Exoscale SOS
Exoscale Simple Object Storage (SOS) is S3-compatible and hosted at `sos-<region>.exo.io`. Public buckets are listable and downloadable through the standard S3 enumeration paths.
Exoscale SOS exposure data
Aggregate figures only. See the full open-buckets data across all providers.
Common misconfiguration class
Exoscale's European focus and clean API make it popular with EU-based startups. Misconfigs cluster around the `public-read` ACL set during early prototyping and never revisited.
Real-world impact
Public-read ACL exposes the object manifest and contents to any caller.
Remediation
- Set bucket ACL to `private`; rotate any keys stored in previously-public objects.
- Use Exoscale IAM roles scoped to bucket prefixes instead of account-wide keys.
URL patterns
Exoscale SOS buckets typically resolve under hostnames like:
example.sos-ch-gva-2.exo.ioexample.sos-de-fra-1.exo.io
Check a specific Exoscale SOS URL
Paste any Exoscale SOS URL into our free Open Viewer to inspect its contents directly in your browser, no signup needed.
Open the ViewerOwn a listed Exoscale SOS bucket?
If a bucket you operate appears in our index and you have remediated the misconfiguration, submit a takedown request and we'll remove it from public listings within 4 hours.
Submit takedown request