You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: pages/object-storage/how-to/host-healthcare-data.mdx
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,7 +1,7 @@
1
1
---
2
2
title: How to create a compliant bucket to host healthcare data
3
3
description: This page details the steps to follow to create a compliant bucket using Scaleway Object Storage to host healthcare data
4
-
tags:
4
+
tags: hds healthcare data health compliant compliance regulatory
5
5
dates:
6
6
validation: 2025-11-12
7
7
posted: 2025-11-12
@@ -44,7 +44,7 @@ To host healthcare data in compliance with HDS requirements, you must create a n
44
44
45
45
7. Enable [bucket versioning](/object-storage/how-to/use-bucket-versioning/) if you want to store multiple versions of your objects (this may lead to higher storage costs).
46
46
47
-
8. Optionally, you can use the cost estimator to simulate your Object Storage costs.
47
+
8. Optionally, you can use the cost estimator to estimate your Object Storage costs.
48
48
49
49
9. Click **Create bucket** to confirm.
50
50
@@ -82,7 +82,7 @@ Refer to the [dedicated documentation](/object-storage/api-cli/enable-sse-c/) fo
82
82
83
83
### Customer-side encryption
84
84
85
-
Customer-side encryption ensures that sensitive data is protected before reaching Scaleway Object Storage, giving you control over the encryption mechanism, and keys management. This method must be used in combination with [Scaleway's HDS-compliant deletion method](#deleting-objects-with-customer-side-encryption).
85
+
Customer-side encryption ensures that sensitive data is protected before reaching Scaleway Object Storage, giving you control over the encryption mechanism, and key management. This method must be used in combination with [Scaleway's HDS-compliant deletion method](#deleting-objects-with-customer-side-encryption).
Copy file name to clipboardExpand all lines: pages/object-storage/reference-content/storage-shared-responsibility-model.mdx
+48-48Lines changed: 48 additions & 48 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,55 +9,55 @@ dates:
9
9
10
10
This document outlines the roles and responsibilities for maintaining and securing your Scaleway storage services, Block Storage and Object Storage including Glacier. Our shared responsibility model clarifies the division of duties between Scaleway and our users, ensuring clarity in managing availability, backups, configurations, and security measures for your storage solutions. By understanding this shared responsibility, you can optimize the performance, reliability, and security of your Scaleway storage services.
11
11
12
-
## Service Provision
12
+
## Service provision
13
13
14
14
Scaleway is responsible for the operational maintenance of all components essential to providing the Service. These include:
15
15
16
-
***Physical Infrastructure:** Managing the physical sites that house the hardware infrastructure used for the Service.
16
+
***Physical infrastructure:** Managing the physical sites that house the hardware infrastructure used for the Service.
17
17
18
-
***Hardware Infrastructure:** Maintaining the underlying hardware. Monitors resource utilization rate and updates its capacity plan.
18
+
***Hardware infrastructure:** Maintaining the underlying hardware. Monitors resource utilization rate and updates its capacity plan.
19
19
20
-
***Virtual Infrastructure:** Ensuring the functionality of the virtualized environment.
20
+
***Virtual infrastructure:** Ensuring the functionality of the virtualized environment.
21
21
22
-
***Hosting Platform:** Operating the application and database hosting platform.
22
+
***Hosting platform:** Operating the application and database hosting platform.
23
23
24
-
***Network:**Establishes storage space connectivity in its default configuration.
24
+
***Network:**Establishing storage space connectivity in its default configuration.
25
25
26
-
***Applications and Databases:** Maintaining the applications and databases themselves.
26
+
***Applications and databases:** Maintaining the applications and databases themselves.
27
27
28
28
Furthermore, Scaleway procures the necessary licenses and usage rights for any third-party solutions that are either used by Scaleway in delivering the Service or made available to the client as part of the Service. It provides the client with necessary information regarding the characteristics and conditions of use of the Service. It also plans and implements updates to the various Service components also considering third-party products used within the Service.
29
29
30
30
You are responsible to ensure that users comply with the Service's terms of use.
31
31
32
-
Scaleway is responsible for monitoring, managing, and forecasting the Services APIs and physical clusters capacity.
32
+
Scaleway is responsible for monitoring, managing, and forecasting the Service APIs and physical cluster capacity.
33
33
34
-
You are responsible for informing Scaleway ahead of time for significant changes in your storage capacity forecast.
34
+
You are responsible for informing Scaleway ahead of time of significant changes in your storage capacity forecast.
35
35
36
-
## Logs and Monitoring
36
+
## Logs and monitoring
37
37
38
38
Scaleway is responsible for the proper monitoring of the Service, including:
39
39
40
40
* Retaining access logs and event traces related to the use and administration of the Services, such as objects and storage spaces (volumes, buckets) creation and deletion, server configuration (including physical and software resource configuration), and user and access rights additions and deletions.
41
41
42
42
* Making access logs and event traces available to the client upon request.
43
43
44
-
### Your Responsibilities
44
+
### Your responsibilities
45
45
46
46
* Retain access logs and event traces provided by the Service Provider.
47
47
48
48
* Ensure the successful completion of tasks performed while using the Service (e.g., volume creation for Block Storage, implementing integrity checksums for Object Storage).
49
49
50
-
*Monitoring the available and remaining space within your provisionned volumes.
50
+
*Monitor the available and remaining space within your provisioned volumes.
51
51
52
-
## Product Resiliency
52
+
## Product resiliency
53
53
54
-
### Availability and Steadiness
54
+
### Availability and steadiness
55
55
56
-
Scaleway ensures high availability through resilient infrastructure, technical and organizational measures, including monitoring service health and incident detection for the data hosted within the Service. Scaleway provides and maintains the operational condition of the control plane and APIs.
56
+
Scaleway ensures high availability through resilient infrastructure, and technical and organizational measures, including monitoring service health and incident detection for the data hosted within the Service. Scaleway provides and maintains the operational condition of the control plane and APIs.
57
57
58
58
Scaleway is responsible for:
59
59
60
-
* Implementing resiliency for the Services at least within an Availability Zone (AZ), and for multi-AZ storage tiers only across multiple Availability Zones.
60
+
* Implementing resiliency for the Services within at least an Availability Zone (AZ), and for multi-AZ storage tiers only, across multiple Availability Zones.
61
61
62
62
* Monitoring service health, performance, and balancing the load of use of the Service.
63
63
@@ -67,15 +67,15 @@ You are responsible for:
67
67
68
68
* Configuring the Service in accordance with your needs, particularly in terms of availability.
69
69
70
-
* Monitoring and notifying breaches of Service Level Agreement concerning the availability of the service.
70
+
* Monitoring and notifying us of breaches of Service Level Agreement concerning the availability of the service.
71
71
72
72
#### Performance
73
73
74
-
You are responsible for optimizing your applications' use of Storage Services. Scaleway monitors and optimize infrastructure-level performance, but note that:
74
+
You are responsible for optimizing your applications' use of Storage Services. Scaleway monitors and optimizes infrastructure-level performance, but note that:
75
75
76
76
* Glacier cold storage data access requires object restoration and can incur delays,
77
77
78
-
* For Object Storage Service, multipart uploads and concurrent requests should be used for large files.
78
+
* For the Object Storage Service, multipart uploads and concurrent requests should be used for large files.
79
79
80
80
**Data Integrity**
81
81
@@ -85,27 +85,27 @@ For all Storage Services, you are responsible for:
85
85
86
86
* Verifying the successful completion and integrity of backups.
87
87
88
-
For the Object Storage Service, Scaleway provides a checksum of each uploaded object allowing the client to perform integrity control or control the integrity of the checksum provided to the client at the time of upload, if applicable.
88
+
For the Object Storage Service, Scaleway provides a checksum of each uploaded object, allowing the client to perform integrity control or control the integrity of the checksum provided to the client at the time of upload, if applicable.
89
89
90
90
You are responsible for:
91
91
92
92
* Verifying the successful completion of the upload via a checksum control.
93
93
94
94
* Controlling the availability and integrity of objects, and restoring damaged objects.
95
95
96
-
## Backups and Replication
96
+
## Backups and replication
97
97
98
98
While Scaleway provides internal resiliency mechanisms and features, it is your responsibility to implement a backup strategy appropriate to your needs and the criticality of your activities, including:
99
99
100
100
* External backups.
101
101
102
102
* Replication to other regions (as allowed by regulations).
103
103
104
-
* Management over your backups and snapshots, and regular control of their integrity.
104
+
* Management of your backups and snapshots, and regular verification of their integrity.
105
105
106
106
Internal resilience does not protect against accidental deletions or application-level corruption.
107
107
108
-
## Configuration and Management
108
+
## Configuration and management
109
109
110
110
Scaleway is responsible for the configuration of API and dataplane settings.
111
111
@@ -117,39 +117,39 @@ You are responsible for:
117
117
118
118
* Provisioning additional space or storage spaces according to your needs
119
119
120
-
* Managing volumes attachment, detachment and deletion according to your needs
120
+
* Managing volume attachment, detachment, and deletion according to your needs
121
121
122
-
* Managing snapshots and snapshots deletion according to your needs
122
+
* Managing snapshots, and snapshots deletion according to your needs
123
123
124
-
### Object Storage Class & Lifecycle Rules
124
+
### Object Storage class & lifecycle rules
125
125
126
-
You are responsible for selecting appropriate storage classes, cleanup unnecessary parts or data, and using lifecycle rules according to your needs. Note that a delay may occur if transitioning or expiring a high number of objects through lifecycle rules per day.
126
+
You are responsible for selecting appropriate storage classes, cleaning up unnecessary parts or data, and using lifecycle rules according to your needs. Note that a delay may occur if transitioning or expiring a high number of objects through lifecycle rules per day.
127
127
128
-
### Access Control
128
+
### Access control
129
129
130
130
Scaleway provides versioning, IAM, and specific Service-level access control tools (ACLs, bucket policies.)
131
131
132
-
You are responsible for managing authorizations and access of your personnel to the Service (Console, API and storage spaces), also ensuring the security of your personnel's authentication means. Your responsibilities include:
132
+
You are responsible for managing authorizations and access of your personnel to the Service (Console, API and storage spaces), and for ensuring the security of your personnel's authentication means. Your responsibilities include:
133
133
134
134
* Ensuring public visibility settings align with your intentions.
135
135
136
136
* Regularly reviewing access rules and permissions.
137
137
138
138
* Activating two-factor authentication (2FA).
139
139
140
-
* Configuring bucket policies (access limitation under certain conditions such as IP with white list and black list (allow or deny, IP range)).
140
+
* Configuring bucket policies (enforcing access limitations under certain conditions such as whitelisting or blacklisting certain IPs (allow or deny, IP range)).
141
141
142
-
Scaleway enforces your configurations but does not intervene in their definition or maintenance.
142
+
Scaleway enforces your configurations but does not intervene in its definition or maintenance.
143
143
144
144
### Versioning
145
145
146
-
You are responsible for
146
+
You are responsible for:
147
147
148
148
* Enabling or deactivating versioning for data recovery.
149
149
150
-
* Managing versioned object lifecycle according to your needs.
150
+
* Managing versioned objects' lifecycle according to your needs.
151
151
152
-
## Encryption and Data Deletion
152
+
## Encryption and data deletion
153
153
154
154
### Encryption
155
155
@@ -165,7 +165,7 @@ For client-side encryption or customer-managed encryption keys, you are responsi
165
165
166
166
* Ensuring data becomes permanently inaccessible when keys are destroyed.
167
167
168
-
### Encryption in Transit
168
+
### Encryption in transit
169
169
170
170
Scaleway provides secure HTTPS endpoints. You must:
* Validate certificates and enforce TLS in custom tools.
177
177
178
-
### Data Deletion
178
+
### Data deletion
179
179
180
-
Deletion is initiated only by you, manually or via configured retention rules.
180
+
Deletion is initiated only by you, manually, or via configured retention rules.
181
181
182
182
Scaleway:
183
183
@@ -187,15 +187,15 @@ Scaleway:
187
187
188
188
* Cannot recover data if versioning is not enabled.
189
189
190
-
## Data Residency
190
+
## Data residency
191
191
192
192
* The customer is responsible for selecting the data location at the time of volume/bucket creation.
193
193
194
194
* Scaleway commits not to modify the geographical location of data without the prior agreement of the customer.
195
195
196
196
* The Glacier class systematically stores objects in Paris, regardless of the Region chosen for the bucket.
197
197
198
-
## Identity and Access Management
198
+
## Identity and access management
199
199
200
200
Scaleway provides tools for access control (IAM, ACLs, and policies). You are responsible for:
201
201
@@ -207,9 +207,9 @@ Scaleway provides tools for access control (IAM, ACLs, and policies). You are re
207
207
208
208
* Detecting and responding to unauthorized access.
209
209
210
-
## Platform and Service Security
210
+
## Platform and service security
211
211
212
-
### Scaleway Responsibilities
212
+
### Scaleway responsibilities
213
213
214
214
Scaleway ensures:
215
215
@@ -227,7 +227,7 @@ Scaleway manages and monitors vulnerabilities related to the provision of its Se
227
227
228
228
See Security & Resilience and Trust Center.
229
229
230
-
### User Responsibilities
230
+
### User responsibilities
231
231
232
232
You are responsible for:
233
233
@@ -271,7 +271,7 @@ Scaleway undertakes to:
271
271
272
272
This section outlines the specific requirements and responsibilities for hosting healthcare data in compliance with the HDS regulatory framework.
273
273
274
-
### HDS Compliance Requirements
274
+
### HDS compliance requirements
275
275
276
276
When storing healthcare data within Scaleway Storage Services, the client is responsible for:
277
277
@@ -287,7 +287,7 @@ When storing healthcare data within Scaleway Storage Services, the client is res
287
287
288
288
Scaleway undertakes to provide HDS-certified infrastructure, and commits to maintain this certification. The loss of said certification may result in the termination of Scaleway’s commercial relationship with the HDS client. The aforementioned elements are included in the HDS contract signed by the client.
289
289
290
-
### Data Residency
290
+
### Data residency
291
291
292
292
Scaleway guarantees that data remains within the authorized datacenters in Paris and does not access personal health data hosted by the client.
293
293
@@ -301,15 +301,15 @@ You must:
301
301
302
302
You must not configure replication, snapshots, backups or transfer data to regions outside the authorized perimeter.
303
303
304
-
### HDS-compliant Resources Identification
304
+
### HDS-compliant resources identification
305
305
306
306
You are responsible for:
307
307
308
308
* Knowing which Storage resources are HDS or not.
309
309
310
310
* Attaching volumes to HDS-compliant Instances only.
311
311
312
-
### Block Storage Encryption and Data deletion
312
+
### Block Storage encryption and data deletion
313
313
314
314
Encryption at rest is mandatory for Volumes hosting healthcare data. Deleted data cannot be restored.
315
315
@@ -325,7 +325,7 @@ Scaleway is responsible for:
325
325
326
326
* Managing the lifecycle, rotation and deletion of the disk encryption keys to access the underlying instances.
327
327
328
-
### Object Storage Encryption and Data deletion
328
+
### Object Storage encryption and data deletion
329
329
330
330
Encryption at rest is mandatory for Object Storage buckets hosting healthcare data, with HDS-compliant key handling by Scaleway. Scaleway provides HDS-compatible mechanisms to encrypt data at rest and guarantee HDS-compliant data deletion.
331
331
@@ -347,7 +347,7 @@ When using the Object Storage service, you are required to:
347
347
348
348
Scaleway must maintain technical guarantees for secure deletion of healthcare data.
349
349
350
-
### HDS-compliant Storage Classes and Prohibited Features
350
+
### HDS-compliant storage classes and prohibited features
0 commit comments