Make stolen data useless. With HyperSphere DNA™ for AWS, compromised S3 credentials alone do not result in data exposure, and data exfiltrated from S3-compatible object storage remains unreadable by human or machine.
Traditional cybersecurity focuses on preventing attackers from getting in. HyperSphere DNA™ (Data Neutralization Appliance) takes a fundamentally different approach to protecting unstructured data. It assumes attackers will compromise cloud infrastructure or storage credentials, assumes breach, and ensures that stolen data remains unreadable.
This approach is sometimes associated with the emerging category of cyberstorage (security built into the storage layer itself). HyperSphere DNA actually neutralizes data before it's written to storage, so exfiltrated objects are unreadable by design, not just access-controlled.
Unlike conventional encryption, which relies on persistent keys that can be compromised along with the data, HyperSphere DNA uses ephemeral key derivation: keys exist only for the instant they're needed, then are destroyed.
How it works:
Deploys as a transparent layer between applications and S3-compatible object storage, using standard S3 API calls; no application code changes required
Intercepts every write, segments data, and uniquely encrypts (AES-256-GCM) each frame with an ephemeral key
Authorized applications continue reading and writing data normally, with no disruption to performance or workflow
Keys are generated at the moment of need and immediately zeroized, never stored or transmitted
Forwards only ciphertext to object storage; no plaintext ever leaves the node
Without persistent keys, exfiltrated data remains unreadable by attackers, even AI and quantum computers
Security posture:
Runs on hardened Ubuntu instances with a minimal attack surface
No default credentials; IMDSv2 enforced; least-privilege instance role
Bundled Prometheus and Grafana for operational visibility
Depending on jurisdiction, data that remains unintelligible after exfiltration may qualify for reduced breach notification obligations, supporting security and compliance objectives alongside technical protection.
Available in five tiers: Developer, Team, Business, Capacity, and Enterprise/Gov.
Highlights
Deploy in minutes: Data neutralization appliance drops in between applications and S3-compatible storage with no code changes required.
Data security that outlasts a breach: Stolen data stays unusable even when cloud infrastructure or S3 storage credentials are compromised.
No key to find, ever: Keys are ephemeral. There's no persistent key material anywhere an attacker, now or years from now, could find.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 30 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
HyperSphere DNA™ (Data Neutralization Appliance) for AWS
You pay by the hour based on the AWS EC2 instance size you run this appliance on. Four instance options are available: t3.medium, m7i.large, m7i.xlarge, and m7i.2xlarge. Each option reflects a different amount of compute and memory, so you choose the size that matches your workload. Pricing scales with the instance you select and the number of hours it runs. You are not charged per gigabyte of data processed. Billing runs through your existing AWS account, so hourly charges appear on your AWS bill.
Top-of-mind questions for buyers
What am I actually running for each hourly instance charge?
Each hourly charge covers the appliance running on one AWS EC2 instance of the size you pick. The appliance sits between your applications and S3-compatible storage, encrypting and decrypting data as it passes through. Larger instance sizes provide more compute and memory for higher concurrent throughput.
Am I charged when the appliance instance is stopped or idle?
Hourly software charges accrue only while the instance runs. A stopped instance does not accrue hourly software fees. Note that stopped instances may still incur underlying AWS storage costs for attached volumes, billed separately by AWS. The software meter counts running time only.
Does my bill change based on how much data the appliance processes?
No. Cost depends only on the instance size you select and the hours it runs. There is no per-gigabyte metering. Data volume and bandwidth passing through the appliance do not change your hourly rate. To handle more throughput, you choose a larger instance size, which changes the hourly rate.
www.hyperspheretech.com+1
Helpful?
Vendor refund policy
Refund requests are reviewed on a case-by-case basis. Customers may request a refund within 30 days of purchase for material product issues, deployment failures, or billing errors. Refunds are not provided for change of mind, unsupported environments, or partially used subscription periods. HyperSphere will make reasonable efforts to resolve technical issues prior to approving any refund.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
GA 1.0
Additional details
Usage instructions
HyperSphere DNA deploys as a single virtual machine instance inside your cloud environment. It acts as an S3 compatible encryption proxy: your application writes to HyperSphere DNA using standard S3 API calls, and every object is encrypted with before being stored in your own object storage bucket. No plaintext ever leaves the node. No encryption key is ever persisted.
Email support@hyperspheretech.com with your AWS account ID and Marketplace agreement ID, this automatically creates a support ticket and you'll receive a confirmation with your ticket number. Your activation token and license API URL will follow (typically within one business day). Do not skip this step; the AMI will not activate without the token. Prefer a portal? Register at support.hyperspheretech.com/helpdesk and submit your request there instead, either way works, and the portal lets you track all your requests in one place.
Launch the HyperSphere DNA AMI into your VPC (private subnet recommended). Require IMDSv2. Open inbound HTTPS to your application CIDR; open or SSH SSM only to your admin CIDR. The instance needs outbound HTTPS to the HyperSphere license API and to your storage/OIDC endpoints.
SSH or SSM to the instance and run first-boot setup:
sudo /opt/securestorage/setup.sh
--non-interactive --role node
--account-license <ACTIVATION_TOKEN_FROM_HYPERSPHERE>
--license-api https://api.hyperspheretech.com
--domain <YOUR_DNS_NAME>
--tls letsencrypt
...plus OIDC and storage-target flags from the deployment guide...
Use https://api.hyperspheretech.com for --license-api.
Complete the key ceremony / unseal steps in the deployment guide (ssctl). The appliance stays sealed and will not serve data until unsealed.
Point your S3 clients at https://<YOUR_DNS_NAME> (SigV4). Confirm health with GET /health and GET /ready.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
HyperSphere DNA™ is a centralized management console for HyperSphere DNA deployments. Deploy alongside two or more DNA nodes to manage vaults, access credentials, monitoring dashboards, and audit logs across your entire encryption fleet from a single interface.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.