Scality

United States · www.scality.com · 26 vendors

Scality is a global technology provider of software-defined storage (SDS) solutions, specializing in distributed file and object storage with cloud data management. The company offers cyber-resilient storage for artificial intelligence, cloud, and backup, enabling enterprises to manage and protect large-scale data.

Resilience scores

Technology vendors

Insights

Last updated 2026-08-03 · revision 1

26 direct vendors, 290 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Scality exhibits a high level of migration readiness, scoring 85 out of 100. This is largely due to its highly modern, cloud-native, and multi-cloud internal tech stack, which includes Kubernetes, Docker, and support for AWS, Azure, and GCP. The use of modern programming languages (Python, Go, Node.js) further supports agile development and cloud integration. Scality's products are built around S3-compatible object storage and software-defined storage principles, which are critical enablers for cloud migration strategies, especially with their 'Hybrid Cloud Data Management' capability. The adoption of containerization (Kubernetes, Docker) implies a microservices-oriented architecture, significantly simplifying the migration of applications and data. Products like ARTESCA are Kubernetes-native and designed for cloud-based data protection targets, directly facilitating backup workload migration. The geographic diversity of vendor headquarters (8 unique countries) suggests a reduced risk of vendor lock-in tied to a single geopolitical region, potentially simplifying vendor transitions during a migration. However, the assessment is constrained by the lack of data on specific regulatory requirements and data residency constraints, which can significantly impact migration strategies. Information on financial stability (revenue concentration, growth history) is also missing, preventing an assessment of the company's capacity to fund large-scale migration initiatives. While vendor geographic diversity is positive, the explicit 'Vendor Lock-in Risk: Unknown' and the ambiguous 'Total Vendors: 0' (despite 22 services) mean that the specific level of vendor lock-in and contract complexity cannot be fully determined.

Compliance

10 in-scope frameworks identified; showing 3.

GDPR (source) — Partially Compliant

Scality has a formal GDPR compliance program in place, including a named Data Protection Officer (Pierre DEROME), GDPR-specific privacy policy provisions for EU/EEA residents, Standard Contractual Clauses for international data transfers, and explicit legal bases for processing. However, no independent third-party GDPR audit or certification has been publicly disclosed. The company processes personal data of EU/EEA residents through its French subsidiary (SCALITY S.A., 11 Rue Tronchet, 75008 Paris) and UK subsidiary (SCALITY Limited, London). Risk is Medium rather than High because documented compliance structures are in place, but the absence of a publicly verifiable audit or certification leaves residual uncertainty. GDPR fines can reach €20M or 4% of global annual turnover, which is a significant financial risk if gaps exist.

Evidence: https://www.scality.com/privacy-policy/, https://www.scality.com/legal/, https://www.scality.com/about-scality/

HIPAA (source) — Assessment Required

Scality explicitly markets its solutions to the healthcare industry, including a dedicated healthcare industry page, medical imaging archive use case, and customer testimonials from healthcare organizations (e.g., SeqOIA Médecine Génomique, referenced on their homepage). The company claims 50+ hospital systems as customers. If Scality's storage software is used to store, process, or transmit Protected Health Information (PHI) on behalf of US healthcare covered entities, Scality would qualify as a Business Associate under HIPAA and must execute Business Associate Agreements (BAAs). Risk is Medium because the consequences of HIPAA non-compliance include civil penalties up to $1.9M per violation category per year, and the healthcare sector is a significant market for Scality. However, as a software vendor (not a cloud service provider storing data directly), the applicability depends on specific customer deployment configurations.

Evidence: https://www.scality.com/industries/healthcare/, https://www.scality.com/use-cases/medical-imaging-archive/

SOC 2 (source) — Assessment Required

Scality provides cloud storage infrastructure software and services to enterprises, cloud service providers, and government organizations. Many of their enterprise and cloud service provider customers would require SOC2 Type II reports as part of their vendor due diligence processes. The absence of a publicly disclosed SOC2 report is notable for a company of Scality's scale and customer profile (Bloomberg, Rackspace, Comcast, EDF, SFR, Orange, Natixis, etc.). Risk is Medium because: (1) enterprise customers increasingly require SOC2 reports from technology vendors; (2) the absence of SOC2 may create competitive disadvantage and customer trust issues; (3) if Scality processes or has access to customer data through support services, SOC2 controls would be relevant. However, as primarily an on-premises software vendor, the direct SOC2 obligation is lower than for SaaS providers.

Evidence: https://www.scality.com/about-scality/, https://www.scality.com/customers/

Financials

Three-year financials

Financial Resilience Score: 6/10

Scality is a privately held venture-backed enterprise storage software company that does not disclose consolidated financial statements. Independent analysts estimate revenue in the US$60-80M range, and the company has raised approximately US$172M+ in disclosed equity funding across Series A through E+ from a diversified syndicate including Menlo Ventures, Iris Capital, Eurazeo, BPI France, Galileo Partners, Omnes Capital, and strategic investor HPE. This strong investor base and 15+ years of continuous operation suggest reasonable financial stability. The company has a blue-chip customer base including Bloomberg, Comcast, Rackspace, EDF, Orange, SFR, Natixis, and 7 of the 15 largest global banks, providing recurring subscription/support revenue with typically high retention. However, the lack of public financial disclosure, ongoing R&D-intensive investment requirements, intense competition from hyperscalers (AWS S3, Azure Blob, Google Cloud) and well-capitalized competitors (Dell, NetApp, IBM, Pure Storage, VAST Data), and tightened late-stage VC funding environment since 2022 create meaningful risk. FX exposure between EUR-denominated costs (Paris R&D) and USD-denominated revenue adds margin volatility. Overall, resilience is moderate: solid strategic positioning and investor support balanced against opacity and competitive intensity.

Key strengths: Strong diversified investor syndicate (Menlo Ventures, Eurazeo, Iris Capital, BPI France, HPE) with ~$172M+ raised, Blue-chip customer base including Bloomberg, Comcast, Rackspace, EDF, Orange, SFR, Natixis, Strategic OEM/reseller partnership with HPE providing distribution scale, Recurring/subscription-oriented revenue model typical of infrastructure software, Product diversification into ransomware-resilient backup and AI/ML data infrastructure, Gartner Magic Quadrant Leader 8 times for Distributed File Systems and Object Storage, 15+ years of continuous operation since 2009 founding

Risk factors: Intense competition from hyperscalers (AWS S3, Azure Blob, Google Cloud Storage), Competition from well-capitalized on-prem competitors (Dell, NetApp, IBM, Pure Storage, MinIO, VAST Data, Cloudian), Private-company opacity with no public consolidated financials, Capital-intensive R&D requirements with unclear path to profitability, Tightened late-stage VC funding environment since 2022, Customer concentration risk in large multi-PB deployments, FX exposure between EUR-denominated costs and USD-denominated revenue, Long enterprise sales cycles (6-18 months) creating quarterly volatility

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report