10. Storage & Media/BYOS Integration

Bring Your Own Storage (BYOS)

Maintain full data sovereignty by connecting your own external enterprise storage providers (AWS S3 or Cloudinary). Project media is stored directly in your own infrastructure.

COMPLETE OWNERSHIP
100% BYOS
Your Cloud · Your Data · Your Compliance

Connect your corporate cloud storage buckets. If you ever leave the platform, your media assets remain in your own accounts.

Zero Vendor Lock-In

BYOS Architecture Overview

BYOS allows enterprise organizations to meet strict compliance mandates by storing all uploaded media assets inside their own cloud accounts:

EXTERNAL / AWS

Amazon S3 Connector

Connect custom S3 buckets across any AWS region with pre-flight API connection verification.

EXTERNAL / CLOUDINARY

Cloudinary Connector

Route media into your Cloudinary cloud environment for custom image transformations and video effects.

SECURITY / ENCRYPTION

AES-256 Key Vault

Access keys and API secrets are encrypted at rest using dedicated hardware security keys.

TELEMETRY / USAGE

Live Capacity Telemetry

Real-time capacity tracking reads directly from your external cloud provider to monitor storage limits.

Supported External Providers

GN-Apex supports the following external storage connections:

ParameterTypeRequirementDescription
Amazon Web Services (AWS S3)Access Key + Secret KeyOptionalStandard S3 buckets across all global AWS regions (us-east-1, eu-west-1, ap-southeast-1, etc.).
CloudinaryAPI Key + Secret + Cloud NameOptionalDirect media delivery and asset management inside your existing Cloudinary cloud namespace.

Connecting an External Bucket in 3 Steps

1
Navigate to Storage Settings

From your dashboard, open Organization Settings → Storage & BYOS and click Add External Provider.

2
Enter Provider Credentials

Select AWS S3 or Cloudinary. Enter your Access Key, Secret Key, and Bucket / Cloud Name.

3
Automated Handshake Verification

GN-Apex executes an immediate pre-flight handshake to verify write permissions before saving. Once confirmed, the provider is marked ACTIVE.

Hardware-Level Credential Encryption

Encrypted at Rest
All external API keys, secret tokens, and bucket credentials are encrypted using AES-256-CBC with unique initialization vectors. Plaintext credentials are never returned over public APIs.