Skip to main content

SinonStore — S3-Compatible Object Storage You Can Audit, Recover and Govern

Self-hosted, S3-compatible storage with a SHA-256 hash-chained audit log, DLP scanning with quarantine, ransomware shield, point-in-time recovery, compliance vault, cross-tenant ACL approvals with delegation, and an access heatmap with drill-down and CSV/JSONL export. Built for compliance and SOC teams who need to prove what happened to every object.

Works with the AWS CLI, every AWS SDK, MinIO Client, rclone, and any S3-compatible tool. Zero vendor lock-in. We never access, mine, or sell your data.

Explore Features Deployment Options

Platform at a Glance

Object storage with the audit, governance and recovery primitives that compliance and SOC teams actually need.

12

Enterprise Features

Audit chain, DLP, ransomware shield, vault, tiering, ACL approvals…

100%

S3 API Compatible

Drop-in replacement for Amazon S3

6

Deployment Modes

Bare metal to air-gapped, with atomic upgrades

256

Hash-Chained Audit

SHA-256 linked entries, end-to-end verifiable

2

Encryption Modes

SSE-S3, SSE-C (SSE-KMS coming soon)

Core Storage Features

Full S3 API compatibility with the features organisations depend on for production workloads.

📦

S3-Compatible API

Buckets, objects, multipart uploads, presigned URLs, object ACLs, bucket policies, tagging, lifecycle rules, CORS, and event notifications. Works unmodified with the AWS CLI, AWS SDKs, MinIO Client and rclone.

🔒

Server-Side Encryption

Two live encryption modes: SSE-S3 (managed keys) and SSE-C (customer-provided keys), with SSE-KMS (key management service) coming soon. AES-256 at rest with per-object key wrapping.

💾

Object Versioning

Multiple object versions with version-specific operations. Recover from accidental deletions or overwrites. Lifecycle rules for version expiration and tier transitions.

🔐

Object Locking (WORM)

Compliance and governance retention modes with per-object retention dates and indefinite legal holds. Helps meet SEC 17a-4, FINRA and other regulatory requirements for immutable data.

🌐

Clustered Deployment

Multi-node deployment with gossip-based membership, configurable replication factor, and quorum-based read/write consistency. Per-node health monitoring and graceful node removal.

📦

Atomic Dist Swap Upgrades

Frontend assets are swapped atomically on upgrade. If a build fails to verify, the previous version stays in place: the site keeps serving and there is no half-deployed state for users to land on.

12 Enterprise Security Features

Security capabilities that go far beyond basic object storage, built in, not bolted on.

SHA-256 Hash-Chained Audit Log

Every action (uploads, deletes, ACL changes, approvals, policy edits) is written to a per-tenant audit chain where each entry hash-links to the previous one. Verify the chain end-to-end on demand; any insert, delete or edit shows as a hash mismatch. Filter by event type, actor, resource or date and export the full trail as CSV or JSONL with actor IDs resolved to display names.

DLP Scanning & Quarantine

Built-in and tenant-custom rules scan content on upload. Each violation is recorded with the matched pattern, severity (critical/high/medium/low) and category. Policies run in monitor or block mode and matched objects can be auto-quarantined; operators resolve violations and optionally release the quarantine, all of it audited.

Ransomware Shield

Real-time detection of bulk-delete patterns, bulk-overwrite patterns and anomalous delete-rate spikes against configurable thresholds. Triggered objects are auto-placed into protective holds (default 72 hours) so they can be recovered. Webhook notifications fire on each event and operators can review the threat feed and manually release holds.

Compliance Vault (WORM)

Two retention modes: compliance (cannot be reduced once locked) and governance (admin can extend), plus indefinite legal holds for litigation. Locked policies cannot be modified without an audit-logged unlock. Objects under retention or hold are blocked from deletion until retention expires.

Smart Tiering & Cost Modelling

Lifecycle transitions across Standard, Standard-IA, Glacier and Deep Archive based on last-access time, with prefix and size exclusions. Pluggable cost model (AWS pricing default), daily cost snapshots per storage class, and a preview that shows projected savings before you commit a policy.

Point-in-Time Recovery

Roll any bucket back to a past state, scoped to the whole bucket, a prefix, or a single object. A timeline view shows recovery points within the configurable protection window; preview the change set (what will be restored, deleted or modified) before launching an async recovery job whose status, progress and result are tracked.

Cross-Tenant ACL Approvals & Delegation

Grant object-level access across tenants without sharing credentials. Each request shows the owner the object metadata, DLP violation summary, active quarantine status and recent audit history before they approve or reject. Tenant admins can delegate approval authority to nominated users with explicit valid-from / valid-until windows; every transition is hash-chained into the audit log.

S3 Object Lambda

Transform objects on read with tenant-defined functions: redact PII, convert formats, compress or watermark (resize coming soon). Transformations are transparent to the S3 client and every invocation is logged for audit.

Geo-Fencing & Data Sovereignty

Restrict bucket access by IP geolocation or explicit IP-to-country mappings. Whitelist allowed regions or block specific countries; every blocked request is recorded with source IP, country and the action taken so you can prove residency enforcement.

Batch Operations

S3-style batch jobs across prefixes, tag filters or explicit object lists: copy, tag, and change storage class (batch ACL and retention changes coming soon). Per-item status (succeeded/failed) is tracked, results are written to a manifest bucket and the job report is auditable.

Access Heatmap with Drill-Down

Day-of-week × hour-of-day heatmap of access activity, colour-coded by intensity. Click any cell to see the top users, operations and buckets for that hour, or stream the underlying entries straight out as CSV or JSONL. Usernames are resolved to display names so the export is forensics-ready out of the box.

Enhanced Presigned URLs

Policy-driven presigned URLs with IP whitelists, country whitelists, prefix or per-key scope, expiration, rate limits and per-operation restrictions (GET vs PUT). Token usage analytics (hits, denials and bytes served) are recorded against each token.

Multi-Tenant by Design

Parent / child tenants with quotas, usage tracking and license-tier feature flags. Platform admins manage tenants; tenant admins manage their own users, keys and policies.

Tenant Hierarchy & Quotas

Parent / child tenants with per-tenant quotas for storage, bucket count, object count and API rate limits. Live usage tracking with warning (80%) and critical (95%) thresholds. Ideal for MSPs serving multiple downstream customers from a single platform.

Admin Dashboard

React-based web UI for bucket and user management, cluster topology and health, audit log viewer with chain-integrity status, ACL approval queue, ACL delegation manager, DLP and ransomware feeds, recovery timeline, presigned-URL policies, and the access heatmap with drill-down.

Webhook Notifications

Webhook delivery on ransomware events, DLP violations and policy transitions. Pair with your existing SIEM or ticketing system to escalate threats and approvals without polling.

Six Ways to Deploy

From a single-node developer setup to a distributed production cluster. All deployment modes are production-ready.

Bare Metal

Direct install on Ubuntu, Debian, RHEL, Rocky, or Alma. Automated script handles Node.js, SQLite, Redis, Nginx, TLS, and 5 systemd services.

Docker Compose

Minimal, standard, full, and distributed profiles. Enterprise workers included for DLP, ransomware, tiering, and other background processing.

Kubernetes & Helm

Production Helm chart with standard, HA, and distributed modes. Autoscaling, persistent volumes, and Ingress configuration included.

Cloud VMs

Deploy on AWS EC2, Azure VMs, GCP Compute, or any provider. Same scripts as bare metal with cloud-optimised storage configuration.

Virtual Machines

VMware, Hyper-V, Proxmox, or KVM. Use the bare metal installer inside your virtualisation stack or export pre-built OVA templates.

Air-Gapped

Fully offline installation with pre-packaged Node.js, npm modules, and all dependencies. No internet connectivity required for deployment or operation.

Why Data Ownership Matters

You own every byte stored in SinonStore, whether it runs on your servers or ours. We never access, read, or mine your data.

You Own Your Data

Self-host or let SinonTech host it for you. Either way, you own 100% of your stored objects. Full compliance with GDPR, UK Data Protection Act, and sector-specific residency requirements. Export, migrate, or delete everything at any time.

Predictable Costs

No egress fees, no request charges, no surprise bills. Whether you run SinonStore on your hardware or ours, costs are predictable and transparent. Total cost of ownership you can forecast.

Full Control

You own the encryption keys, the access logs, and the retention policies. We cannot access, read, or share your data, regardless of where SinonStore runs. Full data portability guaranteed.

Technical Specifications

How SinonStore compares to cloud and self-hosted alternatives.

Capability SinonStore Amazon S3 MinIO Azure Blob
Self-HostedYesNoYesNo
Air-Gap SupportYes (built-in)NoManualNo
S3 API CompatibleYes (full)NativeYesPartial (adapter)
DLP ScanningBuilt-inMacie ($)NoPurview ($)
Ransomware ShieldBuilt-inNoNoNo
Compliance VaultBuilt-in (WORM)Object LockObject LockImmutable storage
Object LambdaBuilt-inYes ($)NoNo
Replication & QuorumConfigurable factor + R/W quorumManagedYesManaged
Hash-Chained Audit LogSHA-256, end-to-end verifiableCloudTrail ($)NoActivity log ($)
ACL Approval WorkflowBuilt-in, with delegationNo (manual IAM)NoNo (manual RBAC)
Multi-TenantYes (parent/child + quotas)Via accountsLimitedVia subscriptions
Data SovereigntyBuilt-in geo-fencingRegion selectionManualRegion selection
Egress FeesNonePer GB ($)NonePer GB ($)
Licence CostIncludedPer request + storageFree / Enterprise ($)Per request + storage

Frequently Asked Questions

What is SinonStore?

SinonStore is a self-hosted, S3-compatible object storage platform built around compliance and SOC operations. It ships with a SHA-256 hash-chained audit log, DLP scanning with quarantine, ransomware shield, point-in-time recovery, compliance vault (WORM) mode, cross-tenant ACL approvals with delegation, and an access heatmap with cell-level drill-down and CSV/JSONL export.

Is SinonStore compatible with Amazon S3?

Yes. SinonStore implements the Amazon S3 API surface: buckets, objects, multipart upload, versioning, tagging, ACLs, encryption and lifecycle. It works with the AWS CLI, AWS SDKs, MinIO Client, rclone and any S3-compatible tool, so you can migrate in or out without application changes.

What makes SinonStore different from MinIO?

SinonStore is built for organisations that need to prove what happened to their data, not just store it. Every action is recorded into a SHA-256 hash-chained audit log that can be verified end-to-end and exported as CSV or JSONL. Cross-tenant access goes through an explicit ACL approval workflow (with optional time-bound delegation) instead of credential sharing. DLP scans, quarantine, ransomware bulk-delete detection, point-in-time recovery, geo-fencing, presigned-URL policies (IP / country / scope / rate-limits) and an access heatmap with drill-down are all first-class capabilities, not bolt-ons.

How does the audit log stay tamper-evident?

Each audit entry stores a SHA-256 hash of its content plus the previous entry's hash, forming a per-tenant chain. A verification endpoint walks the chain end-to-end and reports any breakage, so any insertion, deletion or edit shows up as a hash mismatch. Logs can be filtered by event type, actor, resource and date range, and exported to CSV or JSONL for offline retention with actor IDs resolved to display names.

How does cross-tenant sharing work without credential sharing?

Tenant A requests access to a specific object in Tenant B. Tenant B sees the request alongside the object's metadata, DLP violation summary, active quarantine status and recent audit history, and either approves or rejects it. Tenant admins can delegate approval authority to nominated users for a fixed validity window, and every transition (request, approve, reject, delegate) is written to the hash-chained audit log.

How does point-in-time recovery actually work?

Each bucket has a configurable protection window (typically 30–90 days). A timeline view shows the recovery points within that window. You scope a recovery to the whole bucket, a prefix, or a single object, then preview the change set (what will be restored, deleted or modified) before launching an async job whose status, progress and result summary are tracked.

Does SinonStore support air-gapped installations?

Yes. SinonStore can run fully offline. Dependencies are bundled, single-node and clustered deployments are both supported, and upgrades use an atomic dist swap so a failed upgrade leaves the previous version serving the site.

Own Your Data. All of It.

SinonStore is currently in closed beta. Get in touch to discuss access, enterprise requirements, or migration from cloud storage.

Contact Us Explore Features