> Documentation index: https://rift.sh/llms.txt

# Rift vs Amazon S3

S3 is object storage with grants that AWS checks. Rift is a synced filesystem with grants that your own machines check.

### What Amazon S3 is

Amazon S3 is object storage from AWS. S3 Access Grants can give another AWS account read or write on a single prefix or object, and S3 Files or Mountpoint can present a bucket as a filesystem.

### How they differ

With S3, AWS checks every request, and it can read the data unless you encrypt it yourself before upload. A bucket is not a working folder until something mounts or copies it. Rift puts ordinary files on each machine and encrypts them before they leave.

- Identity
  - Amazon S3: An IAM principal in an AWS account.
  - Rift: A key that each machine and agent makes for itself. No account.

- Smallest share
  - Amazon S3: A bucket, a prefix or one object, as read, write or both.
  - Rift: A folder, a subfolder or one file, as read or write.

- Who checks access
  - Amazon S3: AWS.
  - Rift: Each machine that receives a file checks the grant itself.

- Who can read your files
  - Amazon S3: AWS by default. Only you, if you encrypt on the client and manage the keys yourself.
  - Rift: Only the machines you shared with. Rift Cloud holds ciphertext.

- When your machines are off
  - Amazon S3: Files stay available from S3.
  - Rift: Files stored in Rift Cloud stay available.

### Which to choose

Choose Amazon S3 when

- Your systems already run on AWS.
- You need storage at very large scale with mature tooling.
- Both sides have AWS accounts.

Choose Rift when

- Agents should work on ordinary files on their own disks.
- Whoever stores the files must be unable to read them, with no key handling on your side.
- The other side has no AWS account.

Based on the AWS documentation, read in October 2026. Sources: [Access Grants](https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-grants.html) , [cross-account grants](https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-grants-cross-accounts.html) , [client-side encryption](https://docs.aws.amazon.com/AmazonS3/latest/userguide/UsingClientSideEncryption.html) , [S3 Files](https://docs.aws.amazon.com/AmazonS3/latest/userguide/s3-files.html) , [Mountpoint](https://github.com/awslabs/mountpoint-s3/blob/main/doc/SEMANTICS.md).
