Amazon Macie
Compare with…Macie discovers sensitive data in Amazon S3. Storage classes, file formats and object eligibility limit what it can inspect. Database exports to S3 do not constitute a native database integration. [1]
Discovery & classification [1]
Updated 2 sources
Store and control evidence
Read each documented action together with its limits.
Find sensitive data in S3
Macie inspects supported objects in S3 general-purpose buckets and reads the latest object version. [1]
Directory buckets, S3 Express One Zone and Glacier Deep Archive are excluded. Images, audio and video are not analyzed. Count skipped objects separately from inspected objects. [1]
Data coverage
Read the scope beside each mark. Support for an environment does not establish every capability in every store.
- Microsoft 365
- Unconfirmed
- AWS
- Partial
S3 general-purpose buckets are supported, subject to storage-class, object and file-format limits. [1]
- Google Cloud
- Unconfirmed
- Snowflake and Databricks
- Unconfirmed
- On-prem shares
- Unconfirmed
- SaaS apps
- Unconfirmed
Unconfirmed means the reviewed sources do not establish coverage. How coverage is assessed
Deployment and cost
Pricing
Charges depend on buckets, objects and inspected data. [2]
- Billing
- Bucket monitoring, automated discovery and sensitive-data inspection have separate usage dimensions.
- Additional costs
- S3 request charges can apply. Check the rate for the deployment region.
Deployment architecture and operating workload are not published in the reviewed sources.
Questions for the vendor
- Show which objects were inspected, skipped or excluded, grouped by format, storage class and access failure.
- Seed sensitive examples in supported files and unsupported formats. Show how each appears in results and scan statistics.
- Estimate discovery, repeat scans and S3 request charges for the same buckets and region.