Overview

Product video
Protect data lakes, ingestion pipelines, and application workflows built on AWS storage by scanning for viruses, ransomware, trojans, and other malicious payloads before they propagate downstream.
WHY THIS SOLUTION IS DIFFERENT
- Support for Multiple Data Sources
- Purpose-built for AWS storage
- In-tenant, security-first architecture
- Flexible scanning models
- Static, Dynamic & Forensic Analysis
- Configuration visibility across buckets
- Rapid deployment with minimal operational overhead
SUPPORTED AWS STORAGE Built for AWS storage services including:
- Amazon S3
- Amazon EBS
- Amazon EFS
- Amazon FSx
Engines Identify malware at petabyte scale across all buckets by leveraging the power of Sophos, CSS Premium, or CSS Secure. Engines may be used simultaneously to optimize accuracy and performance.
Scanning Models Integrate the method that fits your needs to minimize process interruptions and eliminate service disruptions. Choose from:
- Event-Based Scanning Scan new or modified objects in real time when uploaded. (easy to integrate into workflows because low or no code changes are needed)
- Retroactive Scanning Scan existing objects on demand or on schedule for baselining and compliance audits.
- API-Based Scanning Scan objects inside or outside of AWS in real time via a REST API before they are written to storage. Ideal for migrations, new application builds, or workflows where scan results determine whether an object is accepted. Analysis Analyze files in real time without having to execute them or by detonating them in a sandbox using the latest analysis techniques; Static and Dynamic Analysis is powered by the SophosLabs Intelix™ Platform. The solution also assists with Forensic Analysis as files are segmented by bucket and account enabling you to trace where the file entered and into which account it was added.
Configurations Identify buckets with secure and insecure permission policies through a unified dashboard to improve visibility into storage misconfigurations.
Setup Deploy via AWS CloudFormation or Terraform in less than 10 minutes. Initial bucket protection and scanning configuration takes less than 5 minutes.
Follow the Getting Started Guide: https://help.cloudstoragesec.com/getting-started/summary/
Security First The solution installs and operates entirely within your AWS account. Data never leaves your environment or region. Optional deployment models include centralized security services accounts, linked account management, and private VPC endpoints.
Case Studies https://cloudstoragesec.com/case-studies
Core Capabilities
- Automated serverless architecture
- Real-time & on-demand scanning
- Centralized management console with dashboards and detailed reporting
- Automatic discovery & scaling across multiple accounts & regions
- No file size or type limitations with CSS Premium
- Problem file remediation (Quarantine, Tag, Delete)
- Notifications and integrations with third-party ticketing systems, Slack, Microsoft Teams, Amazon Chime, SIEM platforms, Amazon SNS, AWS Security Hub, AWS CloudTrail, AWS Control Tower, AWS Transfer Family, and more
ONLY PAY FOR WHAT YOU SCAN Pricing at payment terms that fit with your procurement process. Contact us during your free trial to discuss the best pricing option for you.
NOT TO MISS ARTICLES ON AWS https://aws.amazon.com/blogs/apn/integrating-amazon-s3-malware-scanning-into-your-application-workflow-with-cloud-storage-security/
Highlights
- In-tenant, cloud-native malware scanning for Amazon S3, Amazon EBS, Amazon EFS, and Amazon FSx with no external file transfer.
- Multi-engine virus detection using Sophos, CSS Premium, and CSS Secure with event-based, retroactive, and API scanning models.
- Protect data lakes and application workflows with real-time and on-demand scanning that scales across multi-account AWS environments.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Console Deployment and Permission Setup
- Amazon ECS
Container image
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.