LINESERVE

Object Storage — hosted in Nairobi (ke-1a)

Object storage in Kenya, in a Nairobi data centre

S3-compatible storage that plays nice with your tools — and your budget.

Object storage is where your data actually lives — the backups, the KYC documents, the product photos, the video archive. Where that data sits is a question Kenyan law has an opinion about, and it is the question this page answers first. Lineserve's ke-1a region is in Nairobi. Point any S3 tool at ke-1a.s3.lineserve.net and the objects you write stay in Kenya. You keep the AWS CLI, boto3 and rclone you already use; the only thing that changes is the endpoint.

FromKES 4.52per GB / month· generous free egress
  • S3-compatible API — ke-1a.s3.lineserve.net
  • Data residency for Kenya's Data Protection Act — your data stays in-country
  • Billed in KES — pay with M-Pesa, bank transfer or card
  • Keep the AWS CLI, boto3 and rclone you already use
  • 99.9% availability SLA

No credit card required · Local billing in KES, TZS & NGN

Pricing

Cheaper the more you store

Tiered storage that drops as you grow, with free data transfer and free API requests — you only ever pay for what you store, so serving your own files never triggers a shock bill.

Starter

Up to 1 TB

KES 7.90/GB/mo

Hosted in Nairobi, Dar es Salaam & Lagos

Side projects and small apps.

Create a bucket
Most popular

Growth

Up to 5 TB

KES 6.77/GB/mo

Hosted in Nairobi, Dar es Salaam & Lagos

Growing products and teams.

Create a bucket

Business

Up to 10 TB

KES 5.64/GB/mo

Hosted in Nairobi, Dar es Salaam & Lagos

Data-heavy production workloads.

Create a bucket

Enterprise

10 TB+

KES 4.52/GB/mo

Hosted in Nairobi, Dar es Salaam & Lagos

Custom quote for scale.

Contact sales

Transfer & requests — same at every tier

Data transfer out (egress)FreeNo egress fees — serving your files never triggers a bill.
Data transfer inFreeUploading to Lineserve is always free.
API requestsFreePUT, POST, LIST, and GET are all included.

Prices exclude VAT. Storage is billed on average monthly usage, and the per-GB rate follows your total stored volume. Data transfer and requests are free. Local currency figures are indicative and settled at checkout.

Network

Kenya's bandwidth arrives in Mombasa, not Nairobi

Six subsea systems land on the Kenyan coast — TEAMS, SEACOM, EASSy, LION2, DARE1 and PEACE — and every one of them is roughly 480 km of terrestrial fibre away from a Nairobi data centre. The Communications Authority puts Kenya's lit international capacity at 28,130 Gbps for the January–March 2026 quarter, of which 17,759 Gbps was in use.

That geography is the whole point of a bucket in Nairobi. When a Kenyan user downloads a file from a bucket in Frankfurt, the bytes travel out over that subsea path, up the coast and back inland. Serving the same file from ke-1a means they never reach the coast at all. A product image on a Nairobi shopper's phone comes off a disk in Nairobi, over Safaricom, and that is the entire journey — no Mombasa, no subsea leg, no return trip at the end of it.

2.65M

Fixed subscriptions in Kenya (CA, Q1 2026)

136

Networks peering at KIXP, Nairobi (PeeringDB)

28,130 Gbps

Kenya's lit international capacity (CA, Q1 2026)

480 km

Mombasa landing to Nairobi backhaul

Your users are on Safaricom, Faiba, Zuku and Poa

Of Kenya's 2,656,653 fixed internet subscriptions in the quarter to March 2026, Safaricom holds 941,501, Jamii Telecommunications — Faiba — 517,270, Wananchi's Zuku 276,607 and Poa Internet 256,517. Whichever of those a reader arrives on, they are inside Kenya, and so is the bucket they are reading from.

Nairobi peering — KIXP

The Kenya Internet Exchange Point is a neutral non-profit exchange operated by TESPOK, present in four Nairobi facilities. PeeringDB records 136 peer networks, 151 connections and 2.9 Tbps of combined capacity, with 84% IPv6 adoption. Lineserve peers at KIXP, so traffic between ke-1a and another network present there is exchanged inside Nairobi rather than hauled to Europe and back — for the networks actually present.

Payments

Pay for storage the way you pay for everything else in Kenya

Mobile money penetration in Kenya is 100.1% of population — 53,368,939 active subscriptions across 602,470 registered agents, with M-Pesa holding 89.1% of the market. A Kenyan buyer does not think of M-Pesa as an alternative payment method; cards are the alternative. Storage on /ke is billed in KES, so no foreign card and no forex conversion is involved.

M-Pesa first

Storage has a billing shape that suits mobile money: a small recurring amount that grows slowly as the bucket grows. A few hundred gigabytes is a modest monthly figure, not a capital purchase.

Bank transfer for the archive-sized bills

A multi-terabyte archive or an annual commitment can exceed a mobile-money transaction limit. A transfer handles what a push cannot.

Card if your finance team prefers it

Visa and Mastercard work, in shillings, with no foreign-transaction fee from your bank. They are simply not the default assumption in this market.

The platform

Everything the S3 ecosystem expects

A complete, compatible object store — the endpoints, semantics, and controls your existing tools already know how to talk to.

S3-compatible API

Standard S3 endpoints and semantics. Point your existing SDKs and tools at us and go.

Access keys & policies

Issue scoped access keys and bucket policies to control exactly who reaches what.

Encrypted at rest

Objects are encrypted at rest by default, with TLS in transit on every request.

Versioning

Keep object history and recover from accidental overwrites and deletes.

Lifecycle rules

Expire or transition objects automatically on a schedule you set per bucket.

Presigned URLs

Grant temporary, time-limited access to a single object without sharing keys.

Static website hosting

Serve a static site or SPA straight from a bucket, no server required.

Generous free egress

Serve your own data without the runaway transfer bills global clouds are known for.

Regional endpoints

Store data in the region closest to your users and keep it on the continent.

Regions & endpoints

Store where your users are

Put your data in the region closest to the people reading it. Every region exposes its own S3 endpoint — single-digit latency within the metro, data kept on the continent.

Live

Kenya

ke-1a.s3.lineserve.net

ke-1a.s3.lineserve.net

Nairobi metro

Live

Tanzania

tz-1a.s3.lineserve.net

tz-1a.s3.lineserve.net

Dar es Salaam metro

Live

Nigeria

ng-1a.s3.lineserve.net

ng-1a.s3.lineserve.net

Lagos metro

Expansion zonesUganda · ug-1aSouth Africa · za-1aGhana · gh-1a

Drop-in compatible

Keep the tools you already use

Because the API is S3-compatible, nothing in your stack has to change. Set the endpoint, keep your code. The AWS CLI, boto3, rclone, s3cmd, and any S3 SDK work out of the box.

AWS CLIboto3rclones3cmdMinIO Clientany S3 SDK
terminal
# Point the AWS CLI at your region endpoint — that's the only change.
aws s3 --endpoint-url https://ke-1a.s3.lineserve.net \
  cp ./backup.tar.gz s3://my-bucket/backups/

Same commands, same SDKs. Just a different endpoint.

Use cases

What people store with us

Backups & archives

Offsite backups and long-term archives, priced so keeping data is never the problem.

Media & static assets

Images, video, and downloads served fast from the region nearest your audience.

App & user uploads

A durable home for everything your application writes — attachments, exports, logs.

Data lakes & analytics

Land raw data for pipelines and analytics, close to the compute that reads it.

How it works

Storing data in three steps

1

Create a bucket

Choose a region and name your bucket from the console or the API.

2

Get your access keys

Issue a scoped access key and secret for your app or tool.

3

Upload with any S3 tool

Point your existing SDK or CLI at the endpoint and start reading and writing.

Availability SLA

99.9%

  • Objects stored redundantly and encrypted at rest
  • Service credits applied automatically when we miss the SLA
  • Tier III colocation facilities across all live regions

Reliability

99.9%, and what happens on the day it matters

Your objects are stored redundantly and encrypted at rest, served from Tier III facilities, and backed by a 99.9% availability SLA. Reach a real engineer in your region and timezone when you need one.

Kenya

+254 119 039 063

Why Lineserve

The costs that actually add up

CapabilityLineserveGlobal cloud
Predictable, generous free egress
Billing in KES, TZS & NGN
Single-digit local latency
S3-compatible API
Support in your timezone
Pay in your currency — no forex
Data stays on the continent

Tax & invoicing

The invoice your finance team can actually file

Kenya's standard VAT rate is 16%, and the Kenya Revenue Authority's published list of taxable digital services names cloud backup, email hosting and software subscriptions explicitly. Object storage is squarely in scope. VAT falls due by the 20th of the month following the earlier of invoice, performance or payment, filed on a VAT3 return through iTax.

This matters more on a storage page than on most, because storage is a monthly operating cost a Kenyan business will book every month for years. A finance manager will ask at the first invoice whether the input VAT is claimable — and a Kenyan business buyer cannot claim the expense or the input VAT without a valid tax invoice bearing its own KRA PIN.

What a Kenyan tax invoice carries

The seller's KRA PIN and registered name; a unique invoice number with date and time; the buyer's KRA PIN on B2B sales; an item description with quantity and taxable value; the tax type and the VAT charged, shown separately; and the KRA control number and QR code returned when the invoice is transmitted.

How the storage line itself is calculated

Billing is on average monthly usage, and the per-GB rate follows your total stored volume — so growing past a tier boundary lowers the rate rather than triggering a penalty. You are not locked to the rate you signed up on.

Object-storage figures in local currency are derived from an indicative rate and confirmed at checkout. Lineserve Limited is registered for VAT in Kenya, so your invoice is a Kenyan tax invoice with the 16% shown on it — not a foreign receipt your accountant has to argue about. Talk to [email protected] about your invoicing requirements before you order.

Data residency

Where your objects sit, and what Kenyan law says about it

The law is the Data Protection Act, No. 24 of 2019. The regulator is the Office of the Data Protection Commissioner. Objects written to ke-1a.s3.lineserve.net are held in Nairobi and are not moved out of Kenya without your instruction — data residency for Kenya's Data Protection Act.

Three things about the Act matter specifically to a bucket, and one of them is written as though it were an object-storage requirement.

Hosting abroad does not put you outside the Act

Section 4(b) applies the Act to a controller or processor who is not established or ordinarily resident in Kenya, but processing personal data of data subjects located in Kenya. Moving your object store to Frankfurt moves the data; it does not move the obligation.

Sending personal data out of Kenya has conditions attached

Section 48 permits transfer out of Kenya where the controller or processor has given the Data Commissioner proof of appropriate safeguards, or where the transfer is necessary for contract performance, public interest, legal claims, vital interests or compelling legitimate interests. Section 49(1) is stricter for sensitive personal data: it may only be effected on the data subject's consent and confirmation of appropriate safeguards, and section 49(3) lets the Data Commissioner prohibit, suspend or condition a transfer. Kenya does not ban sending data abroad — it attaches conditions and paperwork. Keeping the objects in Nairobi means that analysis does not arise for that data. That is a simplification argument, not a compliance claim.

Regulation 26 asks for one serving copy, in Kenya

Section 50 of the Act lets the Cabinet Secretary prescribe processing that may only be effected through a server or data centre located in Kenya, and Regulation 26(1) of the Data Protection (General) Regulations, 2021 exercises that power: a controller or processor processing personal data for a listed strategic-interest purpose must either process it through a server and data centre located in Kenya, or store at least one serving copy of the concerned personal data in a data centre located in Kenya. Read that second limb again — it is an object-storage requirement in everything but name. The listed purposes are civil registration and legal identity management; the conduct of elections; overseeing any system for administering public finances by a state organ; running a system designated as protected under the Computer Misuse and Cybercrimes Act, 2018; early childhood or basic education under the Basic Education Act, 2013; and the provision of primary or secondary health care.

Respect how narrow that is

Regulation 26 bites on six named purposes rather than on Kenyan data at large — if your buckets hold civil registration, election, public finance, protected-system, basic education or primary and secondary health care data, a bucket in ke-1a answers it directly. Separately, entities in restricted sectors — financial services, telecommunications, health, education, insurance, betting, public bodies and religious organisations — must register with the ODPC regardless of size, while others may be exempt below KES 5 million turnover and 10 employees. If you are in one of those sectors you are a registered controller, and your processor choice is part of your own filing.

Lineserve supplies the location. Compliance under the Act is yours as the controller — nothing here is a certification, and nothing here says otherwise.

Who stores here

What Kenyan teams keep in ke-1a

Newsrooms and publishers

Nairobi's media sector has a traffic pattern most markets do not: general elections every five years in August, budget day in June, and national exam-results releases each produce a single-day spike on the same handful of sites. The workload is a WordPress or headless CMS behind a cache, with every image, audio file and video cut in a bucket. On a results night the origin serves the same photo set several hundred thousand times — to readers who are in Kenya, from bytes that are in Kenya.

Digital lenders and SACCOs

What goes into object storage is the sensitive half of the business: KYC document images, identity scans, signed loan agreements, statement PDFs pulled for credit scoring, and long-retention audit archives regulators expect to still exist years later. Deposit-taking SACCOs do the same with member records, month-end batch outputs and dividend-run archives. These are exactly the objects a Kenyan controller least wants to explain a cross-border transfer for.

E-commerce and retail

Product photography is the single largest asset class most Kenyan stores own — a WooCommerce or Magento catalogue with a dozen images per SKU, re-served on every category page. Buckets hold the originals and the generated thumbnails; order exports, invoice PDFs and M-Pesa callback logs land in the same place.

ISPs, WISPs and MSPs

Unglamorous and constant: nightly RADIUS and billing database dumps, NetFlow archives, Zabbix and LibreNMS retention, router configuration backups, and CDR archives kept for as long as the licence requires. It has to be in-country to be useful, and it grows every night.

Agencies and the .ke long tail

Nairobi's agency and freelance scene is the reseller channel in this market — one buyer, many client sites. One bucket per client, media offloaded off the VPS disk, nightly site backups written by rclone on a cron.

NGOs and donor programmes

Nairobi hosts a large concentration of NGO and UN regional offices. Their storage is DHIS2 attachments, KoboToolbox and ODK form submissions with photographs attached, and the exports underneath M&E dashboards. Where the programme delivers basic education or primary and secondary health care, Regulation 26 applies directly to that data.

Migrating

Moving a bucket into Nairobi

From an overseas provider

The mechanical part is easy: because both ends speak S3, rclone sync moves the objects directly and the only application change is the endpoint URL and the credentials. The commercial part is the reason to do it. An overseas object store bills in USD on a card — an FX spread and, at most Kenyan banks, a foreign-transaction fee on a charge you will pay every month for years — and it puts a Kenyan controller's personal data outside Kenya, which is the section 48 and 49 analysis above. One honest note on the move itself: your current provider may charge you egress to read your own data out. That cost is theirs, not ours, and it is worth pricing before you start — a 5 TB migration is 5 TB of their egress.

From a local host or an office NAS

The common Kenyan starting point is not a hyperscaler at all. It is a backup drive in the server room, or storage bundled with shared hosting that no S3 tool can address and that has no versioning. Moving to ke-1a gets you versioning and lifecycle rules, presigned URLs for time-limited access to a single object, and scoped access keys with bucket policies — without leaving the country. The local field competes on price and .ke domain bundling; a Nairobi data centre and a Kenyan IP are table stakes here, so the argument on this page is the part nobody publishes: what the invoice does for your VAT return, and what Regulation 26 actually says.

The comparison above is factual and applies to a category, not to a company. We are not naming a competitor.

FAQ

Questions, answered

Yes. We implement the standard S3 API, so the AWS CLI, boto3, rclone, s3cmd, and any S3 SDK work by simply pointing at your region's endpoint. No code changes needed.

There's no egress bill. Data transfer in and out — and API requests — are all free. You only pay for what you store, so serving your own files never triggers a surprise charge.

Objects are stored redundantly and encrypted at rest. Availability is backed by a 99.9% SLA. See the durability section for the specifics of the redundancy in your region.

Yes. Issue scoped access keys, set bucket policies, and generate presigned URLs for temporary, single-object access without sharing keys.

Yes. Enable static website hosting on a bucket to serve a static site or SPA directly, with no server to run.

Yes. Because we're S3-compatible, tools like rclone move data across directly. Our team will help you plan and run the migration at no charge.

You can create multiple buckets per account, and object sizes follow standard S3 multipart limits. Need a higher account limit? Just ask.

In our Nairobi region, ke-1a. Objects written to ke-1a.s3.lineserve.net are stored in Kenya and are not moved out of the country without your instruction.

It gives you data residency for Kenya's Data Protection Act — your objects stay in-country, so the cross-border transfer analysis under sections 48 and 49 does not arise for that data. Compliance under the Act remains yours as the controller. We supply the location, not a certification.

Regulation 26(1) requires processing through a server and data centre located in Kenya, or storing at least one serving copy of the personal data in a data centre located in Kenya, for six named purposes — civil registration and identity, elections, public finance administration, protected computer systems, basic education, and primary or secondary health care. ke-1a is in Nairobi. Whether your specific processing falls inside Regulation 26 is a question for your counsel.

Yes. Set the endpoint to https://ke-1a.s3.lineserve.net and keep your code. The API is S3-compatible, so the SDKs, the CLI flags and the tooling behave the same.

Yes. Kenyan customers pay in KES with M-Pesa and other mobile money, bank transfer, or card. No foreign card and no forex conversion.

Your bucket is in Nairobi, so a GET from a Kenyan user is answered from a disk in the same city — the request goes to KIXP and comes straight back, rather than out to Mombasa and across a subsea cable to fetch a thumbnail. For a store serving product images to shoppers on Safaricom, that is the difference the customer feels on every page.

Yes. Enable static website hosting on the bucket to serve a static site or SPA, or use presigned URLs to hand out time-limited access to a single object without sharing keys.

Because both ends speak S3, rclone sync copies objects across directly and the only change in your application is the endpoint and the credentials. Check what your current provider charges you in egress to read your own data out before you start.

Yes. ke-1a in Nairobi, tz-1a in Dar es Salaam and ng-1a in Lagos are all live, each with its own S3 endpoint. Note that a copy leaving Kenya is a cross-border transfer under the Data Protection Act, and the section 48 and 49 conditions apply to it.

Objects are encrypted at rest by default and every request is TLS-encrypted in transit. Access is controlled with scoped keys and bucket policies.

The per-GB rate follows your total stored volume, so growing past a tier boundary lowers the rate rather than triggering a penalty. Billing is on average monthly usage.

KES. Prices can be viewed in USD, KES, TZS or NGN. Object-storage figures in local currency are derived from an indicative rate and confirmed at checkout.

Yes — talk to [email protected] or +254 119 039 063 for a Business or Enterprise quote, or for help planning a migration.

Start storing in minutes, not migrations

S3-compatible, encrypted, and close to your users — with egress that won't surprise you. Pay in local currency, no card required to start.

No credit card required · 99.9% availability SLA · Local billing in KES, TZS & NGN