Blast Preemptive Cloud Defense Platform turns cloud security from reactive firefighting into proactive protection.
Driven by your cloud context, Blast Compiler transforms your security strategy into tailored preventive guardrails. Over the pillars of identity, data, workloads, and networks, Blast utilizes your native security controls into one unified defense fabric. The platform leverages context-aware simulation layers to confidently validate and enforce those guardrails, with zero business disruption.
The result: a cloud environment secured by default, a security team empowered to innovate rather than remediate, and an organization that consistently stays ahead of threats.
Highlights
Proactive Cloud Security: Prevent misconfigurations and threats before they happen, ensuring your cloud environment remains secure by default.
Seamless Multi-Cloud Support: Easily apply security guardrails across AWS, Azure, GCP, and Kubernetes environments for consistent, scalable security enforcement.
Continuos Impact Simulations: Validate security configurations with real-time simulations, ensuring full compliance and zero business disruption with every change.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing uses a contract-based pricing model with a single dimension measured in Units. Pricing is not published on the Marketplace. Instead, you arrange terms through a private offer by contacting the seller at aws-marketplace-seller@blast.security. Because there is one custom dimension, the cost and unit quantity are set during that direct negotiation rather than through fixed public tiers. You commit to the agreed contract terms and quantity once the private offer is finalized.
Top-of-mind questions for buyers
What does one unit of the Blast Preemptive Cloud Defense Platform represent for billing?
The Marketplace lists a single Units dimension without a public definition of what one unit maps to. Because pricing is arranged through a private offer, the unit meaning and quantity are set during that direct negotiation. Contact the seller at aws-marketplace-seller@blast.security to confirm how units apply to your cloud accounts.
What does the platform actually do that I am paying for under this contract?
You get an agentless, API-based enforcement layer that turns native cloud controls into preventive guardrails. It follows an Assess, Plan, Simulate, and Enforce cycle. It reads metadata only and needs no agents. It orchestrates controls like service control policies, permission boundaries, and organization policies across your cloud accounts.
How is cost set since no price appears on the Marketplace?
This is a contract model with no published price. You do not pay per hour or by pay-as-you-go usage. Instead, you agree to a fixed unit quantity and term through a private offer negotiated directly with the seller. Charges apply once you accept those agreed contract terms.
blast.security
Helpful?
Vendor refund policy
Due to the nature of our product, we do not offer refunds after purchase. All sales are final. If you have any questions or concerns about your purchase, please contact our support team at support@blast.security, before completing your transaction. We are here to assist you and ensure your satisfaction with our service.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Additional details
Usage instructions
☁️ Connecting AWS Cloud Accounts
Setting Up the Blast Role
To enable secure integration between Blast Security and your AWS environment, you'll need to deploy a set of predefined IAM roles using AWS CloudFormation. These roles grant read-only access via AWS STS, allowing Blast to collect data and simulate enforcement impact across your organization.
<Note>
This setup uses a **CloudFormation StackSet** for member and log-archive accounts, and a standalone **CloudFormation Stack** for the management account **with the same template**.
</Note>
AWS CloudFormation Deployment
🔧 Prerequisites
Before deployment, ensure you have the following:
Administrator access to AWS CloudFormation.
AWS Organizations configured with:
Management Account
Member Accounts
Log-Archive Account (The CloudTrail S3 Bucket Account)
ARN of your CloudTrail S3 bucket (in the Log-Archive account).
(Optional) ARN of the KMS key used for CloudTrail log encryption.
ExternalId provided by the Blast team.
1️⃣ Deploy Roles to Member & Log-Archive Accounts (StackSet)
Accounts: All AWS Member Accounts + Log-Archive Account\
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Rubrik Security Cloud is a comprehensive, SaaS-delivered platform providing enterprise-scale, agentic cyber resilience. Purpose-built for AWS ecosystems, Rubrik offers frictionless deployment and intelligent auto-discovery to instantly secure Amazon EC2, RDS, DynamoDB, S3, and other AWS resources alongside multi-cloud and hybrid environments, with zero infrastructure to manage.
Rubrik Agent Cloud enables organizations to deliver AI transformation and deploy agents at scale with confidence. As the first agent operations platform for the enterprise, it is built to monitor agent actions, govern agent behavior, and remediate mistakes before they spread.
While AI agents accelerate innovation, they introduce significant risks, such as hallucination and cyber compromise. Rubrik Agent Cloud solves this by monitoring and auditing agentic actions, enforcing real-time guardrails for agentic changes, and undoing agent mistakes. It is the ultimate enterprise control layer for the entire AI agent lifecycle, helping you unleash AI without risk.
Advanced threat prevention security for AWS and hybrid cloud environments, with Threat Extraction and Threat Emulation, and with GWLB (starting with R81.20)
**Please note: To ensure optimal operations, Check Point recommends a 4 vCores machine size. This provides balanced efficiency and smooth performance, which most customers find ideal for their needs.
Advanced threat prevention security for AWS and hybrid cloud environments, with Threat Extraction and Threat Emulation.
**Please note: To ensure optimal operations, Check Point recommends a 4 vCores machine size. This provides balanced efficiency and smooth performance, which most customers find ideal for their needs.
Blast is a high-performance API and development tooling platform focused on providing access to blockchain nodes for Web3 developers.
Leveraging an advanced smart routing system and a proprietary cloud architecture optimized for blockchain infrastructure, Blast stands out as one of the most reliable and fastest API and node providers in the Web3 space for more than 39 different blockchains. Additionally, we offer the most competitive pricing in the industry, ensuring top-tier performance and affordability for developers and enterprises alike.
Omnissa Horizon on Amazon WorkSpaces Core secures and delivers high-performance virtual desktops and apps to any device, anywhere, optimizing performance for variable network conditions.
Enhanced with Workspace ONE, it provides modern desktop and endpoint lifecycle management, patching, and automated app workflows under unified security controls.
Operating with App Volumes, the solution accelerates application lifecycle management through on-demand delivery, slashing user downtime and pool complexity, while Omnissa DEX continuously measures, analyzes, and remediates issues to guarantee an intuitive, best-in-class employee experience.
Keywords: Virtual desktops and apps, Amazon WorkSpaces Core, Workspace ONE endpoint management, App Volumes application lifecycle management, Omnissa DEX employee experience.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.