Bring your own storage

Point Filarr at your own S3-compatible bucket: your synced files live with the provider YOU choose, end-to-end encrypted before they leave. Available on the Pro plan, from desktop and web alike.

What your bucket sees: nothing

Encryption happens on your devices, before upload. Your bucket only ever receives AES-256-GCM blobs: no filename, no content, no key. A bucket administrator — you, your host, an auditor — can read none of it.

Three steps

1

Create a bucket

On Cloudflare R2, Amazon S3, Backblaze B2, Wasabi, Scaleway, OVHcloud… or any S3-compatible storage. No CORS configuration needed.

2

Create a restricted key

Filarr hands you the exact IAM policy to paste, scoped to your prefix: the key can only touch your own objects, never the rest of the bucket.

3

Paste, test, migrate

Filarr probes the bucket before saving anything, then copies your existing data server-to-server, resumable. Your workspace stays usable during the copy.

The hard rules

Encrypted before it leaves

Encryption keys never leave your devices. The Filarr server relays and verifies — it does not decrypt your files.

No silent fallback

An unreachable bucket is an error said to your face — never an invented “empty vault”, never a quiet switch to different storage.

Health monitored

The server probes your bucket every 6 hours: latency, outage, revoked key. You hear about it before sync silently stops.

The exit stays open

Subscription lapsed? Your data stays readable for 30 days and copying back to Filarr Cloud stays available. Your bytes are never held hostage.

Supported providers

Ready-made presets for the big names — and a custom-endpoint mode for everything else (self-hosted MinIO included).

Cloudflare R2Amazon S3Backblaze B2WasabiScalewayOVHcloudCustom endpoint (S3-compatible)

Everything that comes with it

Assisted migration

Server-to-server copy in both directions, independent verification before any purge, resumes after interruption.

One bucket per profile

Each profile on the account can have its own target — personal profile on R2, work profile on the company bucket.

Organization bucket

On Teams and Enterprise, the organization's shared vaults live on the company bucket, vault-by-vault migration included.

Compliance export

A signed document stating where every profile's bytes live — hand it to an audit as-is.

IAM recipe included

The exact policy to paste at your provider, scoped to your prefix. No root keys in Filarr.

Guardrails

Probe before save, target-change quota shown before it bites, secret sealed server-side and never returned.

Your files, your bucket

BYOS is included in the Pro plan — from the desktop app or app.filarr.com.