Erasure coding, not copies
Three copies waste three times the disk and still die with the second failure. Tessera survives twenty-four failures on 1.6× the storage — so you buy durability once, not three times.
Every object is split into 64 encrypted shards and spread across three continents. Any 40 of them rebuild it. Lose a rack, a data centre, an entire power grid — your reads never notice.
10 TB free for 90 days · no card · export everything at full speed whenever you want out.
Measured across all 38 regions, every hour, and published without an asterisk. If one of them slips, you hear it from us first.
A 4 GB archive arrived over a single connection. Reed–Solomon coding turned it into the sixty-four fragments you are flying through.
Every fragment is ciphertext with its own checksum. On its own it reconstructs nothing, so a stolen one is worth nothing.
Placement is decided by correlated-failure score — power grid, network transit, jurisdiction, hardware batch — not by geography.
Twenty-four of them can burn at the same moment. The read path never notices, and neither do you.
Three copies waste three times the disk and still die with the second failure. Tessera survives twenty-four failures on 1.6× the storage — so you buy durability once, not three times.
Read your own data as often as you like. No transfer meter, no surprise line on the invoice — so nobody on your team has to think twice before running the query.
Keys never touch our plane. Shards are ciphertext before the first packet leaves your firewall — a breach on our side hands the attacker noise.
Archived and hot data sit on the same path. A ten-year-old object answers as fast as one written this morning — no restore jobs, no waiting twelve hours to read your own archive.
Point your existing SDK at a new endpoint and change one line. Multipart, presigned URLs, versioning and lifecycle rules behave exactly as before — migrations take an afternoon, not a quarter.
Object lock, legal hold and a Merkle audit trail your auditor verifies on their own machine — without a call, an NDA or a single word of trust in us.
One TLS connection to the nearest of 38 edge points. Multipart uploads resume from the last verified block.
Reed–Solomon 64/40 in hardware. Each fragment carries its own checksum and generation number.
A solver picks destinations by correlated-failure score: power grid, network transit, jurisdiction, hardware batch.
A Merkle root is written to an append-only ledger. Nothing about the object can change silently after this point.
Reads pull the forty fastest shards, not the forty nearest. Slow disks are simply outrun.
You pick a durability class and stop thinking about it. The solver picks the continents, the grids and the racks — and quietly moves shards whenever the risk model changes.
Every object publishes a Merkle root. Verify a restore against your own copy of the ledger, offline, on a laptop — our cooperation is not part of the process.
Bring your own KMS or hold the raw keys. A subpoena served on Tessera hands over ciphertext and placement metadata — there is nothing else for us to give.
Full-speed export at zero cost, with a signed manifest. The only honest argument against lock-in is a door that opens — try it on day one if you like.
Every plan: no egress fees, no minimum term, no charge to leave. Billing is per terabyte actually stored, measured hourly.
Migration reads from any S3-compatible source at line rate — 40 TB over a 10 Gb link before lunch. Point it at one bucket, keep the original until you trust the copy.
No card to start · no egress fees, ever · a signed export manifest on request.