Baffle's Amazon S3 Data Proxy enables encryption of entire files or elements in files (text, JSON, XML, CSV, and Parquet) while transferring to Amazon S3 buckets. The client protocols include S3, SFTP, HTTP or API to support all transfers without infrastructure modification or code changes.
Protect against Amazon S3 breaches due to misconfiguration or attack. Regulations and security frameworks, such as GDPR, NIST, CCPA, and PCI-DSS, demand control & "least privilege" access to sensitive data in AWS. Baffle provides application-level encryption (the gold standard for data security) without the cost, time, and effort of other products. In SaaS (multi-tenant) applications, enable every tenant to provide their own key (BYOK,HYOK).
Baffle makes the migration of data into AWS S3 buckets easy, performant and secure.
With no client-side code changes, translate and encrypt between S3, SFTP, HTTP and Baffle API client to Amazon S3.
Deploy as a container (not a SaaS) to preserve privacy, scale, and support HA/DR within your existing infrastructure architecture.
Encrypt entire files or elements of files (text, JSON, XML, CSV, and Parquet) using traditional AES or format preserving encryption.
Enable logical data isolation between tenants and geographies by allowing each tenant to encrypt with their own key (BYOK, HYOK).
Use Baffle’s S3 data proxy to migrate data and secure the entire pipeline for GenAI training, Data warehouses, and the multitude of other services AWS offers with S3 as their data lakes.
Highlights
With no client-side code changes, translate and encrypt between S3, SFTP, HTTP and Baffle API client to Amazon S3.
Deploy as a container (not a SaaS) to preserve privacy, scale, and support HA/DR within your existing infrastructure architecture.
Encrypt entire files or elements of files (text, JSON, XML, CSV, and Parquet) using traditional AES or format preserving encryption.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 30 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
You pay by the hour based on the AWS instance size you run this trial software on. The six options—t3.large, m4.xlarge, t2.large, m5.large, t3.xlarge, and m5.xlarge—are different EC2 instance types, not feature tiers. Each carries its own hourly rate, so pricing scales with the compute capacity you choose. Larger or higher-performance instances cost more per hour. You select the instance type that fits your workload and are billed only for the hours you use. All options deliver the same data security capabilities.
Top-of-mind questions for buyers
What does one billing unit represent for each instance option?
Each unit is one hour that the trial software runs on a single EC2 instance of the chosen type. The instance type (t3.large, m4.xlarge, t2.large, m5.large, t3.xlarge, or m5.xlarge) sets the compute size. You are metered per running hour, and each instance you launch bills separately.
Am I charged when the instance is stopped or paused?
Software charges accrue only while the instance runs. A stopped instance stops the hourly software meter. Underlying AWS storage or other resource fees may still apply while the instance sits stopped, but the trial software itself bills running hours only.
Do larger instance types unlock extra data security features?
No. All six instance types deliver the same data security capabilities, including client-side encryption, field-level anonymization, role-based access control, and no-code deployment. The instance type changes only the compute capacity and hourly rate, not the feature set you receive.
baffle.io
Helpful?
Vendor refund policy
Free 30-day trial. Refunds are handled on a case-by-case basis via support.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
This CloudFormation (CF) template automates the setup for Baffle Trial for Data Security for Amazon S3 on AWS credentials, and IP whitelisting. It then employs conditions to adapt resource creation based on the selected workflow.
The template provisions foundational resources like VPCs, subnets, internet gateways, and route tables for networking. It also sets up an S3 bucket and IAM roles for managing keys and permissions.
Security measures include the setup of EC2 security groups and IAM roles, ensuring controlled access to resources and encrypted data transmission.
Outputs provide convenient access URLs for Baffle Manager and baffle s3 endpoint
By encapsulating all these configurations into a single template, this CF script simplifies the deployment and management of Baffle Data Protection, fostering a secure and efficient data environment on AWS.
DeleteBucketLambdaExecutionRole:
The Lambda execution role is needed to empty the content of data and key S3 buckets. The bucket needs to be emptied before it can be deleted while tearing the stacks. The following are policies needed
Lambda Assume Role
List and Delete object roles on 2 specific S3 buckets
CloudWatch role to log
BaffleShieldRole:
This is required for the Baffle Manager and Baffle S3 Proxy to generate the key, store the key in S3, and store the operated file in the S3. The following are policies needed
EC2 assume role
S3 put, get, list object and get bucket policy on 2 S3 bucket
CloudFormation Template (CFT)
AWS CloudFormation templates are JSON or YAML-formatted text files that simplify provisioning and management on AWS. The templates describe the service or application architecture you want to deploy, and AWS CloudFormation uses those templates to provision and configure the required services (such as Amazon EC2 instances or Amazon RDS DB instances). The deployed application and associated resources are called a "stack."
Version release notes
Realese 2.9.3.10
Additional details
Usage instructions
Template components
CloudFormation template
Usage instructions
Run the CF template
An email ID is requested to create an account with the Baffle service. The email ID is used to ensure uniqueness of the account name. The email ID is not collected nor will Baffle send emails to that email ID
If asked for a startup password please input "baffle123"
"
PLEASE NOTE: Pricing is for illustration purposes only and varies depending on customer environment, requirements and other factors. Please contact us at for more details." docs.baffle.io
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Baffle's data-centric protection enables organizations to comply with the latest data protection regulations and cybersecurity frameworks. Baffle provides the benefits of application-level encryption without code changes, providing you the most flexible solution for protecting sensitive data in AWS.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.