Hemanth Chinnadandluru / Integration & Security
← All Aspera posts

IBM Aspera on Cloud explained: plans, security, storage and billing

2026-08Aspera11 min read

IBM Aspera on Cloud (AoC) is easy to describe as “fast file transfer in the cloud,” but that misses the useful part. It is a SaaS platform for securely exchanging large files and folders across users, organizations, cloud storage and on-premises storage, while IBM Aspera FASP handles the high-speed data movement.

This post strips the service down to what matters when you are evaluating or designing it: how AoC fits into the architecture, the security controls, edition differences, tethered HSTS nodes, and the billing model.

Commercial entitlements in this article are based on IBM Aspera on Cloud Service Description i126-8034-11 dated October 2024. Always validate the current IBM order document before making a commercial decision.

Aspera on Cloud in 60 seconds

Question Short answer
What is it? A cloud service for high-speed file and folder exchange.
What moves the data? IBM Aspera FASP high-speed transport technology.
Where can the data live? IBM-managed cloud storage, other cloud storage, or customer-managed on-premises storage.
Can external users collaborate? Yes. AoC is designed for sharing across users and even separate organizations.
Can existing HSTS infrastructure be used? Yes. Customer-managed IBM Aspera HSTS servers can be attached as tethered nodes.

A simple way to think about it is:

User → Aspera on Cloud → Aspera transfer engine → cloud or on-premises storage

AoC provides the collaboration and control experience; FASP provides the high-speed transport; the actual content can remain in different storage locations.

Why FASP matters

Traditional file transfer protocols can struggle when files are large, latency is high, or the sender and receiver are geographically far apart. Aspera uses FASP to move large data sets efficiently across those conditions without making file size, type or file count the design constraint.

Aspera on Cloud is not just cloud storage with an upload button — it is a collaboration layer built around Aspera's high-speed transfer technology.

Security is built into the service

The service description calls out five security and resiliency capabilities that are worth remembering.

Capability What it gives you
Encryption Encryption in transit plus encryption-at-rest options with client- and server-side control.
Integrity verification Each transmitted block can be checked for data integrity.
Authentication & access control Authenticated storage roots, configurable read/write/list access and role-based access controls.
Automatic resume Interrupted files and directories can retry and continue from a checkpoint instead of restarting from zero.
Bring Your Own Key Server-side encryption-at-rest keys can integrate with IBM Key Protect for key lifecycle management.

The editions at a glance

IBM's service description lists five subscription editions plus a Pay As You Go option. The table below captures the differences that matter most during sizing.

Edition Organizations / Workspaces Included IBM-managed storage Included egress Tethered HSTS
Essentials 1 organization / 1 workspace 1 TB First 10 TB Unlimited
Standard Plus 1 organization / 100 workspaces 10 TB First 100 TB Unlimited
Advanced 1 organization / unlimited workspaces 10 TB First 100 TB Unlimited
Premium Unlimited organizations / unlimited workspaces 20 TB First 250 TB Unlimited
Enterprise Unlimited organizations / unlimited workspaces 25 TB First 500 TB Unlimited
Pay As You Go 1 organization / 1 workspace Not included; charged per use Included in per-GB transfer pricing 1 tethered node

What actually changes as you move up the plans?

Storage and egress are only part of the story. Collaboration, automation and administrative scale are the bigger differentiators.

Feature Essentials Standard Plus Advanced Premium Enterprise
SAML SSO Yes Yes Yes Yes
Shared Inboxes Yes Yes Yes Yes
Brandable email templates Yes Yes Yes Yes
Concurrent automation jobs 5 5 10 10
File deletion policies 1 5 10 150 250
Custom URLs 1 1 Not specified 5 Not specified
Recursive search Yes Not specified
File Preview* Yes Yes

*The source document describes File Preview when AoC is used with client AWS S3 storage and includes additional prerequisites covered later in this post.

Which edition fits which type of deployment?

This is a practical reading of the entitlements, not a replacement for IBM commercial guidance.

What is a tethered HSTS node?

A tethered node is a client-installed and client-managed IBM Aspera High-Speed Transfer Server connected to the Aspera on Cloud organization. It lets AoC work with storage that remains in the customer's own environment instead of forcing all content into IBM-managed cloud storage.

This is particularly useful in hybrid architectures:

AoC users → Aspera on Cloud → tethered HSTS → customer-managed storage

Most subscription editions in the supplied service description include unlimited tethered HSTS nodes. Pay As You Go includes a single tethered node.

The billing model: three things that sound similar but are not

This is the most important commercial distinction in the document.

Charge area What it means Simple example
Transfer usage Data transmitted to and from the Aspera on Cloud service. Upload 10 GB + download 10 GB = 20 GB of transfer usage.
Egress Cloud-provider cost for data leaving the infrastructure provider. Usage beyond the included egress allowance can incur pass-through overage charges.
Storage IBM Aspera-managed IBM Cloud Object Storage included with subscription editions. Usage above the included storage plus any pre-purchased storage is charged as overage.

The 10 GB example that makes transfer billing clear

If a user uploads a 10 GB file, that is 10 GB of transfer usage. If another user downloads the same file, another 10 GB is counted.

Total transfer usage: 20 GB.

That is why file size alone is not enough when estimating consumption. You need to understand how many times the content enters and leaves the service.

Tethered nodes change the billing picture

The service description makes two useful distinctions:

It also states that customer-managed tethered infrastructure is not metered for AoC egress pass-through charges, and customer-owned storage attached through supported Aspera mechanisms is not billed as AoC managed storage.

Optional capacity: storage and egress

If the included capacity is not enough, the service description provides additional options.

File Preview has an important prerequisite

Premium and Enterprise list File Preview when AoC is used with client AWS S3 storage. The client must generate the preview from its own AWS Lambda instance.

The service description also requires the client to build a container image containing FFmpeg. IBM does not provide or manage FFmpeg, and the client is responsible for assessing codec licensing requirements.

In other words: File Preview is a capability with customer-side AWS and FFmpeg responsibilities, not simply a switch that IBM turns on.

What enabling software comes with each model?

Edition Enabling software listed in the service description
Essentials Aspera clients + HSTS
Standard Plus Aspera clients + HSTS + Aspera Proxy + HTTP Gateway
Advanced Aspera clients + HSTS + Aspera Proxy + HTTP Gateway
Premium Aspera clients + IBM Aspera Enterprise software suite
Enterprise Aspera clients + IBM Aspera Enterprise
Pay As You Go Aspera clients + HSTS

The client software list in the source includes Aspera Connect, Aspera on Cloud Mobile, Aspera Desktop Client, Aspera CLI and Aspera Cargo.

Service availability and support

IBM defines service availability at the Cloud Service level and associates subscription credits with monthly availability thresholds.

Monthly availability Service credit
Less than 99.9% 2% of monthly subscription fee
Less than 99.0% 5%
Less than 95.0% 10%

The applicable claim process, support severity levels, response times and support hours are handled through IBM's Cloud Service support documentation. Optional enhanced support offerings can also be purchased.

Six questions I would answer before selecting a plan

What people usually misunderstand

Common assumption Better way to think about it
“AoC means all my data must move into IBM storage.” No. AoC can work with cloud and on-premises storage, including customer-managed tethered HSTS.
“A 10 GB file means 10 GB of usage.” Not necessarily. Upload plus download of that file is 20 GB of transfer usage.
“Transfer usage and egress are the same charge.” No. The service description treats transfer usage, infrastructure-provider egress and storage as separate concepts.
“Higher editions only buy more storage.” No. SSO, Workspaces, Shared Inboxes, automation, search and organization scale are major differentiators.
“File Preview is completely IBM-managed.” Not in the documented AWS S3 model; the client has Lambda, container and FFmpeg responsibilities.

Final take

The cleanest way to evaluate IBM Aspera on Cloud is to separate it into four decisions: how users collaborate, where the content lives, how the data is transferred, and how that movement is metered.

If the requirement is simply one workspace and moderate file exchange, the entry tiers are easy to understand. Once you introduce SSO, many workspaces, multiple organizations, automation, large egress volumes or customer-managed HSTS infrastructure, the edition choice becomes an architecture and consumption decision rather than just a storage-size decision.

For hybrid environments, tethered HSTS is especially important: it lets the Aspera on Cloud experience sit above customer-managed infrastructure without forcing every workload into the same storage model. That is where AoC becomes more interesting than a conventional cloud file-sharing service.

Contact

Working on something similar?

If one of these matches a problem in front of you, I am happy to talk it through.