Data security for Amazon S3.

Amazon S3 can store and retrieve vast amounts of data from anywhere – and the Immuta native integration with Amazon S3 Access Grants can protect that data, regardless of format, at enterprise scale. Immuta builds on S3 security controls for structured and unstructured data stored in S3, so all downstream users can request, access, and put that data to work – quickly, securely, and confidently.

Immuta impact

Put your Amazon S3 data to work.

With the Immuta native S3 integration, you can:

Simplify operations

Simplify operations.

Manage 93x fewer data policies while also improving transparency.

Improve data security

Improve data security.

Granular security for structured data in S3.

Unlock data’s value

Unlock value.

100x faster access to data in S3 – all with less risk.

“By leveraging this new release by Immuta and AWS, we envision a single control plane for Booking.com data owners and governors to manage access at scale for all S3 resources ingested into our data lake (both structured and unstructured). Moreover, as this integration is based on a new S3 native access control capability, it gives us confidence that controls will be enforced consistently, no matter which technology data consumers will choose to access the data.”

Luca Falsina, Principal Software Engineer, Booking.com
Key Capabilities

The Immuta + S3 architecture.

The Immuta integration with Amazon S3 allows you to leverage attributes to map object access to users or IAM roles. Using Amazon Macie to detect file contents, Immuta attaches data source-level tags to the S3 prefix-based data sources via the Immuta UI or API. Those tags are then used to create policies that protect data sources at the S3 prefix level.

Why Immuta

Benefits of Immuta for S3 security.

Amazon S3 only

  • Standard controls for static access control patterns
  • Limited scalability (5KB on IAM policies and 20KB on buckets)
  • Policies must be rewritten for each platform
  • No data usage monitoring or risk remediation
  • No sensitive data discovery or customizable classification

Amazon S3 with Immuta

  • 93x fewer policies required with dynamic controls
  • Centralized policy management provides transparency and consistency
  • Local and global policies ensure robust, flexible access control
  • Policies extended to Amazon EMR Spark workloads for complex processing
  • Proactive data monitoring and compliance auditing
use cases

Put S3 data to work with Immuta.

Immuta allows customers to maximize their investment in S3 by modernizing data access, simplifying data security, and enabling data mesh architectures.

Train and deploy RAG-based AI models.

As organizations adopt AI applications, RAG-based GenAI systems enable customization without adding intensive resource constraints. Immuta works with Amazon S3 to protect structured and unstructured data that is fed into these systems, so you can safely deploy RAG-based AI models by filtering inputs and responses at runtime with attribute-based controls.

Simplify data security and monitoring.

By separating policy from platform, Immuta consistently enforces policies across S3 and any other platform in your tech stack, including Amazon EMR and Amazon SageMaker. This gives you more control and visibility into how data is being protected, accessed, used, and shared across various AWS platforms, as well as other leading cloud providers such as Snowflake and Databricks.

Efficiently publish data products for data marketplaces.

For organizations leveraging S3 within a data marketplace, Immuta allows data product owners to efficiently publish data products, while giving data stewards and domain owners – those who know the data best – responsibility for their data management. This frees up IT bottlenecks and supports data use across business units, allowing you to increase agility with speed and scale.

See a demo of Immuta with Amazon S3.