Make stolen data useless. With HyperSphere DNA™ for AWS, compromised S3 credentials alone do not result in data exposure, and data exfiltrated from S3-compatible object storage remains unreadable by human or machine.
Traditional cybersecurity focuses on preventing attackers from getting in. HyperSphere DNA™ (Data Neutralization Appliance) takes a fundamentally different approach to protecting unstructured data. It assumes attackers will compromise cloud infrastructure or storage credentials, assumes breach, and ensures that stolen data remains unreadable.
This approach is sometimes associated with the emerging category of cyberstorage (security built into the storage layer itself). HyperSphere DNA actually neutralizes data before it's written to storage, so exfiltrated objects are unreadable by design, not just access-controlled.
Unlike conventional encryption, which relies on persistent keys that can be compromised along with the data, HyperSphere DNA uses ephemeral key derivation: keys exist only for the instant they're needed, then are destroyed.
How it works:
Deploys as a transparent layer between applications and S3-compatible object storage, using standard S3 API calls; no application code changes required
Intercepts every write, segments data, and uniquely encrypts (AES-256-GCM) each frame with an ephemeral key
Authorized applications continue reading and writing data normally, with no disruption to performance or workflow
Keys are generated at the moment of need and immediately zeroized, never stored or transmitted
Forwards only ciphertext to object storage; no plaintext ever leaves the node
Without persistent keys, exfiltrated data remains unreadable by attackers, even AI and quantum computers
Security posture:
Runs on hardened Ubuntu instances with a minimal attack surface
No default credentials; IMDSv2 enforced; least-privilege instance role
Bundled Prometheus and Grafana for operational visibility
Depending on jurisdiction, data that remains unintelligible after exfiltration may qualify for reduced breach notification obligations, supporting security and compliance objectives alongside technical protection.
Available in five tiers: Developer, Team, Business, Capacity, and Enterprise/Gov.
Highlights
Deploy in minutes: Data neutralization appliance drops in between applications and S3-compatible storage with no code changes required.
Data security that outlasts a breach: Stolen data stays unusable even when cloud infrastructure or S3 storage credentials are compromised.
No key to find, ever: Keys are ephemeral. There's no persistent key material anywhere an attacker, now or years from now, could find.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour for running this appliance on a single c7g.large ARM-based compute instance. Billing is usage-based, so charges accrue for each hour the instance runs. There is one pricing dimension, tied to that instance size, and your hourly software cost stays the same regardless of how much data you protect. You deploy the appliance in your own AWS environment, and it sits between your applications and S3-compatible storage. AWS infrastructure charges for the underlying instance apply separately from this hourly software rate.
Top-of-mind questions for buyers
What resources do I get with the c7g.large hourly rate, and what does the appliance actually do?
The rate runs the appliance on one c7g.large ARM-based instance. It sits between your applications and S3-compatible storage. It splits files into frames, encrypts each with a per-frame key derived in memory, then discards the keys. Applications use standard S3 API calls with no code changes.
Am I charged more if I protect more data or add more S3 buckets?
No. The hourly software rate is tied to the running instance, not data volume. You are billed per hour the c7g.large instance runs, regardless of how many objects or buckets it protects. AWS storage and infrastructure charges for the underlying resources apply separately.
Am I charged when the appliance instance is stopped or not processing requests?
The software rate meters each hour the instance runs. A fully stopped instance does not accrue this hourly software charge. The appliance bills on running time, not on the number of read or write operations it handles. Underlying AWS storage fees may still apply while stopped.
www.hyperspheretech.com+1
Helpful?
Vendor refund policy
Refund requests are reviewed on a case-by-case basis. Customers may request a refund within 30 days of purchase for material product issues, deployment failures, or billing errors. Refunds are not provided for change of mind, unsupported environments, or partially used subscription periods. HyperSphere will make reasonable efforts to resolve technical issues prior to approving any refund.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
This release adds native AWS Marketplace entitlement and metered-billing support, including signed entitlements, protected-data limits, and subscription lifecycle handling. It also strengthens Marketplace node communications and adds automated secure initialization for AWS deployments.
Additional details
Usage instructions
HyperSphere DNA deploys as a single virtual machine instance inside your cloud environment. It acts as an S3 compatible encryption proxy: your application writes to HyperSphere DNA using standard S3 API calls, and every object is encrypted with before being stored in your own object storage bucket. No plaintext ever leaves the node. No encryption key is ever persisted.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Make stolen data useless. With HyperSphere DNA™ for AWS, compromised S3 credentials alone do not result in data exposure, and data exfiltrated from S3-compatible object storage remains unreadable by human or machine.
Cisco DNA Center Virtual Appliance extends Cisco's industry leading on-premise network controller and network management solution. The virtual form factor allows for a geo-distributable architecture, rapid and agile deployment, and optimized IT spending.
HyperSphere DNA™ is a centralized management console for HyperSphere DNA deployments. Deploy alongside two or more DNA nodes to manage vaults, access credentials, monitoring dashboards, and audit logs across your entire encryption fleet from a single interface.
The VM-Series Next Generation Firewall (NGFW) gives security teams complete visibility and control over all networks using powerful traffic identification, malware prevention, and threat intelligence technologies.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.