Rift vs Amazon S3

S3 is object storage with grants that AWS checks. Rift is a synced filesystem with grants that your own machines check.

Amazon S3

Youlaptop
work
api
billing
runs
.env
Amazon S3
It can read your files.
work
api
billing
runs
.env
one prefix, read
OpenClawOpenClawanother company's agent
holds a role in its own AWS account
apiread

Rift

Youlaptop
work
api
billing
runs
.env
Rift Cloud
It cannot read your files. It holds only ciphertext.
Fv+a8LdicjU6ce
efFPD/W3GEGTbB
FFu91EY6OfuOIc
j3iz+iV3W5kvab
1hZDb7nJAxjHmy
one folder, read
OpenClawOpenClawanother company's agent
holds its own key
apiread

What Amazon S3 is

Amazon S3 is object storage from AWS. S3 Access Grants can give another AWS account read or write on a single prefix or object, and S3 Files or Mountpoint can present a bucket as a filesystem.

How they differ

With S3, AWS checks every request, and it can read the data unless you encrypt it yourself before upload. A bucket is not a working folder until something mounts or copies it. Rift puts ordinary files on each machine and encrypts them before they leave.

Amazon S3Rift
IdentityAmazon S3An IAM principal in an AWS account.RiftA key that each machine and agent makes for itself. No account.
Smallest shareAmazon S3A bucket, a prefix or one object, as read, write or both.RiftA folder, a subfolder or one file, as read or write.
Who checks accessAmazon S3AWS.RiftEach machine that receives a file checks the grant itself.
Who can read your filesAmazon S3AWS by default. Only you, if you encrypt on the client and manage the keys yourself.RiftOnly the machines you shared with. Rift Cloud holds ciphertext.
When your machines are offAmazon S3Files stay available from S3.RiftFiles stored in Rift Cloud stay available.

Which to choose

Choose Amazon S3 when

  • Your systems already run on AWS.
  • You need storage at very large scale with mature tooling.
  • Both sides have AWS accounts.

Choose Rift when

  • Agents should work on ordinary files on their own disks.
  • Whoever stores the files must be unable to read them, with no key handling on your side.
  • The other side has no AWS account.

Based on the AWS documentation, read in October 2026. Sources: Access Grants, cross-account grants, client-side encryption, S3 Files, Mountpoint.