DataSunrise Security secures databases and data in real-time. DataSunrise includes Database Activity Monitoring (DAM), Dynamic Data Masking, Static Data Masking, Sensitive Data Discovery, Compliance Automation and Vulnerability Assessment. DataSunrise secures all major SQL and NoSQL databases, data-warehouses and data lakes on AWS: all RDS database engines(PostgreSQL, MySQL, MariaDB, Oracle, MSSQL), Amazon Aurora, DynamoDB, Redshift, Athena, Elasticsearch, S3. DataSunrise secures other databases such as SAP HANA,Oracle, Cassandra, Impala, Heroku, DB2, Greenplum, MongoDB, Netezza, Hive, Vertica. DataSunrise enables PII and PHI data protection, auditing, discovery, compliance with privacy law,SOX, HIPAA, ISO27001, PCI or GDPR. DataSunrise gives customers full and granular control over security of sensitive data, access to data and databases and automated compliance policies. DataSunrise empowers organizations when moving their databases workload to db managed services, preserves same level of data security and data auditing. DataSunrise High-Availability, Autoscaling and Failover for AWS, all available DataSunrise instances monitored and configured from a single console. Authentication proxy, Active Directory and LDAP support. Integration with CloudWatch and IAM and SIEM.
Highlights
Why Take Chances with Database Security. Database Security Is Essential
Secure and mask data, and control of all activity and DAM in RDS, Redshift or other databases
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
This listing carries no software charge, so both options are free to use. You choose between two AWS instance sizes for running the deployment: t3.medium and t3.small. Both are billed hourly, and your only cost comes from the underlying AWS compute. The two dimensions are not feature tiers; they differ by instance capacity. Pick t3.small for lighter workloads or t3.medium when you need more compute headroom. Your total scales with how many hours each instance runs and which size you select.
Top-of-mind questions for buyers
What does one hourly unit of t3.medium or t3.small actually give me?
Each unit maps to one AWS EC2 instance of that size running the software. The t3.small provides less compute capacity; the t3.medium provides more. The listing adds no software charge, so you pay only the standard AWS rate for running that instance size per hour.
Am I charged when I stop or pause the instance running this deployment?
The software carries no charge, so stopping an instance removes hourly compute costs for that instance. Stopped instances may still incur underlying AWS storage fees for attached volumes. Metering follows running time, so costs accrue only while the t3.small or t3.medium instance is active.
Can I run more than one instance for continuous protection?
Yes. You can deploy multiple instances with load balancing and redundancy for always-on operation, or a single instance for initial scans and periodic reviews. Each running instance accrues its own hourly compute cost. Your total scales with instance count, size, and hours run.
www.datasunrise.com
Helpful?
Vendor refund policy
This product is offered free of charge. Because no fees are collected, refunds do not apply. For any questions or support requests, please contact us at support@datasunrise.com
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
DataSunrise Data Security Posture Management (DSPM) is a comprehensive enterprise solution for managing data security and compliance across multi-cloud infrastructure. This CloudFormation template deploys a fully configured DSPM instance in approximately 10 minutes, ready to protect your sensitive data.
Key Features:
Automated Data Protection - Discover and classify sensitive data including PII, PHI, PCI DSS, and HIPAA regulated information. Monitor database activity in real-time with threat detection, apply dynamic data masking and access control, and generate complete audit trails for compliance reporting.
Multi-Cloud Support - Unified security management across AWS (RDS, Aurora, Redshift, DocumentDB, OpenSearch, Athena, S3, EFS, FSx), Azure (SQL Database, PostgreSQL, MySQL, Cosmos DB, Storage Accounts), and on-premise environments (PostgreSQL, MySQL, Oracle, SQL Server, MongoDB, Cassandra, SAP HANA, and 15+ other databases).
Quick Deployment - Complete infrastructure deployment in ~10 minutes inside your existing VPC, with integrated RDS PostgreSQL for configuration storage, SSL certificates, and CloudWatch monitoring. For private deployments, your VPC must provide AWS API access through NAT or customer-managed VPC endpoints for S3 and Secrets Manager. Estimated monthly cost: $67-90 USD (includes EC2 instances, RDS, storage, and optional monitoring).
CloudFormation Template (CFT)
AWS CloudFormation templates are JSON or YAML-formatted text files that simplify provisioning and management on AWS. The templates describe the service or application architecture you want to deploy, and AWS CloudFormation uses those templates to provision and configure the required services (such as Amazon EC2 instances or Amazon RDS DB instances). The deployed application and associated resources are called a "stack."
Click Continue to Configuration, select your region
Click Continue to Launch - Launch CloudFormation
Configure required parameters:
Stack name (max 47 characters)
Administrator email for notifications
EC2 Key Pair for SSH access
Existing VPC ID, EC2 subnet ID, and RDS DB subnets
Optional: attach existing security groups to allow corporate access to the DSPM console or SSH
Important: For private deployment (DspmInternetAccess=false), the selected VPC/subnet must already provide outbound access to AWS APIs. DSPM bootstrap requires access to AWS Secrets Manager and S3 through NAT Gateway, NAT instance, or customer-provided VPC endpoints for Secrets Manager and S3. Without this access, DSPM cannot retrieve secrets/configuration and the service will not start.
Click Create Stack and wait ~10 minutes
Access DSPM Console
Go to CloudFormation - Stacks - Outputs tab
Copy the WebConsole URL: https://<IP>:8080
Open URL in browser (accept self-signed certificate warning)
Sign In
On DSPM login page, authenticate with AWS
Follow the on-screen instructions
After first login, DSPM will automatically discover data assets in your AWS account:
DSPM deploys DataSunrise instance with auto-configured networking
Add database credentials
Update your application to connect through DataSunrise proxy
Total time: ~15-20 minutes
Discover Sensitive Data
Go to Dashboard - select any database
Click Action - Scan
Select security standards (PCI DSS, HIPAA, GDPR)
Choose information types (SSN, credit cards, PHI, etc.)
Click Start Discovery
Review results
What Gets Deployed
DSPM Instance (t3.medium): Web console on port 8080 with IAM role for AWS access
DataSunrise Reference (t3.small): Reference instance for validation
PostgreSQL RDS (db.t3.micro): DSPM configuration and data storage
Network resources: Default security groups in the selected VPC; customer-managed security groups can be attached for corporate access
S3 Bucket: Terraform state cache
Secrets Manager: Auto-generated credentials and encryption keys
IAM Role: Minimally privileged role for AWS resource discovery and protection
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
DataSunrise Database & Data Security, Database Activity Monitoring, Data Masking, Sensitive Data Discovery. This offer supports securing only one database instance. Please contact awsmp_sales@datasunrise.com if want to provision for more than 2 database instances or to have a private offer created.
Setting up DataSunrise the very first time for our client was honestly a little intimidating. The dashboard had way more knobs and buttons than I expected. But after some trial, communication with tech support, and late-night caffeine, things started to make sense. The real breakthrough came when we set up dynamic data masking. Watching sensitive numbers instantly transform into scrambled data—unless the right person logged in—was a bit of a “wow” moment.
What do you dislike about the product?
Nothing’s perfect. Even though DataSunrise is flexible, it took patience to figure out the best way to set up role-based masking. Imho the User Guide was decent, but sometimes when we hit cryptic error messages, it felt like we were playing detective. However their support was available 24/7 , and helped a lot.
What problems is the product solving and how is that benefiting you?
I see that it solves the problem of unauthorized access and data leakage by providing a granular, real-time database Firewall.
Miguel S.
Excellent tool to protect and monitor your Databases
Reviewed on May 29, 2025
Review provided by G2
What do you like best about the product?
It is an excellent database security and monitoring tool that unifies features such as firewall, auditing, vulnerability scanning, and data masking.
What do you dislike about the product?
It requires a lot of knowledge of how to use the tool due to the large number of features and options it has that allow you to create very specific rules.
What problems is the product solving and how is that benefiting you?
It has allowed us to limit the access and actions that can be executed in the databases, in addition to monitoring the security events that occur in them, allowing us to receive alerts and take action in the event of any anomaly or cybersecurity incident that may arise.
Erick W.
I tried it and it works better than I thought.
Reviewed on May 27, 2025
Review provided by G2
What do you like best about the product?
It is easy to install or implement, its configuration is very intuitive, easy to use, its support is efficient and responds quickly. Something interesting is its integration.
What do you dislike about the product?
They should update the manuals and guides, but it is compensated by the support.
What problems is the product solving and how is that benefiting you?
Comply with banking security standards, control user access by groups and schedules, audits, all without touching the database or the need to add anything to the DB.
Financial Services
Perfect security for database
Reviewed on Aug 25, 2022
Review provided by G2
What do you like best about the product?
It's data masking solution is the best and very helpful
What do you dislike about the product?
I believe there could be more solutions which would make it more helpful
What problems is the product solving and how is that benefiting you?
It helps in keeping our database secure and there is minimal risk with this software
Yugal G.
Good and convenient Data Masking tool
Reviewed on Aug 24, 2022
Review provided by G2
What do you like best about the product?
This tool has acted as guard to protect sensitive data to avoid exposure to the outside world. The platform masks sensitive data with encryption code which makes it very secure and makes the supply of data intact. This process is done on a real-time basis and keeps on changing the encryption.
What do you dislike about the product?
There are multiple options but the production team can add vulnerability options also so that the overall protection can be improved. Also the user interface can be improved so that the user does not feels bored while working on this.
What problems is the product solving and how is that benefiting you?
It has helped to secure our database which was quite exposed to the outside world earlier. We had several cyber attacks as well earlier but after we have started using this there is not a single instance of a data breach.