{
  "fixes": {
    "slug": "wasabi-hot-cloud-storage",
    "name": "Wasabi Hot Cloud Storage",
    "listing": "https://www.anchorterminal.com/tools/wasabi-hot-cloud-storage",
    "markdown": "# Fix list: Wasabi Hot Cloud Storage\n\nFrom Anchor Terminal's listing at https://www.anchorterminal.com/tools/wasabi-hot-cloud-storage, the October 2026 research run, assessed 9 October 2026. Grade C, 61.2 out of 100.\n\nThis is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.\n\nFor a coding agent working on Wasabi Hot Cloud Storage: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.\n\n## 1. Payments \u0026 pricing, 40 out of 100, up to 7.5 more on the total\n\nWhy it scored 40: No x402, MPP or L402 (0). $7.99 a TB-month is public without a login, with the 1 TB and 90-day minimums stated in the pricing FAQ (20). A free trial with no card, 100 GB for 30 days with a company email (20). A person fills in a form with a phone number, opens an emailed invitation and sets up MFA. The Account Control API creates sub-accounts only for partners and control accounts (0).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):\n\nThe published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).\n\n- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).\n\nPayment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.\n\nOpen-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.\n\n## 2. Reliability, 65 out of 100, up to 7 more on the total\n\nWhy it scored 65: Graded as a hosted API on the S3 surface. Status page at status.wasabi.com with a readable history feed (20). In the 90 days to 9 October 2026 the feed shows S3 in Frankfurt unavailable for 27 minutes on 4 August, PUT latency and errors in US-EAST-1 on 26 August, two console access incidents and one WACM reporting fault, which we read as minor (20). No request limits with numbers for the S3 API. The fair use policy adjusts concurrency per account, and only the Account Control API has figures (0). The error table lists `RequestRateLimitExceeded` and a 503 `Unavailable`, with no Retry-After or backoff guidance found (5). An SLA page is published. Its current text is drawn by script, and the version of 21 February 2024 gives credits of 10 per cent below 99.9 per cent monthly uptime and 25 per cent below 99.0 (10). The S3 API is generally available, and the MCP server is a beta (10).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):\n\nHosted APIs, MCP servers, models and platforms.\n\n- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.\n\nLocal packages, SDKs, frameworks and stdio MCP servers.\n\n- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.\n\nProtocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.\n\n## 3. Schema \u0026 documentation, 59 out of 100, up to 6.7 more on the total\n\nWhy it scored 59: No OpenAPI file. The S3 reference documents differences from AWS S3 API version 2006-03-01 and lists the supported IAM and STS actions, so the AWS model is the contract by compatibility (12). llms.txt at docs.wasabi.com with about 1,480 Markdown pages (10). The reference explains Wasabi's own operations (MOVE, compose, append) and leaves the rest to AWS's documentation (10). Typed through the AWS model, with Wasabi's extra headers described in tables (9). An error table of more than 60 codes with HTTP statuses, and request examples for the extensions, but the general error page lists only four statuses (11). API versions are pinned, but the API news page was last updated on 24 August 2026 with one line and its archive stops at June 2024 (7).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):\n\nAPIs and MCP servers.\n\n- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.\n\nModels are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.\n\n## 4. Agent ergonomics, 68 out of 100, up to 5.2 more on the total\n\nWhy it scored 68: Graded as an API. The MCP beta's tool definitions are not published. Responses are sized through S3's own controls (max-keys, prefix, delimiter, HEAD and Range), which Wasabi supports by compatibility and does not document itself (18). Pagination and prefix filters as in S3 (18). Named error codes with messages, and little recovery guidance beyond a few such as 'Try again in five minutes' (12). A PUT by key can be repeated safely. No conditional-write or retry guidance was found (10). AWS SDKs and the AWS CLI work with a changed endpoint, and there is no Wasabi SDK. The endpoint must match the bucket's region, or PUT and DELETE fail (10).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):\n\n- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.\n\nModels are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.\n\n## 5. Maintenance \u0026 community, 46 out of 100, up to 4.7 more on the total\n\nWhy it scored 46: Closed service. The newest dated change we found is the hosted MCP article of 28 August 2026, 42 days before the check (20). Dated entries in the last 90 days are that article and an API docs note of 24 August. The console notes are dated only 'Summer 2026' (10). An announcements page and email support, with no public issue tracker or forum found (8). No Wasabi SDK. AWS SDKs are the supported clients, and the only MCP registry entry for Wasabi is a third party's (5). No packages to check (3).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):\n\n- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.\n\nModels are read for deprecation notice periods and model churn rather than release counts.\n\n## 6. Security \u0026 auth, 83 out of 100, up to 3 more on the total\n\nWhy it scored 83: IAM users, groups, roles and policies, bucket policies, key rotation with two keys a user, and STS AssumeRole sessions of up to 12 hours. The MCP beta issues short-lived OAuth tokens per service path. Two off because the S3 API also accepts plain HTTP (28). AmazonS3ReadOnlyAccess, Object Lock, compliance mode, MFA Delete and Multi-User Authorisation, with no confirmation step in the API (18). Returns stored bytes, with no guidance on treating them as untrusted (8). Bucket access logs, administrative audit logs kept for download for 90 days or saved to an Object Lock bucket, and compliance logging (14). security.txt at the site root, a vulnerability disclosure programme page whose text we could not read, Wasabi's own ISO 27001:2022 certificate valid to 9 June 2028 and public statements on named vulnerabilities. SOC 2 is claimed for the data centres, and no bug bounty was found (15).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-security):\n\n- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.\n\nModels are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.\n\n## 7. Transparency \u0026 trust, 69 out of 100, up to 2.7 more on the total\n\nMade of editorial 59, provenance 79.\n\nWhy it scored 69: Closed service under a Customer Agreement whose current text is drawn by script. The version of 22 September 2025 is clear on ownership and deletion of content (13). That version says content is irretrievably deleted after deletion or termination, and the DPA of 14 July 2025 covers return and destruction and breach notice. The current privacy policy and DPA were unread, and no retention periods in days were found (18). Dated notices for the FTP and TLS 1.0 and 1.1 retirements and 51 days' notice of the July 2026 price rise, but no general deprecation policy (10). A sub-processor list with locations and purposes (version of 19 December 2025), and the data centre operator named for each of 16 regions (18).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):\n\n- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).\n\nThe other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.\n\nProvenance checks not met in full (half of this category, computed from checked facts):\n\n- Endpoint on the vendor's domain: s3.wasabisys.com is not on wasabi.com (0 of 15)\n- Terms of service: published, but our reader couldn't read it (7 of 10)\n- Privacy policy: published, but our reader couldn't read it (7 of 10)\n\n## Deductions\n\nEach comes off the total. A fixed and documented problem counts for less at the next check.\n\n- 9 October 2026. The sign-up guide, updated on 15 September 2026, advertises a trial of up to 1 TB for 30 days, while the trial page gives 100 GB for 30 days with a company email and 10 GB for 14 days with a free mail address. Two points for the conflicting claim (https://docs.wasabi.com/docs/signing-up-for-wasabi; https://wasabi.com/try-free).\n\n## What we couldn't check\n\nWhat we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.\n\n- unchecked: the current Customer Agreement, privacy policy, SLA, DPA, sub-processor list, acceptable use policy and website terms of use, which wasabi.com draws by script. Earlier PDF versions were read where linked\n- unchecked: the vulnerability disclosure programme page, also drawn by script\n- unchecked: the MCP beta's tool list, definitions and annotations. No request was sent to mcp.wasabisys.dev\n- unchecked: the component list on status.wasabi.com, whose page showed our reader only the subscription form\n- Whether the benchmark and public review clause of the 22 September 2025 Customer Agreement survives in the current version\n- Which trial size applies, 1 TB for 30 days per the sign-up guide or 100 GB per the trial page\n- Where the fair use policy starts limiting requests, since no figures are published\n- Whether Wasabi holds a SOC 2 report of its own. The pages read attribute SOC 2 to the data centres\n- One guessed docs address (a free egress policy page) was requested and returned 404\n\n## Weaknesses\n\n- No numeric request limits for the S3 API. The fair use policy adjusts concurrent requests per account by stored volume\n- Pay as You Go bills at least 1 TB a month and charges for objects deleted before 90 days\n- The current Customer Agreement, privacy policy, SLA and DPA are drawn by script, so only earlier PDF versions could be read\n- The Customer Agreement of 22 September 2025 bars benchmarks and public reviews of the service without written approval\n- The hosted MCP server is a beta on a public test instance with no uptime commitment\n\n## What costs an agent a turn today\n\nThe notes we give agents before they call it. Each one is a workaround an agent shouldn't need.\n\n- Use the bucket's own regional endpoint, such as `s3.eu-central-2.wasabisys.com`. The docs say a wrong endpoint allows GET but not PUT or DELETE\n- Ask for a sub-user key with a policy limited to one bucket, or an STS session. A root key has full access, billing included\n- Avoid short-lived objects. Each object deleted before 90 days is billed for the remaining days, and objects under 4 KB bill as 4 KB\n- Keep monthly downloads at or below the stored volume, the limit of the free egress policy\n- Call `https://` endpoints explicitly. The S3 API also accepts plain HTTP\n- For the MCP beta, type `https://mcp.wasabisys.dev/s3` from the page text. The links in the docs table point at a different host\n\n## When it's done\n\nSend what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `\"kind\": \"dispute\"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.\n",
    "grade": "C",
    "score": 61.2,
    "assessed": "2026-10-09",
    "run": "October 2026 research run",
    "categories": [
      {
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "score": 40,
        "maxGain": 7.5,
        "reason": "No x402, MPP or L402 (0). $7.99 a TB-month is public without a login, with the 1 TB and 90-day minimums stated in the pricing FAQ (20). A free trial with no card, 100 GB for 30 days with a company email (20). A person fills in a form with a phone number, opens an emailed invitation and sets up MFA. The Account Control API creates sub-accounts only for partners and control accounts (0).",
        "checklist": [
          "The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).",
          "- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).",
          "Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.",
          "Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-payments"
      },
      {
        "key": "reliability",
        "name": "Reliability",
        "score": 65,
        "maxGain": 7,
        "reason": "Graded as a hosted API on the S3 surface. Status page at status.wasabi.com with a readable history feed (20). In the 90 days to 9 October 2026 the feed shows S3 in Frankfurt unavailable for 27 minutes on 4 August, PUT latency and errors in US-EAST-1 on 26 August, two console access incidents and one WACM reporting fault, which we read as minor (20). No request limits with numbers for the S3 API. The fair use policy adjusts concurrency per account, and only the Account Control API has figures (0). The error table lists `RequestRateLimitExceeded` and a 503 `Unavailable`, with no Retry-After or backoff guidance found (5). An SLA page is published. Its current text is drawn by script, and the version of 21 February 2024 gives credits of 10 per cent below 99.9 per cent monthly uptime and 25 per cent below 99.0 (10). The S3 API is generally available, and the MCP server is a beta (10).",
        "checklist": [
          "Hosted APIs, MCP servers, models and platforms.",
          "- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.",
          "Local packages, SDKs, frameworks and stdio MCP servers.",
          "- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.",
          "Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-reliability"
      },
      {
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "score": 59,
        "maxGain": 6.7,
        "reason": "No OpenAPI file. The S3 reference documents differences from AWS S3 API version 2006-03-01 and lists the supported IAM and STS actions, so the AWS model is the contract by compatibility (12). llms.txt at docs.wasabi.com with about 1,480 Markdown pages (10). The reference explains Wasabi's own operations (MOVE, compose, append) and leaves the rest to AWS's documentation (10). Typed through the AWS model, with Wasabi's extra headers described in tables (9). An error table of more than 60 codes with HTTP statuses, and request examples for the extensions, but the general error page lists only four statuses (11). API versions are pinned, but the API news page was last updated on 24 August 2026 with one line and its archive stops at June 2024 (7).",
        "checklist": [
          "APIs and MCP servers.",
          "- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.",
          "Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-schema"
      },
      {
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "score": 68,
        "maxGain": 5.2,
        "reason": "Graded as an API. The MCP beta's tool definitions are not published. Responses are sized through S3's own controls (max-keys, prefix, delimiter, HEAD and Range), which Wasabi supports by compatibility and does not document itself (18). Pagination and prefix filters as in S3 (18). Named error codes with messages, and little recovery guidance beyond a few such as 'Try again in five minutes' (12). A PUT by key can be repeated safely. No conditional-write or retry guidance was found (10). AWS SDKs and the AWS CLI work with a changed endpoint, and there is no Wasabi SDK. The endpoint must match the bucket's region, or PUT and DELETE fail (10).",
        "checklist": [
          "- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.",
          "Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-ergonomics"
      },
      {
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "score": 46,
        "maxGain": 4.7,
        "reason": "Closed service. The newest dated change we found is the hosted MCP article of 28 August 2026, 42 days before the check (20). Dated entries in the last 90 days are that article and an API docs note of 24 August. The console notes are dated only 'Summer 2026' (10). An announcements page and email support, with no public issue tracker or forum found (8). No Wasabi SDK. AWS SDKs are the supported clients, and the only MCP registry entry for Wasabi is a third party's (5). No packages to check (3).",
        "checklist": [
          "- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.",
          "Models are read for deprecation notice periods and model churn rather than release counts."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-maintenance"
      },
      {
        "key": "security",
        "name": "Security \u0026 auth",
        "score": 83,
        "maxGain": 3,
        "reason": "IAM users, groups, roles and policies, bucket policies, key rotation with two keys a user, and STS AssumeRole sessions of up to 12 hours. The MCP beta issues short-lived OAuth tokens per service path. Two off because the S3 API also accepts plain HTTP (28). AmazonS3ReadOnlyAccess, Object Lock, compliance mode, MFA Delete and Multi-User Authorisation, with no confirmation step in the API (18). Returns stored bytes, with no guidance on treating them as untrusted (8). Bucket access logs, administrative audit logs kept for download for 90 days or saved to an Object Lock bucket, and compliance logging (14). security.txt at the site root, a vulnerability disclosure programme page whose text we could not read, Wasabi's own ISO 27001:2022 certificate valid to 9 June 2028 and public statements on named vulnerabilities. SOC 2 is claimed for the data centres, and no bug bounty was found (15).",
        "checklist": [
          "- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.",
          "Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-security"
      },
      {
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "score": 69,
        "maxGain": 2.7,
        "reason": "Closed service under a Customer Agreement whose current text is drawn by script. The version of 22 September 2025 is clear on ownership and deletion of content (13). That version says content is irretrievably deleted after deletion or termination, and the DPA of 14 July 2025 covers return and destruction and breach notice. The current privacy policy and DPA were unread, and no retention periods in days were found (18). Dated notices for the FTP and TLS 1.0 and 1.1 retirements and 51 days' notice of the July 2026 price rise, but no general deprecation policy (10). A sub-processor list with locations and purposes (version of 19 December 2025), and the data centre operator named for each of 16 regions (18).",
        "blend": "editorial 59, provenance 79",
        "checklist": [
          "- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).",
          "The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-transparency"
      }
    ],
    "provenance": [
      {
        "label": "Endpoint on the vendor's domain",
        "value": "s3.wasabisys.com is not on wasabi.com",
        "points": 0,
        "max": 15
      },
      {
        "label": "Terms of service",
        "value": "published, but our reader couldn't read it",
        "points": 7,
        "max": 10
      },
      {
        "label": "Privacy policy",
        "value": "published, but our reader couldn't read it",
        "points": 7,
        "max": 10
      }
    ],
    "deductions": [
      "9 October 2026. The sign-up guide, updated on 15 September 2026, advertises a trial of up to 1 TB for 30 days, while the trial page gives 100 GB for 30 days with a company email and 10 GB for 14 days with a free mail address. Two points for the conflicting claim (https://docs.wasabi.com/docs/signing-up-for-wasabi; https://wasabi.com/try-free)."
    ],
    "unchecked": [
      "unchecked: the current Customer Agreement, privacy policy, SLA, DPA, sub-processor list, acceptable use policy and website terms of use, which wasabi.com draws by script. Earlier PDF versions were read where linked",
      "unchecked: the vulnerability disclosure programme page, also drawn by script",
      "unchecked: the MCP beta's tool list, definitions and annotations. No request was sent to mcp.wasabisys.dev",
      "unchecked: the component list on status.wasabi.com, whose page showed our reader only the subscription form",
      "Whether the benchmark and public review clause of the 22 September 2025 Customer Agreement survives in the current version",
      "Which trial size applies, 1 TB for 30 days per the sign-up guide or 100 GB per the trial page",
      "Where the fair use policy starts limiting requests, since no figures are published",
      "Whether Wasabi holds a SOC 2 report of its own. The pages read attribute SOC 2 to the data centres",
      "One guessed docs address (a free egress policy page) was requested and returned 404"
    ],
    "weaknesses": [
      "No numeric request limits for the S3 API. The fair use policy adjusts concurrent requests per account by stored volume",
      "Pay as You Go bills at least 1 TB a month and charges for objects deleted before 90 days",
      "The current Customer Agreement, privacy policy, SLA and DPA are drawn by script, so only earlier PDF versions could be read",
      "The Customer Agreement of 22 September 2025 bars benchmarks and public reviews of the service without written approval",
      "The hosted MCP server is a beta on a public test instance with no uptime commitment"
    ],
    "agentNotes": [
      "Use the bucket's own regional endpoint, such as `s3.eu-central-2.wasabisys.com`. The docs say a wrong endpoint allows GET but not PUT or DELETE",
      "Ask for a sub-user key with a policy limited to one bucket, or an STS session. A root key has full access, billing included",
      "Avoid short-lived objects. Each object deleted before 90 days is billed for the remaining days, and objects under 4 KB bill as 4 KB",
      "Keep monthly downloads at or below the stored volume, the limit of the free egress policy",
      "Call `https://` endpoints explicitly. The S3 API also accepts plain HTTP",
      "For the MCP beta, type `https://mcp.wasabisys.dev/s3` from the page text. The links in the docs table point at a different host"
    ],
    "recheck": "https://www.anchorterminal.com/builders/#disputes"
  },
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  }
}
