3-compatible endpoint
Point rclone, restic, Veeam or the AWS SDK at s3.stashfiles.lol and it works. Multipart, presigned URLs, lifecycle rules and bucket policies all behave the way you expect.
Erasure coded, three sites
Objects are split 12+4 across independent racks in two data centres, with an asynchronous third copy on cold media. Losing a full site costs you nothing but a rebuild window.
An audit log you can export
Reads, writes, key rotations and share links, each with actor, address and object version. Streamed to your bucket or your SIEM as newline-delimited JSON.
Restores are rehearsed
A monthly job pulls a random sample of objects, verifies checksums against the manifest and mails you the report. Backups you have never restored are not backups.
We would rather not be able to read your files.
Keys are generated in your browser or your client, wrapped with a passphrase we never receive, and stored only in wrapped form. A subpoena served on us produces ciphertext and metadata — which is exactly the point.
- AES-256-GCM per object, with a fresh data key derived from your vault key on every write.
- Argon2id for passphrase stretching, tuned to a second of work on a modern laptop.
- Recovery you control. Print the recovery key at setup; lose it and nobody, us included, gets the vault back.
- Warrant canary updated on the first working day of every month on our status page.
passphrase → Argon2id → vault key
AES-256-GCM, fresh data key per write
Helsinki · Frankfurt · cold third copy
object size, timestamps, version hash — nothing else
One price per terabyte. Egress included.
No request charges, no retrieval tiers, no bill that triples the month you actually need your data back.
Keep
One vault, one person, everything encrypted.
- Unlimited versions, 90-day history
- S3 endpoint and web access
- Egress up to 2× stored volume
Hold
Shared vaults, retention policy and audit export.
- Object lock and legal hold
- Unlimited seats and access keys
- Audit log streaming and webhooks
- Monthly restore verification report
Attest
Dedicated pool, signed reports, your auditors welcome.
- Single-tenant storage pool
- DPA, sub-processor list, SLA credits
- On-site audit by arrangement
What people ask before signing up
Why can't I just sign up?
Accounts are opened by hand. We check that there is a real organisation behind the request, agree a retention posture, and only then issue credentials. It is slower, and it is the reason we have never had to run an abuse team.
What happens if I forget my passphrase?
Nothing good. The recovery key printed at setup is the only other way in, and we do not hold a copy. This is an unusual property for a cloud service and it is deliberate — but plan for it.
Can I migrate off?
Yes, and we will help. The endpoint is S3-compatible, so rclone sync is the whole migration. There is no egress charge for a documented exit, and we keep no copies once you confirm the move.
Who else touches the data?
Nobody. We rent rack space and transit; the servers, the disks and the keys to the cages are ours. The current sub-processor list is two companies — a payment processor and a transactional mail provider — and neither can see object data.
Do you respond to takedown requests?
We respond to lawful orders from Finnish and German authorities, and we publish counts in our transparency report. Because content is encrypted client side, what we can hand over is metadata: object sizes, timestamps and the account behind them.
Put it somewhere you trust.
Tell us what you need to keep and for how long. We will come back with a plan and a quote.