the metadata economy · zero-knowledge by architecture

They encrypt your files.
They keep your metadata. We keep neither.

Who downloads what, from where, how big, how often — that record is now worth more than the data itself. Every cloud keeps yours. XNS has no access to your data or your metadata, and no coordinator ever watches your reads.

no access logsno read coordinatorclient-side keysexclusive metadata
● live · distributed storage network
The metadata economy

The data was never the prize. The metadata is.

Content tells you what one file holds. Metadata tells you everything else — and it doesn't need to be decrypted to do it.

"We kill people based on metadata."
The value of metadata, in five words.
— Gen. Michael Hayden, former Director of the NSA & CIA, 2014
61%
of government data demands to Microsoft sought metadata, not file content.
Microsoft Law Enforcement Requests Report, H2 2025
$20 · 70 min
to re-identify individuals and infer health, relationships, and gun ownership — from metadata alone.
Stanford MetaPhone study, PNAS 2016

How we compare

Everyone keeps your metadata. Even the ‘zero-knowledge’ ones.

Encrypting file names isn’t the same as hiding who pulls what, when. A coordinator in the read path sees the pattern regardless of how the bytes are scrambled.

XNSAWS S3WasabiBackblazeStorj
Sees your object namesNoYesYesYesEncrypted*
Sees access patterns (who · when · size)NoYesYesYesYes
Coordinator in the read pathNoneYesYesYesSatellite
Can hand over your activityCan't — we don't hold itYesYesYesYes

*Storj encrypts file names, but bucket names are plaintext and its own privacy policy logs access frequency, shard sizes, IP and times. "Zero-knowledge" covers content — not access patterns. · verify before publish · 2026-06

Why we can't see it

Four places your activity could leak. We close all four.

1

Your index stays with you

The Relayer — your S3 gateway — runs on-prem or with your MSP and holds the only copy of your object index. It never ships to XNS.

2

Providers hold ciphertext confetti

Each object is encrypted on your side, then erasure-split into 120 slivers across independent providers — one of 120, unreadable, uncorrelatable. A provider can't tell a backup from a video, or your file from anyone else's.

3

The Conductor brokers capacity, not activity

To contract storage and bill you, it maps a cost-center ID to the sectors you hold — your exact contracted capacity and where those sectors sit, because that's the invoice. And nothing more: no object names, no per-access events, no read history. Nothing close to a satellite watching every request.

4

No one watches your reads

Downloads go from your gateway straight to the providers. There is no coordinator in the read path to log who pulled what, when. This is the line Storj can't cross — its Satellite brokers every single access.


The whole list

Everything that leaves your gateway.

Bucket names, object keys, sizes, folder structure, versions, tags and access times live in the database on the gateway you run. They are never sent to us. What does leave is the operational telemetry needed to meter usage and watch the health of the network. This is all of it — not a summary, not the highlights.

What leaves your gateway
What it is
Installation identifier
Which Relayer sent the report. Not a user, not a bucket
Storage provider public key
Which storage host the measurement concerns
Period start and end
The reporting window
Aggregate bytes up and down
Totals for the period, per provider. Not per object, not per bucket
Read and write timing, throughput
Performance measurement
Error counts and categories
Operational health

There is a second way to check this, blunter than any policy statement: the XNS-side service that handles our contracting and settlement — the only system that ever talks to your Relayer about money — contains zero occurrences of the word “bucket”. It has no concept of one. A system cannot report what it has no field for.

Two modes, your call

Sovereignty is a switch.

Storj is locked to central satellites. We run both — and even our convenient default never sees your data or metadata.

default · central contracting

We handle the plumbing

We broker the storage pools so you never touch crypto or wallets. The only thing we record is your invoice — a cost-center ID mapped to contracted capacity. Never your object names, your contents, or your reads. The most any legal order can compel is ending a contract, never handing over your bytes.

total sovereignty · local contracting

Flip it on, answer to no one

Your Relayer contracts directly with the network using its own wallet. No central party at all — not even a contract for anyone to terminate. Pure self-custody of your storage. Storj can't decentralize; you can.

Store like nobody’s watching. Because nobody is.

Get keys, point any S3 tool at your Relayer, and store on a network that holds your storage — and nothing about you.

Claims on this page last verified
© Copyright - SCP, Corp | Xa Net Services and Affiliates