How it works Capabilities Architecture Regions Pricing Start free →

Every byte,
exactly where
it belongs.

Every object is split into 64 encrypted shards and spread across three continents. Any 40 of them rebuild it. Lose a rack, a data centre, an entire power grid — your reads never notice.

10 TB free for 90 days · no card · export everything at full speed whenever you want out.

Four numbers that decide everything else.

Measured across all 38 regions, every hour, and published without an asterisk. If one of them slips, you hear it from us first.

0stored today
0objects sealed
0bytes lost since 2019
0median read, hot or archived

This is one file.

A 4 GB archive arrived over a single connection. Reed–Solomon coding turned it into the sixty-four fragments you are flying through.

None of them means anything.

Every fragment is ciphertext with its own checksum. On its own it reconstructs nothing, so a stolen one is worth nothing.

No two share a rack.

Placement is decided by correlated-failure score — power grid, network transit, jurisdiction, hardware batch — not by geography.

Any 40 rebuild the whole.

Twenty-four of them can burn at the same moment. The read path never notices, and neither do you.

Tessera · lattice
stage 01 / 04

Built for data that outlives its authors.

0164 / 40

Erasure coding, not copies

Three copies waste three times the disk and still die with the second failure. Tessera survives twenty-four failures on 1.6× the storage — so you buy durability once, not three times.

02$0.00

Egress that costs nothing

Read your own data as often as you like. No transfer meter, no surprise line on the invoice — so nobody on your team has to think twice before running the query.

03AES-256

Encrypted before it leaves

Keys never touch our plane. Shards are ciphertext before the first packet leaves your firewall — a breach on our side hands the attacker noise.

049 ms

No cold tier tax

Archived and hot data sit on the same path. A ten-year-old object answers as fast as one written this morning — no restore jobs, no waiting twelve hours to read your own archive.

05S3

The API you already wrote

Point your existing SDK at a new endpoint and change one line. Multipart, presigned URLs, versioning and lifecycle rules behave exactly as before — migrations take an afternoon, not a quarter.

06WORM

Immutability with a receipt

Object lock, legal hold and a Merkle audit trail your auditor verifies on their own machine — without a call, an NDA or a single word of trust in us.

Five stages between your write and a durable object.

CONTINUOUS RE-VERIFICATION LOOP · EVERY 72 HOURS Ingestedge pop Shard64 fragments Placerisk solver Sealmerkle root Serve9 ms path
Ingest

One TLS connection to the nearest of 38 edge points. Multipart uploads resume from the last verified block.

Shard

Reed–Solomon 64/40 in hardware. Each fragment carries its own checksum and generation number.

Place

A solver picks destinations by correlated-failure score: power grid, network transit, jurisdiction, hardware batch.

Seal

A Merkle root is written to an append-only ledger. Nothing about the object can change silently after this point.

Serve

Reads pull the forty fastest shards, not the forty nearest. Slow disks are simply outrun.

Drag to spin the world

Geography is a failure domain, not a feature.

You pick a durability class and stop thinking about it. The solver picks the continents, the grids and the racks — and quietly moves shards whenever the risk model changes.

Amsterdam · eu-west-17 msPrimary
Ashburn · us-east-29 msPrimary
Singapore · ap-se-111 msPrimary
Reykjavík · arc-north-118 msCold witness
São Paulo · sa-east-122 msWitness

Auditable by people who do not trust us.

01

Proof, not promises

Every object publishes a Merkle root. Verify a restore against your own copy of the ledger, offline, on a laptop — our cooperation is not part of the process.

02

Keys you hold

Bring your own KMS or hold the raw keys. A subpoena served on Tessera hands over ciphertext and placement metadata — there is nothing else for us to give.

03

Exit in a day

Full-speed export at zero cost, with a signed manifest. The only honest argument against lock-in is a door that opens — try it on day one if you like.

One number. No egress.

Shard
$4 / TB / month
  • Up to 50 TB
  • Eleven nines of durability
  • S3-compatible API
  • Community support
Start with 10 TB free
Lattice
$3 / TB / month
  • Unlimited volume
  • Object lock & legal hold
  • Private placement policies
  • 99.99% availability, in writing
  • A named engineer, not a queue
Talk to us
Sovereign
Custom
  • Jurisdiction pinning
  • Dedicated hardware batches
  • On-prem witness nodes
  • Quarterly audit package
Talk to us

Every plan: no egress fees, no minimum term, no charge to leave. Billing is per terabyte actually stored, measured hourly.

Move one bucket. Watch it stop being your problem.

Migration reads from any S3-compatible source at line rate — 40 TB over a 10 Gb link before lunch. Point it at one bucket, keep the original until you trust the copy.

No card to start · no egress fees, ever · a signed export manifest on request.

Built in the cold — Reykjavík, Amsterdam, Singapore. Fictional brand, made for a design study · 2026