
Overview

Product video
*** NOTE: For custom pricing/contract, please contact aws@normalyze.ai for a private offer. Freemium for 1-cloud account available at https://normalyze.ai/freemium ***
Normalyze helps organizations protect all the data they run in the cloud. Normalyze put data security at the center of information security. With Normalyze, users can discover and visualize their cloud data attack surface within minutes and get real-time visibility and control into their security posture, including access, configurations, and sensitive data to secure cloud infrastructures at scale.
Through its agentless assessment, data discovery, data classification, AI driven vulnerability analysis, risk prioritization, and comprehensive remediation insights, Normalyze helps enterprises understand the complete picture when it comes to cloud data risks. That includes everything needed to be discovered and understood around the applications, infrastructure, configurations, vulnerabilities, and the identities and permissions associated with the user and system access.
DISCOVER & ANALYZE
The Normalyze platform initially performs its agentless cloud discovery scan to identify all cloud systems in the environment. During this discovery of cloud resources, Normalyze identifies and prioritizes everything running operationally in the cloud environment and interconnected systems. Normalyze's AI-backend also scrutinizes all structured and unstructured data within the cloud environment. A real-time, visual graph is created of all available cloud resources; what identities have access to these systems, their permissions, and all of the available data stores.
DETECT & PRIORITIZE
After the Discovery phase, Normalyze prioritizes proprietary, regulated, and otherwise sensitive data and ranks it in its importance and risk level. The risks are determined by vulnerability severity, the nature of the data, its access paths, and the condition of its resource configurations.
The agentless Normalyze assessments are continuous. Every time an asset is added, changed, or removed, the graph is instantly updated. In this analysis, the identity and permission information is considered, along with uncovered vulnerabilities and misconfigurations that could lead to a data breach. The AI-driven analysis will look at everything within the cloud environment and identify all of the possible paths to sensitive data and potentially viable attack vectors.
All of the discovered data, whether structured or unstructured, is prioritized based on sensitivity and associated regulatory controls (e.g. PCI DSS, HIPAA, GDPR, etc.). Normalyze will highlight the data that needs immediate attention. The Normalyze one-pass data scanner samples enterprise data to detect sensitive entries (e.g. names, social security numbers, credit card numbers, etc.) within data stores. Normalyze then connects the data via specific profiles to confirm the presence of sensitive and proprietary data. Unique to Normalyze, this scan capability helps customers reduce false-positives and increase efficiency of scans.
IMPORTANT: None of this scan data ever leaves the control of the customer or ever moves to another cloud, nor is it ever transferred to another region or nation. Normalyze only collects metadata necessary to create the visual graph.
REMEDIATE & PREVENT
With cloud assets discovered, data identified and classified, and then remediation prioritized based on sensitivity, enterprise security teams are ready to take steps to remedy the most pressing data risks and work down from there.
As Normalyze identifies risky conditions, its prioritization engine makes all of the conditions that place data at risk so that teams understand what steps they need to remedy the situation. Remediation efforts can be dispatched to a service management platform, or other automated measures can be taken. Specific groups or individuals can be alerted to remedy the vulnerability, or steps can be taken to remove access.
Highlights
- 100% Agentless & autonomous discovery, classification and cataloging for all data and access points across AWS, Azure, GCP, Snowflake and other cloud environments. >> Free tier and trial available at https://normalyze.ai/freemium
- Fully-automated Data Security Posture Management (DSPM) with continuous monitoring, risk detection, and guided remediation.
- Discover, visualize and remediate your cloud data attack surface within minutes. Get real-time visibility and control into your security posture, including access, configurations, sensitive data, and threats.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/month |
|---|---|---|
Normalyze Freemium | Visit: https://normalyze.ai/pricing/ and select Free (1 Cloud Acct) | $0.00 |
Normalyze Premium | Up to 3 cloud accounts; 1TB of data scanning; 60 day graph history | $995.00 |
Normalyze Enterprise T1 | Ent features; 24x7 support; API; Scope limits: please get custom quote | $10,000.00 |
Vendor refund policy
N/A
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Support
Vendor support
Normalyze - Freemium, 1-Cloud Environment Trial Account >> https://normalyze.ai/freemium Normalyze - Cloud Data Security Posture Management Platform // Support Documents >> https://normalyze.ai/resources/documents/ Contact Us >>
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

Standard contract
Customer reviews
AI classification has transformed data visibility and now simplifies policy‑driven protection
What is our primary use case?
I have been dealing with Proofpoint Data Security Posture Management as a distributor. If you are speaking on the Proofpoint data program, that will be three years. However, if you are speaking to the DSPM, which is a point product on its own that was acquired from Normalize, then that is just recently.
What is most valuable?
The features I find most valuable in the product include the AI-powered classification. When you scan your cloud repositories, it finds and classifies data. It does not just discover; it discovers and then classifies the data or the files that it discovers based on the content. For instance, if there is credit card data in a PDF file, it classifies that file as financial, depending on the naming convention. It could be financial, could be PCI DSS, or similar classifications.
It has helped my data security strategy very well because one thing is to set static DLP rules. However, how do you start setting rules when you have little or zero visibility as to where your critical or sensitive data resides? First, you need to discover your data. You do not want to take any actions until you have clear visibility over all of your data and where they reside. Once you have visibility as a result of the discovery, and the DSPM does the AI-powered classification, it is not just been discovered but also been classified. Then it is pretty much easy to set up your static DLP rules and get results instantaneously.
Normalize's real-time alerts influence my approach to mitigating data vulnerabilities because you get real-time notification on what has been discovered. Not only that, but it also gives you the monetary value on a dashboard. It gives you a monetary value of your data. If it discovers lots of data that had not been discovered over time, then it tells you that in this repository or in this cloud share, you are at the risk of X amount of dollars. You risk losing this amount of dollars. Better put, it quantifies and monetizes it as well.
What needs improvement?
In my opinion, what should be improved about Proofpoint Data Security Posture Management is that it is quite advanced. I think they should ease it up a bit. When it comes to setting of policies, I wish there were a single policy that deals with multiple channels of exfiltration instead of having to do multiple policies to deal with maybe data exfiltration through web upload, data exfiltration through USB, data exfiltration through print, copy and paste, and so forth. It would have been much easier if I had one policy, and then I could turn on the light for all of these different exfiltration channels. A critical example is saying I want to put up a PII policy that will secure social security numbers. That is the condition, social security number. Then in the same policy, I should be able to state that I want this to block exfiltration through USB. However, I want it to allow uploads through web or uploads to a particular website or URL. I want it to allow that kind of granularity where you can flick around things on the same policy. Currently, with Proofpoint Data Security Posture Management, you have to build multiple policies for different channels. Most importantly, the Boolean logic in their policies is incomplete. It just has the AND function. Boolean should carry AND and OR. I am saying if this data contains PII data OR PCI data—either of them—it flags either PCI or PII. But what it has now is AND. For it to fire or trigger, both must be triggered. So if somebody puts only one, maybe PII, and does not put PCI, then it does not trigger. It should have an OR, so that I can have multiple policies and then differentiate them so that if this OR this OR this, either of these triggers. I have flagged that and raised that as a concern to the product team.
I expect additional features from them in the next release, specifically the OR feature for the conditions. However, I am happy with the agent, the lightweight agent, the amount of activities it captures. Beyond just the DLP, it looks at the sites and URLs you are going to, it looks at the file renaming, it looks at the attempt to uninstall, and it looks really deep even though it is user mode. I am happy with that. The Boolean logic is what I think is incomplete at the moment.
How are customer service and support?
I assess their technical support as satisfactory. I am happy with the support. When it comes to response time, there is some room for improvement. Overall, I give them an eight out of ten rating for everything.
What other advice do I have?
It has improved my compliance efforts absolutely because first and foremost, with the classification, it guides users with the auto-classification. It guides users as to data compliance or as to data security or data protection compliance, whether it is an internal governance thing or it is a regulatory, regional regulatory, or industrial regulatory compliance. With that single feature of classification, it helps. I would rate the product overall as a nine out of ten.
Normalyze
Our data can be recovered easily
Authenticate website
User friendly
Some features have to be added for security purpose