Listing Thumbnail

    reCost.io - Object-Level Threat Detection for Amazon S3

     Info
    Deployed on AWS
    reCost.io delivers object-level threat detection and access intelligence for Amazon S3. Agentless and read-only, it reveals every identity, AI agent, and MCP client reading your data. The platform detects unusual identities, dormant data becoming active, abnormal reads and writes, denied-access patterns, credential misuse, and direct activity from AI agents, crawlers, and automated tools. reCost analyzes metadata and behavior only, never object contents, and forwards high-signal findings into your existing security stack.

    Overview

    When an identity, an AI agent, or a stolen credential calls the Amazon S3 API directly, the request never crosses a workload. There is no process to instrument and no network path to inspect. Runtime and posture tools have nothing to observe. The only evidence is the S3 server access log, and most organizations never ingest those logs because the volume makes SIEM ingestion uneconomical. The result is an entire access layer that goes unmonitored.

    reCost.io turns those logs into a queryable, object-level record of who and what read, listed, wrote, or deleted every object, and when. Every request is attributed to an IAM identity and user agent through assume-role chains. Each identity is baselined so that deviations in volume, operation mix, timing, and assets touched become findings rather than noise. The record supports investigation years after the fact: supply an object key or a date and receive the complete access history.

    The platform is built for the agentic era. reCost.io identifies AI agents, MCP clients, and external crawlers touching your storage, including the read-only and consent flags they actually operated with. It surfaces agents performing writes where they were assumed read-only, roles declared read-only attempting to copy or delete, and the true consumer behind a presigned URL when the signing role masks the reader.

    Detections span destructive and evasive behavior that only appears in access logs: encryption-based ransomware patterns, bulk deletions and delete-marker floods, lifecycle rules scheduling silent data deletion, versioning or object-lock changes that remove recovery, logging configuration changes, and denied writes from AWS logging services that quietly break log integrity. It also covers enumerate-then-retrieve sequences, dormant prefixes suddenly read, cross-account and cross-region copies, anonymous requests, end-of-life SDKs with known CVEs, and direct object reads that bypass Iceberg, Delta Lake, or Hudi catalogs.

    Deployment takes under an hour with a scoped read-only role. No agents, no per-bucket connectors, no code changes, no CloudTrail data-event costs, and object contents are never read. Curated findings route into your existing SIEM, SOC, or ticketing workflow while billions of log lines remain in your own account. reCost.io operates at hundreds of billions of objects and roughly 100 billion requests per month, with retention long enough to support audit and investigation.

    Highlights

    • Sees what workload tools cannot. Direct-to-storage access never crosses a workload, so runtime and posture tools have nothing to observe. The evidence exists only in S3 access logs, which most teams never ingest because SIEM volume pricing makes it uneconomical. reCost.io processes 100 percent of them, with no sampling.
    • Built for AI agents and MCP. Attributes every AI agent, MCP client, and external crawler touching your storage, including the read-only and consent flags they actually ran with. Detects agents writing where they were assumed read-only, and identifies the true consumer behind presigned URLs when the signing role masks the reader.
    • Agentless, read-only, and metadata only. Deploys in under an hour with a scoped read-only role. No agents, no per-bucket connectors, no code changes. Object contents are never read. Curated findings flow into your existing SIEM or ticketing system while the full log volume stays in your own account.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    reCost.io - Object-Level Threat Detection for Amazon S3

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (3)

     Info
    Dimension
    Description
    Cost/12 months
    Startup
    Up to 500 TB
    $5,000.00
    Business
    501 TB to 2 PB
    $18,000.00
    Enterprise
    2+ PB
    $60,000.00

    Vendor refund policy

    reCost.io does not offer refunds. However, we provide a 3-week free trial so customers can evaluate the platform before committing to an annual subscription. If you have any questions or need assistance, please contact us at support@recost.io .

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Support Email: support@recost.io 

    Customers receive email support with response times under 24 hours. Our team assists with onboarding, IAM role configuration, log source validation, detection tuning, and SIEM or ticketing integration. Enterprise customers receive priority support, including direct access to our engineering team for investigation assistance and custom detection development. Documentation and onboarding guides are available through our support portal.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.