Overview
Data Loss Prevention (DLP) for Amazon S3 & EC2 is an in-tenant solution that leverages data classification to identify sensitive data at petabyte scale. You can then automatically quarantine objects / files across all S3 buckets or tag sensitive data stored in EC2 (EBS volumes), EFS, and FSx to ensure you're protected against data breaches. Knowing where PII exists in your applications and automatically protecting that data enables you to proactively manage data privacy and meet compliance frameworks like SOC 2, PCI DSS, and HIPAA.
HOW THIS SOLUTION IS DIFFERENT We have harnessed three decades of DLP experience to give you an automated solution with:
- Multiple Scanning Models
- Custom RegEx Policy Creation
- Configuration Intelligence
- Simplified Setup
- Security First Approach with In-Tenant Scanning
Scanning Models This solution offers three flexible scanning options that integrate seamlessly into your workflow:
- Event - scan new data in real time when dropped into storage (easy to integrate into workflows because minimal code changes are needed)
- Retro - scan existing data on demand or via schedule (use to baseline data and for compliance audits)
- API - scan data in real time via a REST-based API before they are written (useful for workflows where the scan dictates whether a file should be stored/used based on scan verdict)
Custom RegEx Write custom regular expression (RegEx) policies with the help of our Amazon Bedrock integration. All you need to do is enter a simple text prompt to identify patterns or text and the exact value you need for the rule will be created within the console. The solution also comes with predefined policies for common personally identifiable information items like social security numbers or credit card numbers.
Configurations Quickly gain visibility into misconfigurations including publicly accessible buckets as well as encryption status via a single unified dashboard.
Setup Deploy via AWS CloudFormation or HashiCorp Terraform in less than 10 minutes. Initial scanning setup takes less than 5 minutes with just a few clicks of the mouse. Follow the Getting Started Guide: https://help.cloudstoragesec.com/getting-started/summary/ .
Security First This solution installs and runs in your AWS account, so data never leaves your environment or region. Additional ways to further enhance security include centralized security services account deployment with linked accounts and a private VPC endpoint deployment option.
CUSTOMER-FAVORITE FEATURES
- Automated serverless architecture
- Real-time, scheduled & on-demand scanning
- Easy management console, built-in dashboards & detailed reporting
- Automatic data discovery & scaling across multiple accounts & regions
- XL file scanning
- Problem file remediation (automatic Quarantine, Tag, Delete)
- Robust notifications & integrations - this solution integrates with third party ticketing, Slack, Microsoft Teams, Amazon Chime, SIEM, Amazon SNS, AWS Security Hub, AWS CloudTrail, AWS Control Tower, AWS Transfer Family, and more
ONLY PAY FOR WHAT YOU SCAN Pricing at payment terms that fit with your procurement process. We offer pay-as-you-go pricing, prepaid discounts, and private offers. Contact us at https://cloudstoragesec.com/contact to discuss the best pricing option for you.
EXTEND COMPLIANCE AND SECURITY WITH ADVANCED THREAT PROTECTION In addition to data privacy and protection requirements, many compliance frameworks and regulations require organizations to implement procedures that protect against advanced threats such as ransomware. This solution also offers malware detection and prevention. Identify malicious code at petabyte scale by leveraging the power of Sophos, CrowdStrike, or ClamAV®. Engines may be used individually or simultaneously to optimize accuracy and performance.
Highlights
- Broad support for storage services including Amazon S3, Amazon EBS, Amazon EFS, and Amazon FSx.
- Enterprise-level features including extra large file scanning (up to 5TB), automated custom RegEx policy creation, and built-in prevention.
- This solution runs completely in-tenant so data never leaves your AWS account or VPC for scanning.
Details
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Cost/unit |
---|---|
Free Trial Usage | $0.001 |
Monthly Subscription - includes 100GB of premium engine scanning | $99.00 |
Scanning above 100GB (per GB) | $0.80 |
Premium engine add-on above 100GB (Sophos per GB) | $1.00 |
Malware file static analysis (Sophos per file) | $0.05 |
Malware cloud detonation (Sophos per file) | $0.50 |
Used to track included GB | $0.001 |
One time fee used for special pricing offers | $0.001 |
Premium engine add-on above 100GB (CSS Premium per GB) | $1.00 |
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Console Deployment and Permission Setup
- Amazon ECS
Container image
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.
Version release notes
Additional details
Usage instructions
Subscribing to this product will take you through the sign-up and deployment process. Deployment consists of launching a CloudFormation Template provided to you on the last configuration page of signup (also located in the Help Docs). Once Stack creation is completed, look to the Stack Outputs for the Console access URL and open that in your browser. Any additional deployment and management tasks are performed from within the Console.
For detailed steps on how to subscribe, deploy and use the product, please review: http://help.cloudstoragesec.com/getting-started/how-to-subscribe/
Resources
Vendor resources
Support
Vendor support
If you need help, let us know! Please do not hesitate to contact us with questions or to get started with a proof-of-concept (POC) at https://cloudstoragesec.com/contact . Support engineers are online Monday-Friday and aim to respond to emails within 1 business day. If you need faster response times or technical support over the phone/via video, Premium Support and Professional Service plans are available for purchase; for more information, visit https://cloudstoragesecurity.com/support . Also, customers often find the answers they need in our Help Docs at
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.