Discover and protect sensitive data and personal identifiable information (PII) in Amazon S3 and Amazon EC2 to support compliance and security mandates. Scan up to 500GB for free during the 30 day free trial.
Data Loss Prevention (DLP) for Amazon S3 and Amazon EC2 is a cloud-based in-tenant solution that leverages data classification to identify sensitive data at petabyte scale and quarantine objects / files across all S3 buckets and EC2 (EBS volumes). Knowing what PII exists and automatically protecting it enables you to proactively manage data privacy and protection as well as compliance with frameworks such as SOC 2, PCI DSS, and HIPAA.
HOW IT WORKS
We have harnessed three decades of DLP experience to give you an automated solution that:
Deploys using an automated serverless architecture
Provides real-time & on-demand DLP scanning
Identifies hundreds of sensitive data types and PII
Covers 11 regional localizations: USA, UK, France, Germany, Ireland, Spain, Australia, Canada, Japan, China, Global
Allows you to tag and quarantine files identified as sensitive or that have PII
Supports robust notifications & integrations - this solution integrates with third party ticketing, Slack, Microsoft Teams, Amazon Chime, SIEM, Amazon SNS, AWS Security Hub, AWS CloudTrail, AWS Control Tower, AWS Transfer Family, and more
DLP for Amazon S3 and EC2 scales automatically to efficiently scan the largest of datasets, with no file size limit. For the next 90 days we are offering this solution completely free. All we ask is that you share your product feedback with us at support@cloudstoragesec.com.
A streamlined installation via an AWS Fargate Container and deployment via an AWS CloudFormation template means you are up and running in about 15 minutes. From there, a few clicks is all it takes to initiate a DLP scan on demand or to schedule it later in the day, week, or month (scanning agents can be configured to meet a wide range of compliance requirements).
Once a scan is complete, a report of the files containing PII and sensitive data is generated, allowing you to see the type of data each file contains as well as the bucket in which it resides.
Additionally, you can identify bucket attributes such as whether it is publicly accessible or encrypted. Cross reference classification and bucket protection findings to determine whether a bucket containing sensitive data is exposed; when combined, data points such as these can be used to assess data risk and prioritize vulnerability management.
You will be alerted to findings via real-time notifications within the console or through AWS SNS. Findings can also be sent to AWS Security Hub, third party ticketing systems, SIEM solutions, Slack, Microsoft Teams, or Amazon Chime.
To further support security and performance, the solution runs in tenant, meaning your sensitive data remains in your AWS account.
EXTEND COMPLIANCE AND SECURITY WITH ADVANCED THREAT PROTECTION
In addition to data privacy and protection requirements, many compliance frameworks and regulations require organizations to implement procedures that protect against advanced threats. Specifically, by scanning for malware and PII. In line with the AWS Shared Responsibility Model, it is the responsibility of the organization using S3 and EC2 to do so.
Through our other solution Antivirus for Amazon S3 solution, Cloud Storage Security provides you with assurance that the files shared across their applications and data lakes are free from malware and risk of data breaches by scanning each item for advanced threats and PII. You can find Antivirus for Amazon S3 in AWS Marketplace at https://aws.amazon.com/marketplace/pp/prodview-q7oc4shdnpc4w.
If you would like to make a long-term purchase of this solution plus our Antivirus for Amazon S3, your organization is eligible to receive discounted pricing; contact us to learn more at support@cloudstoragesec.com.
Highlights
To take advantage of the 30day free trial and scan up to 500GB of data at no charge.
Identifies hundreds of sensitive data types across a variety of file types and 11 regional localizations; looks at bucket configurations
Pinpoint Personally Identifiable Information (PII), financial data, health care information, government ID numbers and more, as well as where it resides, at scale
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay based on how much data you scan each month, measured in gigabytes (GB). Start with a 30-day free trial. The Monthly Subscription includes 100 GB of scanning per month. Beyond that, usage tiers apply as your monthly volume grows: 101-500 GB, 501-1500 GB, 1501-3000 GB, and 3001 GB or more. Separate dimensions cover scanning pre-existing objects already in storage. The Included GBs dimension tracks your bundled scanning allowance. A One Time Fees dimension supports special pricing offers. Together these let billing scale with your actual scan volume.
Top-of-mind questions for buyers
What counts as a scanned gigabyte for billing purposes?
Billing meters the volume of data the product scans, measured in gigabytes. The product scans files in your storage for malware, threats, and sensitive data. Each gigabyte the product processes counts toward your monthly total, which sets your usage tier.
What happens when my monthly scan volume moves from one tier to the next?
Your monthly scan total determines which tier applies. The Monthly Subscription includes 100 GB. Beyond that, tiers cover 101-500 GB, 501-1500 GB, 1501-3000 GB, and 3001 GB or more. The tier follows your actual measured volume for that month, so pricing scales with usage.
Why is scanning pre-existing objects billed separately from ongoing scans?
Pre-existing objects are files already sitting in your storage before you start scanning. This one-time backlog scan uses its own dimension, separate from the monthly usage tiers that meter new and ongoing scan activity. Both charges can appear together on your invoice.
help.cloudstoragesec.com
Helpful?
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.
Subscribing to this product will take you through the sign-up and deployment process. Deployment consists of launching a CloudFormation Template provided to you on the last configuration page of signup (also located in the Help Docs). Once Stack creation is completed, look to the Stack Outputs for the Console access URL and open that in your browser. Any additional deployment and management tasks are performed from within the Console.
If you need help during your 30-day free trial, we are happy to provide email support via support@cloudstoragesec.com. We respond to support requests via email during your 30-day free trial within 24 hours Monday through Friday. We can also provide more in-depth support via phone and web meetings for Proof of Concept (POC) engagements. If you would like more information about initiating a POC, please contact one of our experts at https://cloudstoragesec.com/contact. Cloud Storage Security also offers Premium Support and Professional Service plans for purchase in AWS Marketplace
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Identifies hundreds of sensitive data types including PII, financial data, healthcare information, and government ID numbers across multiple file types and 11 regional localizations
Automated Scanning Architecture
Deploys using serverless architecture with AWS Fargate Container and AWS CloudFormation template, supporting real-time and on-demand DLP scanning at petabyte scale with no file size limit
Data Quarantine and Tagging
Automatically quarantines objects and files identified as sensitive or containing PII across all S3 buckets and EC2 EBS volumes, with capability to tag flagged items
Multi-Channel Notifications and Integrations
Supports robust notifications and integrations with third-party ticketing systems, Slack, Microsoft Teams, Amazon Chime, SIEM solutions, Amazon SNS, AWS Security Hub, AWS CloudTrail, AWS Control Tower, and AWS Transfer Family
Bucket Configuration Assessment
Evaluates bucket attributes including public accessibility status and encryption configuration to cross-reference with classification findings and assess data risk exposure
Multi-Engine Malware Detection
Utilizes 30+ anti-malware engines for malware detection and threat identification.
Real-Time File Scanning
Conducts real-time scanning of files prior to upload to S3 buckets, triggered by S3 events.
Deep Content Disarm and Reconstruction
Implements Deep CDR technology to disarm active embedded threats and reconstruct sanitized file versions to prevent zero-day attacks and advanced evasive malware.
Scheduled and On-Demand Scanning
Supports flexible scanning modes including real-time, scheduled weekly or monthly scans, and on-demand file inspections.
Sensitive Data Detection and Redaction
Automatically detects compliance violations and sensitive data within files, with capability to redact or report identified sensitive information.
Malware Detection Engine
Open-source ClamAV antivirus engine for detecting viruses, worms, trojans, and latest malware threats
Scanning Modes
Real-time, scheduled, on-demand, on-access, and API-based virus scanning capabilities
Automated Threat Response
Automatic tagging, deletion, or quarantine of infected files with immediate notifications via email, Slack, Microsoft Teams, AWS Security Hub, Systems Manager OpsCenter, or Amazon SNS
File Processing Capacity
Support for scanning files up to 2 GB in size across multiple AWS accounts and S3 buckets
Malware Database Updates
Continuous updates to malware signatures to protect against latest and emerging threats
We're a small team with limited time so we needed something quick to deploy and simple to test/use. This was up and running in no time. The level of documentation and support that was provided by this team is impressive.
G.
Up and classifying in no time
Reviewed on Sep 02, 2022
Review from a verified AWS customer
I was able to deploy and configure this tool in about 20 minutes to start testing it out. All you need to do is select your buckets, set your rules, and select the schedule you want it to run on. Really nice that it also deploys in GovCloud and you can bundle it with their Antivirus tool too.