IBM Aspera on Cloud (AoC) is easy to describe as “fast file transfer in the cloud,” but that misses the useful part. It is a SaaS platform for securely exchanging large files and folders across users, organizations, cloud storage and on-premises storage, while IBM Aspera FASP handles the high-speed data movement.
This post strips the service down to what matters when you are evaluating or designing it: how AoC fits into the architecture, the security controls, edition differences, tethered HSTS nodes, and the billing model.
Commercial entitlements in this article are based on IBM Aspera on Cloud Service Description i126-8034-11 dated October 2024. Always validate the current IBM order document before making a commercial decision.
Aspera on Cloud in 60 seconds
| Question | Short answer |
|---|---|
| What is it? | A cloud service for high-speed file and folder exchange. |
| What moves the data? | IBM Aspera FASP high-speed transport technology. |
| Where can the data live? | IBM-managed cloud storage, other cloud storage, or customer-managed on-premises storage. |
| Can external users collaborate? | Yes. AoC is designed for sharing across users and even separate organizations. |
| Can existing HSTS infrastructure be used? | Yes. Customer-managed IBM Aspera HSTS servers can be attached as tethered nodes. |
A simple way to think about it is:
User → Aspera on Cloud → Aspera transfer engine → cloud or on-premises storage
AoC provides the collaboration and control experience; FASP provides the high-speed transport; the actual content can remain in different storage locations.
Why FASP matters
Traditional file transfer protocols can struggle when files are large, latency is high, or the sender and receiver are geographically far apart. Aspera uses FASP to move large data sets efficiently across those conditions without making file size, type or file count the design constraint.
Aspera on Cloud is not just cloud storage with an upload button — it is a collaboration layer built around Aspera's high-speed transfer technology.
Security is built into the service
The service description calls out five security and resiliency capabilities that are worth remembering.
| Capability | What it gives you |
|---|---|
| Encryption | Encryption in transit plus encryption-at-rest options with client- and server-side control. |
| Integrity verification | Each transmitted block can be checked for data integrity. |
| Authentication & access control | Authenticated storage roots, configurable read/write/list access and role-based access controls. |
| Automatic resume | Interrupted files and directories can retry and continue from a checkpoint instead of restarting from zero. |
| Bring Your Own Key | Server-side encryption-at-rest keys can integrate with IBM Key Protect for key lifecycle management. |
The editions at a glance
IBM's service description lists five subscription editions plus a Pay As You Go option. The table below captures the differences that matter most during sizing.
| Edition | Organizations / Workspaces | Included IBM-managed storage | Included egress | Tethered HSTS |
|---|---|---|---|---|
| Essentials | 1 organization / 1 workspace | 1 TB | First 10 TB | Unlimited |
| Standard Plus | 1 organization / 100 workspaces | 10 TB | First 100 TB | Unlimited |
| Advanced | 1 organization / unlimited workspaces | 10 TB | First 100 TB | Unlimited |
| Premium | Unlimited organizations / unlimited workspaces | 20 TB | First 250 TB | Unlimited |
| Enterprise | Unlimited organizations / unlimited workspaces | 25 TB | First 500 TB | Unlimited |
| Pay As You Go | 1 organization / 1 workspace | Not included; charged per use | Included in per-GB transfer pricing | 1 tethered node |
What actually changes as you move up the plans?
Storage and egress are only part of the story. Collaboration, automation and administrative scale are the bigger differentiators.
| Feature | Essentials | Standard Plus | Advanced | Premium | Enterprise |
|---|---|---|---|---|---|
| SAML SSO | — | Yes | Yes | Yes | Yes |
| Shared Inboxes | — | Yes | Yes | Yes | Yes |
| Brandable email templates | — | Yes | Yes | Yes | Yes |
| Concurrent automation jobs | — | 5 | 5 | 10 | 10 |
| File deletion policies | 1 | 5 | 10 | 150 | 250 |
| Custom URLs | 1 | 1 | Not specified | 5 | Not specified |
| Recursive search | — | — | — | Yes | Not specified |
| File Preview* | — | — | — | Yes | Yes |
*The source document describes File Preview when AoC is used with client AWS S3 storage and includes additional prerequisites covered later in this post.
Which edition fits which type of deployment?
This is a practical reading of the entitlements, not a replacement for IBM commercial guidance.
- Essentials: a small deployment with one workspace and straightforward file exchange.
- Standard Plus: organizations that need SSO, Shared Inboxes, more workspaces and a small amount of automation.
- Advanced: a single organization that needs unlimited workspaces and more deletion-policy flexibility.
- Premium: larger multi-organization deployments that need more storage, egress, automation, search and access to the Aspera Enterprise software suite.
- Enterprise: the highest-volume model in this service description, with 25 TB managed storage and the first 500 TB of egress included.
- Pay As You Go: variable or smaller usage where the client does not want to commit to a subscription term or fixed entitlement quantity.
What is a tethered HSTS node?
A tethered node is a client-installed and client-managed IBM Aspera High-Speed Transfer Server connected to the Aspera on Cloud organization. It lets AoC work with storage that remains in the customer's own environment instead of forcing all content into IBM-managed cloud storage.
This is particularly useful in hybrid architectures:
AoC users → Aspera on Cloud → tethered HSTS → customer-managed storage
Most subscription editions in the supplied service description include unlimited tethered HSTS nodes. Pay As You Go includes a single tethered node.
The billing model: three things that sound similar but are not
This is the most important commercial distinction in the document.
| Charge area | What it means | Simple example |
|---|---|---|
| Transfer usage | Data transmitted to and from the Aspera on Cloud service. | Upload 10 GB + download 10 GB = 20 GB of transfer usage. |
| Egress | Cloud-provider cost for data leaving the infrastructure provider. | Usage beyond the included egress allowance can incur pass-through overage charges. |
| Storage | IBM Aspera-managed IBM Cloud Object Storage included with subscription editions. | Usage above the included storage plus any pre-purchased storage is charged as overage. |
The 10 GB example that makes transfer billing clear
If a user uploads a 10 GB file, that is 10 GB of transfer usage. If another user downloads the same file, another 10 GB is counted.
Total transfer usage: 20 GB.
That is why file size alone is not enough when estimating consumption. You need to understand how many times the content enters and leaves the service.
Tethered nodes change the billing picture
The service description makes two useful distinctions:
- AoC-entitled tethered nodes. Transfer activity is measured under the Aspera on Cloud subscription.
- Separately licensed perpetual HSTS. A tethered server covered by its own perpetual HSTS or Aspera Enterprise license is not metered or billed through AoC under the same transfer-usage model.
It also states that customer-managed tethered infrastructure is not metered for AoC egress pass-through charges, and customer-owned storage attached through supported Aspera mechanisms is not billed as AoC managed storage.
Optional capacity: storage and egress
If the included capacity is not enough, the service description provides additional options.
- Additional Storage: pre-purchase more IBM Aspera-managed IBM Cloud Object Storage.
- Additional Egress: pre-purchase more egress capacity.
- Storage Pay Per Use: pay for storage consumed above included and pre-purchased capacity.
- Egress Pay Per Use: pay for egress above the included and pre-purchased allowance.
File Preview has an important prerequisite
Premium and Enterprise list File Preview when AoC is used with client AWS S3 storage. The client must generate the preview from its own AWS Lambda instance.
The service description also requires the client to build a container image containing FFmpeg. IBM does not provide or manage FFmpeg, and the client is responsible for assessing codec licensing requirements.
In other words: File Preview is a capability with customer-side AWS and FFmpeg responsibilities, not simply a switch that IBM turns on.
What enabling software comes with each model?
| Edition | Enabling software listed in the service description |
|---|---|
| Essentials | Aspera clients + HSTS |
| Standard Plus | Aspera clients + HSTS + Aspera Proxy + HTTP Gateway |
| Advanced | Aspera clients + HSTS + Aspera Proxy + HTTP Gateway |
| Premium | Aspera clients + IBM Aspera Enterprise software suite |
| Enterprise | Aspera clients + IBM Aspera Enterprise |
| Pay As You Go | Aspera clients + HSTS |
The client software list in the source includes Aspera Connect, Aspera on Cloud Mobile, Aspera Desktop Client, Aspera CLI and Aspera Cargo.
Service availability and support
IBM defines service availability at the Cloud Service level and associates subscription credits with monthly availability thresholds.
| Monthly availability | Service credit |
|---|---|
| Less than 99.9% | 2% of monthly subscription fee |
| Less than 99.0% | 5% |
| Less than 95.0% | 10% |
The applicable claim process, support severity levels, response times and support hours are handled through IBM's Cloud Service support documentation. Optional enhanced support offerings can also be purchased.
Six questions I would answer before selecting a plan
- How much data will actually move? Count uploads and downloads, not just stored file size.
- How much cloud egress do we expect? Transfer usage and cloud-provider egress are separate concepts.
- Where should the files live? IBM-managed storage, your own cloud storage, or on-premises storage behind tethered HSTS.
- How many organizations and workspaces are required? This can eliminate lower editions quickly.
- Do we need SSO, Shared Inboxes or automation? Those collaboration features are major tier differentiators.
- How is HSTS licensed? An AoC-entitled tethered node and a separately licensed perpetual HSTS server have different metering implications.
What people usually misunderstand
| Common assumption | Better way to think about it |
|---|---|
| “AoC means all my data must move into IBM storage.” | No. AoC can work with cloud and on-premises storage, including customer-managed tethered HSTS. |
| “A 10 GB file means 10 GB of usage.” | Not necessarily. Upload plus download of that file is 20 GB of transfer usage. |
| “Transfer usage and egress are the same charge.” | No. The service description treats transfer usage, infrastructure-provider egress and storage as separate concepts. |
| “Higher editions only buy more storage.” | No. SSO, Workspaces, Shared Inboxes, automation, search and organization scale are major differentiators. |
| “File Preview is completely IBM-managed.” | Not in the documented AWS S3 model; the client has Lambda, container and FFmpeg responsibilities. |
Final take
The cleanest way to evaluate IBM Aspera on Cloud is to separate it into four decisions: how users collaborate, where the content lives, how the data is transferred, and how that movement is metered.
If the requirement is simply one workspace and moderate file exchange, the entry tiers are easy to understand. Once you introduce SSO, many workspaces, multiple organizations, automation, large egress volumes or customer-managed HSTS infrastructure, the edition choice becomes an architecture and consumption decision rather than just a storage-size decision.
For hybrid environments, tethered HSTS is especially important: it lets the Aspera on Cloud experience sit above customer-managed infrastructure without forcing every workload into the same storage model. That is where AoC becomes more interesting than a conventional cloud file-sharing service.