S3/AWS multi-factor authentication, in combination with bucket versioning, ensures that if you can keep a redundant offsite record of your key and version information, you can always retrieve your data. An attacker requires your key fob to permanently delete an item. Of course, you'll need to physically secure your key fob.
It has been a while since I looked at S3 and didn't spot multi-factor authentication at the time. At only $13for the fob it seems like an interesting alternative.
http://aws.amazon.com/mfa/