---
title: "Keep the data in your own bucket"
description: "For a compliance-heavy buyer, \"the data never leaves an account we control\" is often the only acceptable shape. It is also the highest-margin thing we can sell, and those two facts are not in tension."
url: "https://saved.sh/blog/own-your-bucket"
date: "2026-08-02"
author: "saved.sh"
tag: "Security"
---

There is a question that ends backup vendor evaluations at regulated companies,
and it usually arrives about twenty minutes in:

> Does the data leave our cloud account?

For most vendors the honest answer is yes, and the conversation is effectively
over regardless of how good the product is. Encryption helps. It does not always
help enough, because the requirement is frequently about custody and jurisdiction
rather than confidentiality.

## Point it at your own storage [#point-it-at-your-own-storage]

<Figure caption="Two destinations sit inside our custody and are billed as stored bytes. The third does not, and is not.">
  <DestinationsFan />
</Figure>

An artifact can land in several destinations at once. Our primary storage, our
storage at a second provider, and a bucket you own in an account you control.

On the third, we orchestrate, verify and track every run, and we store nothing.
The bytes go from your machine to your bucket. What you are buying is the
scheduling, the encryption boundary, the retention policy and the run history,
which is the part that is actually hard.

## The incentives, stated out loud [#the-incentives-stated-out-loud]

This is the highest-margin thing we can sell, because it removes our largest
recurring cost. We are telling you that because it is the reason to trust the
offer rather than a reason to doubt it.

<Aside title="Where a vendor's incentives usually point">
  Most storage-backed products want your bytes on their infrastructure, because
  storage is the recurring revenue. A vendor offering to hold none of your data is
  either confused about their business model or selling you something other than
  storage. We are selling something other than storage.
</Aside>

<Stats>
  <Stat value="0" label="Bytes we store on this path" />

  <Stat value="0" unit="USD" label="Charged by us for that storage" />

  <Stat value="1" label="Procurement objection this removes entirely" />
</Stats>

## Secondary is not a cold tier, deliberately [#secondary-is-not-a-cold-tier-deliberately]

The middle option deserves a note, because it looks like a place to save money
and is not.

A secondary copy lives at a different provider, and it is ordinary storage rather
than a cold or archival class. Cold tiers charge for retrieval, and the deep ones
charge heavily, so a single legitimate disaster-recovery restore can cost more
than a year of storage.

That cost does not track anything we would bill you for, because a retrieval fee
is a function of the storage class rather than of the bytes moved. What secondary
sells is provider independence: if one provider has a bad day, or a bad year, the
copy is somewhere else.

## What you still get [#what-you-still-get]

Everything except the storage:

* Encryption applied on your machine with your key, unchanged
* Retention enforced against your bucket, under a hold you cannot later shorten
* A run history you can audit, with sizes and checksums
* The same artifact format, restorable by hand with no vendor involved

<Aside title="The trade, so you can weigh it" tone="accent">
  You take on the bucket. Its lifecycle policy, its access controls, its bill and
  its regional configuration are yours, and a misconfiguration there is not
  something we can see or fix for you. That is the actual cost of custody, and
  anyone who tells you custody is free is selling something.
</Aside>

## Which one to pick [#which-one-to-pick]

If nobody is asking where the data lives, use our primary storage. It is simpler,
and simpler is worth something.

If somebody is asking, the answer is available, and it does not cost you features
to take it.
