This is the multi-page printable view of this section. .
Cloud Exit Standard
- 1: C1 · No exit toll
- 2: C2 · Whole-data export
- 3: C3 · Standard interfaces
- 4: C4 · No commitment lock
- 5: C5 · Accountable downtime
-
6: Rating method
-
7: Provider registry
-
8: Badge policy
-
9: Scope and non-targets
The Cloud Exit Standard asks one narrow question: does this service preserve the customer’s practical ability to leave? It does not rank product quality, feature depth, market share, or whether buying the service was a good decision.
Five criteria
| ID | Test | Question |
|---|---|---|
| C1 | No exit toll | Does leaving trigger punitive transfer or extraction charges? |
| C2 | Whole-data export | Can the complete usable dataset be exported in bounded time? |
| C3 | Standard interfaces | Can core operations be reproduced through public, implementable interfaces? |
| C4 | No commitment lock | Do commercial commitments preserve a practical path out? |
| C5 | Accountable downtime | Are incidents, remedies, and responsibility auditable? |
Every criterion uses the same page contract: definition → verification → worked example → boundaries and objections. A result is scoped to a product, region, plan, and review date; it is never a timeless verdict on a company.
What this standard is not
- It is not a demand that every workload leave every cloud.
- It is not a security certification, availability benchmark, or purchasing recommendation.
- It is not a moral ranking of providers.
- It does not infer a result from a logo, company size, or deployment model.
The method defines evidence, review, expiry, and appeal. The registry remains empty until an entry clears that process.
1 - C1 · No exit toll
Draft criterion, version 0.1. No provider result is implied by this page.
Definition
A service passes C1 when a customer can move customer-owned data to another operator without charges that are disproportionate to ordinary delivery cost or that make exit economically impractical. The assessed path must be available at useful bulk-transfer scale, not only as a token free allowance.
How to verify
- Define the full export volume, request count, retrieval class, region, and deadline.
- Price every required read, retrieval, API request, transfer, appliance, and support item.
- Compare exit cost with normal monthly service cost and with an independently procurable transfer path.
- Record waivers, eligibility limits, notice periods, and whether the customer must negotiate.
Worked example
For data volume , retrieval price , request cost , and transfer price :
The draft method reports the absolute cost, months of ordinary service cost, and cost per exported unit. A pass/fail threshold will not be fixed until the first public calibration set has been reviewed.
Boundaries and objections
- Network delivery has a real cost; C1 does not require every transfer to be free.
- A documented, automatic exit waiver can count, but a discretionary sales concession cannot.
- Physical transfer appliances can qualify if capacity, lead time, and total cost are practical.
- A low storage price does not offset an exit toll; the two are reported separately.
2 - C2 · Whole-data export
Draft criterion, version 0.1. No provider result is implied by this page.
Definition
A service passes C2 when the customer can export all customer-owned data plus the metadata required to use it elsewhere, in documented formats and within a bounded duration. A dashboard download of only the current visible state is not a whole-data export when history, schema, permissions, versions, or logs are required to reconstruct the service.
How to verify
Inventory primary data, schema, identities and ACLs, versions, audit logs, configuration, keys, and derived indexes. Run an export, restore it into an independent environment, verify counts and checksums, and record elapsed time, rate limits, downtime, and missing semantics.
Worked example
An object store with every object copied but without version history or legal hold metadata is reported as a partial export when those features are in use. A database dump that restores rows but loses roles, extensions, or scheduled jobs is likewise partial, not complete.
Boundaries and objections
- Provider-owned telemetry and proprietary internal models are outside scope unless contracted as customer data.
- A documented transformation is acceptable when the target format preserves required meaning.
- Export existence is insufficient: throughput and restore verification are part of the test.
3 - C3 · Standard interfaces
Draft criterion, version 0.1. No provider result is implied by this page.
Definition
A service passes C3 when the core operations needed to continue the workload are exposed through documented interfaces that independent implementations can reasonably reproduce. “Standard” means open enough to implement and test, not merely widely used under one vendor’s control.
How to verify
List every operation on the critical path, map it to a published specification, exercise the same workload against an independent implementation or adapter, and record incompatible semantics, undocumented extensions, and control-plane dependencies.
Worked example
An S3-compatible data plane may reduce migration work, but compatibility is a test result, not a label. Versioning, multipart upload, retention, checksums, events, and identity semantics must be tested when the workload uses them.
Boundaries and objections
- A proprietary control plane can coexist with a portable data plane; report both.
- An adapter counts only when it is maintained, testable, and does not discard required semantics.
- Commodity protocols do not guarantee operational portability; configuration and identity may still lock the workload in.
4 - C4 · No commitment lock
Draft criterion, version 0.1. No provider result is implied by this page.
Definition
A service passes C4 when commercial commitments do not turn an otherwise portable workload into an economically stranded one. Commitments are not a failure by themselves; the test measures term, unused balance, scope, transferability, cancellation, and the penalty created by leaving early.
How to verify
Record contract duration, committed spend, eligible products, utilization assumption, prepayment, refund and transfer rules, renewal behavior, and the unused obligation at each plausible exit date. Compare the committed effective price with both on-demand cost and the cost of leaving.
Worked example
A three-year discount can lower unit price while increasing total exit cost. The ledger therefore shows at least two values: effective unit cost while the commitment is fully used, and stranded value if the workload exits at month 6, 12, 18, or 24.
Boundaries and objections
- Voluntary commitments can be rational financing choices; the standard does not forbid them.
- Credits tied to one product family are reported differently from credits transferable across the portfolio.
- A nominal cancellation path is not practical if it requires discretionary approval or forfeits most remaining value.
5 - C5 · Accountable downtime
Draft criterion, version 0.1. No provider result is implied by this page.
Definition
A service passes C5 when material downtime leaves an auditable record: timely status, bounded impact, a substantive explanation, corrective action, and the contractual remedy promised to affected customers. Perfect uptime is not the test; accountable failure is.
How to verify
Compare the status timeline, customer-observed impact, incident report, contractual SLA, claim process, compensation, and evidence of corrective work. Record what is public, what is available only to affected customers, and what remains unknown.
Worked example
An incident with a timely status page but no scope, root cause, remediation, or claim path is only partially accountable. A detailed report without a usable remedy may also be partial; transparency and contractual accountability are separate fields before they are combined.
Boundaries and objections
- C5 does not reward long reports for minor incidents or demand disclosure that creates a new security risk.
- Customer error and shared-responsibility failures remain in scope when the provider’s controls or communication materially shaped the outcome.
- SLA credits are evidence of remedy, not proof that the business loss was made whole.
6 - Rating method
Method status: v0.1 draft. It is suitable for calibration and public review, not yet for issuing a badge.
Unit of assessment
The unit is provider + product + region + commercial plan + review date. Company-wide claims are prohibited unless every material product and region in scope has been tested. A result can therefore differ across regions, storage classes, or contract types from the same provider.
Result states
| State | Meaning |
|---|---|
| Pass | Evidence satisfies the criterion in the stated scope. |
| Partial | A practical path exists, but a material limitation remains. |
| Fail | Evidence shows the criterion is not satisfied. |
| Unknown | Evidence is missing, inaccessible, contradictory, or not yet tested. |
| Stale | The review is older than its validity window. |
Unknown is not a failure. Stale is not silently converted into the last known result.
Evidence hierarchy
- Contract, official price page, technical documentation, incident report, or machine-readable provider data.
- Reproducible measurement with inputs, date, region, account class, and raw output.
- First-party operating account with a named organization and bounded workload.
- Independent reporting with links to primary evidence.
- Editorial analysis, clearly labeled and never sufficient by itself for a rating.
Every citation records a collection date. Screenshots preserve transient price or policy states but do not replace a stable URL when one exists.
Review flow
- Scope the exact product, region, plan, and features under test.
- Collect primary sources and archive the source window.
- Reproduce export, interface, or price tests where access permits.
- Review every C1–C5 field and record dissent or unknowns.
- Notify the provider or maintainer of the factual draft when a contact is available.
- Publish the result, evidence bundle, review date, and expiry date together.
- Revisit material changes and the scheduled review window.
The dataset target is a quarterly release. Each individual rating expires after 180 days unless its sources are rechecked. This prevents a missed quarterly release from presenting old information as current.
Corrections and appeals
Anyone may submit contrary evidence. A valid appeal identifies the exact field, scope, date, and primary source or reproducible test. Factual corrections are made promptly with a visible revision note. Method disagreements are recorded and considered for the next standard version; they do not rewrite an old test after seeing the result.
Conflicts of interest
The initiator, Ruohang Feng, sells commercial support for Pigsty, a self-hosted PostgreSQL platform, and may benefit from decisions to self-host databases. Named commercial tools must repeat relevant disclosures on the page that names them. Reviewers record employment, investment, sponsorship, consulting, and competitive interests. Disclosure does not make a claim correct; it lets the reader price the risk while checking the evidence.
Versioning policy
- Standard changes use semantic document versions: major for incompatible criteria, minor for new fields or thresholds, patch for clarifications.
- Dataset releases use a date plus revision and never overwrite a prior published snapshot.
- Provider results point to the exact standard and dataset versions used.
- The registry shows stale and withdrawn states instead of erasing history.
7 - Provider registry
The registry is intentionally empty in v0.1. Publishing a provider name without a complete evidence bundle would turn a standard into an assertion.
Entries will be generated from one reviewed YAML record per assessment under
data/vendors/. The method defines scope, states, expiry,
and appeals. The absence of an entry means not assessed, never approved or
rejected.
8 - Badge policy
No badge asset is issued in v0.1. A badge is a distribution mechanism for a reviewed result, not a logo for the project.
Issuance requirements
- The exact product, region, plan, standard version, review date, and expiry date are visible.
- All five criteria have evidence; an Unknown result cannot be hidden.
- The badge links to the registry record, not to a marketing landing page.
- A material product or policy change suspends the badge until review.
- The project can withdraw a badge while preserving the historical record and reason.
SVG artwork, embed code, and trademark terms belong to a later phase after the method has been calibrated on real assessments.
9 - Scope and non-targets
In scope
- Transfer, retrieval, extraction, or deletion charges that shape exit economics.
- Missing or incomplete bulk export paths.
- Proprietary interfaces and semantics on the workload’s critical path.
- Commitments, credits, and contracts that strand economic value.
- Incident transparency, contractual remedies, and corrective accountability.
Outside scope
- Whether cloud, colocation, managed service, or owned hardware is inherently better.
- Provider size, nationality, ownership, or popularity.
- Product features unrelated to portability.
- A claim that every organization should self-host.
Compute vendors, CDNs, network carriers, colocation facilities, managed service providers, and cloud platforms can all be allies when they make portability real. The boundary follows conduct: selling resources is trade; pricing the fact that a customer cannot leave is rent extraction.