Skip to main content
Support
0
Contact us
Nederlands
Deutsch
Español
Dedicated serversFlexible VPSCloud TechnologyColocationChallenges in ITSectorsCareers
Cloud Compute

With Cloud Compute, you have access anytime and anywhere to a portal through which you can configure your entire IT environment from wherever you are in the world.

Cloud Storage

Reliable access to your files, infrastructure, and applications at all times – with no interruptions or delays. At Worldstream, we offer a variety of storage solutions.

Flexible cloud icon
Flexible cloud
Private cloud icon
Private cloud
Bare metal icon
Bare Metal Compute
Hollow cube icon
Object storage
Hollow cube icon
File storage
Block storage icon
Block storage
Backup storage icon
Backup storage
Need support?

With experienced engineers and an average response time track record on 7 minutes, you can expect a solid technical support solution in next to no time.

All Servers

Choose your Dedicated Server now. Custom or Instant Delivery. Powerhouse servers built for your use case.

Use Cases

Whatever your use case, we’re here to help you find the ideal solution.

Deal servers icon
Deals
AMD servers icon
AMD Processors
AI servers icon
Intel Processors
Hollow cube icon
Virtualisation, Containerisation and Orchestration
Hollow cube icon
Websites and Applications
Hollow cube icon
Gaming and Streaming Infrastructure

24/7/365 support with an average response time of just 7 minutes. Thanks to our own data centers, our engineers can go directly to your server for fast, hands-on assistance. Email or call us anytime.

Smart outsourcing

Some IT creates added value, while other types are supportive. Use that as a starting point for outsourcing.

Cost Efficiency

Complete IT packages may seem like the safe option, but when you consider the costs, other choices often make more sense.

IT flexibility & control

Outsourcing doesn’t mean losing control; it actually provides more flexibility and control.

Cloud repatriation

The cloud is not a final destination: You should continuously evaluate and adjust your cloud environment as needs evolve.

Financial services
Logistics & Transportation
Retail & E-commerce
Media & Entertainment
Tech & Software Development
Security
Managed Service Providers
Need support?

With experienced engineers and an average response time track record on 7 minutes, you can expect a solid technical support solution in next to no time.

Chat with usContact us
About WorldstreamAbout the technologyCasesKnowledge base
About usMeet the teamJobsBecome a resellerCertificationsOur data centersOur networkDDoS ProtectionAMD EPYC serversTechnology PartnersOperating SystemsAll casesEasyTerraDutch Drone CompanyPerfGridArticlesFAQNews and BlogsProducts and Services
Contact us

Call +31 (0) 174 – 712 117

Industriestraat 53, Naaldwijk

Nederlands
Deutsch
Español
0
Dedicated serversFlexible VPSCloud TechnologyColocationChallenges in ITSectorsCareersAbout WorldstreamAbout the technologyCasesKnowledge baseMy Worldstream
Contact
Support
NederlandsDeutschEspañol
  1. HomeHome
  2. Knowledge Base
  3. Storage
  4. Securing and controlling access to your object storage

Securing and controlling access to your object storage

Applies to Object StorageAudience Technical evaluator, existing customerLast reviewed September 2026

Quick answer

Object storage security rests on three separate ideas: encryption of the data itself, control over who can access it, and, separately, locking specific data so it can't be changed or deleted no matter who asks. Worldstream's Object Storage supports Object Lock, a write-once setting you turn on when you create a bucket. The rest of this article explains how the three fit together.

Encryption at rest

Server-side encryption means the storage platform encrypts your data as it's written and decrypts it again as it's read back, without you having to encrypt anything on your end first. It protects the data sitting on disk: if a drive were somehow removed or accessed outside the normal API path, the contents would be unreadable without the encryption key. Most S3-compatible object storage platforms apply this by default, transparently, so ordinary reads and writes through the S3 API don't change at all.

A variant worth knowing about is customer-provided-key encryption, sometimes called SSE-C. Instead of relying entirely on the provider's own key management, you supply your own encryption key with each request, and the platform uses that key rather than one it manages internally. That gives you more direct control over the key material, but it comes with a real responsibility: if you lose your key, the provider generally can't recover the data for you, because they never held a copy of it.

Access control: policies, ACLs and pre-signed URLs

Encryption protects data at rest; access control decides who's allowed to read, write, or list it in the first place. On S3-compatible platforms this usually takes two forms. Bucket policies and object-level access control lists (ACLs) define permissions declaratively, who or what can perform which actions against a bucket or an individual object, and they're the mechanism you'd use to keep a bucket private by default or open specific parts of it deliberately.

Pre-signed URLs solve a narrower, common problem: letting someone outside your organisation download or upload a single object without handing them your actual credentials. A pre-signed URL grants temporary, time-limited access to one specific object. It expires on its own, so there's no standing credential to revoke afterwards, which makes it a convenient way to share one file, an invoice, an export, an installer, without opening up broader account access.

Legal hold vs. Object Lock: two different locks

It's easy to conflate these because they both stop data from being changed, but they're not the same mechanism.

A legal hold, as a general concept on S3-compatible platforms, is an indefinite lock placed on an individual object. It overrides whatever retention or lifecycle rule would otherwise apply to that object, and it stays in force until someone with the right permissions explicitly removes it, typically for a compliance or e-discovery reason rather than a storage-management one.

Worldstream's Object Lock feature is a different thing. It's a write-once (WORM) setting applied at the bucket level, turned on when you create the bucket, and it cannot be disabled again once the bucket exists. That makes it a decision you take upfront, per bucket, rather than something you switch on later. If your use case needs per-object legal holds specifically, rather than a bucket-wide write-once guarantee set at creation time, check with Worldstream support first.

MechanismScopeTypical purpose
Object Lock (Worldstream Object Storage)Whole bucket, set at creationWrite-once (WORM) protection you commit to upfront
Legal hold (general concept)Individual object, applied and removed as neededIndefinite lock overriding retention, usually for compliance reasons

Related articles

  • What is Object Storage?
  • Object storage lifecycle rules and storage tiering: automating hot-to-cold data
  • Why you can't FTP or mount into S3-compatible object storage
Was this article helpful?

Solid IT. No Surprises

Sparring partner for IT maturity
Eliminating barriers so you can run
Predictable and transparant costs

Contact

  • Industriestraat 53, Naaldwijk
  • Payment Methods
  • Abuse
  • Developers Resources
  • Network Operations Center
  • About us
  • Meet the team
  • Jobs
  • Become a reseller
  • Certifications
  • Our data centers
  • Our network
  • DDoS Protection
  • AMD EPYC servers
  • Technology Partners
  • Operating Systems
  • Overview
  • FAQ
  • Cases
  • News & Blogs
  • Use Cases
Nederlands
Deutsch
Español
Nederlands
Deutsch
Español
  • Legal
  • Disclosure