# Which leading hybrid cloud storage vendors have the strongest compliance and encryption for an enterprise that handles regulated data and cannot accept a storage solution with weak security controls?

<p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Hoping to get a read from folks who review and evaluate cloud storage software for regulated environments. Which leading hybrid cloud storage vendors have the strongest compliance and encryption for an enterprise that handles regulated data and cannot accept a storage solution with weak security controls?</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Working from the<a class="a a--md" elv="true" href="https://www.g2.com/categories/hybrid-cloud-storage-solutions"> </a><a class="a a--md" elv="true" href="https://www.g2.com/categories/hybrid-cloud-storage-solutions">hybrid cloud storage solutions</a> category, I’d set the bar, roughly as this:</p><ul>
<li>Encryption at rest and in transit as the default, not a setting someone has to remember</li>
<li>Keys the enterprise holds, so nobody upstream can read the data</li>
<li>Certifications auditors recognize without a fight</li>
<li>Locked retention for records that legally cannot be altered or deleted</li>
<li>A clear trail of who touched what, and when</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Some tools that keep coming up:</p><ul>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/netapp-ontap-data-management-software/reviews"><strong>NetApp ONTAP</strong></a>: encryption is built into the storage itself, and its SnapLock feature locks records so they cannot be changed or deleted until their retention period ends. A long-standing answer in finance and healthcare, but it needs real expertise to run.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/nasuni/reviews"><strong>Nasuni</strong></a>: encrypts everything before it leaves your site, and you hold the keys, so the cloud behind it only ever stores scrambled data. Enterprise reviewers give it the highest satisfaction in this category. Built for file data, though, not databases.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/google-cloud-storage/reviews"><strong>Google Cloud Storage</strong></a>: encrypts by default, lets you manage your own keys, and reviewers score its data security top of this category. The catch is that it's the public-cloud half of the equation, so residency comes down to how carefully you set it up.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/azure-stack/reviews"><strong>Azure Stack</strong></a>: the answer when the regulator's position is "the data doesn’t leave the building." It runs Azure services inside your own datacenter, even disconnected. Reviewer satisfaction sits on the lower side in this category's data, and you carry the infrastructure burden.</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">For those who run security reviews on storage vendors: what's the issue that actually makes a tool fail one? And is there anything i should add to my evaluation criteria?</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true"></p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true"></p>

##### Post Metadata
- Posted at: 23 days ago
- Author title: Tech Consultant
- Net upvotes: 1


## Comments
### Comment 1

&lt;p&gt;From G2 reviews, the issue that most commonly fails a vendor in a real security review is key management depth. G2 reviewers describe tools that offer encryption, but where customer-managed keys are an add-on or require a third-party KMS integration that introduces its own audit complexity, with Nasuni&#39;s client-side encryption model and NetApp&#39;s SnapLock consistently passing that test without extra configuration. The criteria most often missing from evaluation checklists is data residency verification under replication. Reviewers in regulated industries flag that several platforms encrypt correctly but replicate to regions that violate residency requirements unless explicitly restricted, which only surfaces during the audit rather than the evaluation.&lt;/p&gt;

##### Comment Metadata
- Posted at: 21 days ago
- Author title: Marketing Executive





## Related discussions
- [How well does Trello scale into a larger team?](https://www.g2.com/discussions/1-how-well-does-trello-scale-into-a-larger-team)
  - Posted at: about 13 years ago
  - Comments: 6
- [Can we please add a new section](https://www.g2.com/discussions/2-can-we-please-add-a-new-section)
  - Posted at: about 13 years ago
  - Comments: 0
- [Quantifiable benefits from implementing your CRM](https://www.g2.com/discussions/quantifiable-benefits-from-implementing-your-crm)
  - Posted at: about 13 years ago
  - Comments: 4


