Overview
Interested in discounted pricing? Contact sales@cloudstoragesec.com for a Private Offer.
Protect data lakes, ingestion pipelines, and application workflows built on AWS storage by scanning for viruses, ransomware, trojans, and other malicious payloads before they propagate downstream.
WHY THIS SOLUTION IS DIFFERENT
- Support for Multiple Data Sources
- Purpose-built for AWS storage
- In-tenant, security-first architecture
- Flexible scanning models
- Static, Dynamic & Forensic Analysis
- Configuration visibility across buckets
- Rapid deployment with minimal operational overhead
SUPPORTED AWS STORAGE Built for AWS storage services including:
- Amazon S3
- Amazon EBS
- Amazon EFS
- Amazon FSx
Engines Identify malware at petabyte scale across all buckets by leveraging the power of Sophos, CSS Premium, or CSS Secure. Engines may be used simultaneously to optimize accuracy and performance.
Scanning Models Integrate the method that fits your needs to minimize process interruptions and eliminate service disruptions. Choose from:
- Event-Based Scanning Scan new or modified objects in real time when uploaded. (easy to integrate into workflows because low or no code changes are needed)
- Retroactive Scanning Scan existing objects on demand or on schedule for baselining and compliance audits.
- API-Based Scanning Scan objects inside or outside of AWS in real time via a REST API before they are written to storage. Ideal for migrations, new application builds, or workflows where scan results determine whether an object is accepted.
Analysis Perform static analysis without execution or detonate files in a sandbox using SophosLabs Intelix™. Files are segmented by bucket and account to support traceability and forensic investigation.
Configurations Identify buckets with secure and insecure permission policies through a unified dashboard to improve visibility into storage misconfigurations.
Setup Deploy via AWS CloudFormation or Terraform in less than 10 minutes. Initial bucket protection and scanning configuration takes less than 5 minutes.
Follow the Getting Started Guide: https://help.cloudstoragesec.com/getting-started/summary/
Security First The solution installs and operates entirely within your AWS account. Data never leaves your environment or region. Optional deployment models include centralized security services accounts, linked account management, and private VPC endpoints.
Case Studies https://cloudstoragesec.com/case-studies
Core Capabilities
- Automated serverless architecture
- Real-time & on-demand scanning
- Centralized management console with dashboards and detailed reporting
- Automatic discovery & scaling across multiple accounts & regions
- No file size or type limitations with CSS Premium
- Problem file remediation (Quarantine, Tag, Delete)
- Notifications and integrations with third-party ticketing systems, Slack, Microsoft Teams, Amazon Chime, SIEM platforms, Amazon SNS, AWS Security Hub, AWS CloudTrail, AWS Control Tower, AWS Transfer Family, and more
Flexible Pricing Choose between pay-as-you-go pricing based on scan volume or tiered plans with unlimited scanning. Private offers and prepaid discounts are available.
NOT TO MISS ARTICLES ON AWS https://aws.amazon.com/blogs/apn/integrating-amazon-s3-malware-scanning-into-your-application-workflow-with-cloud-storage-security/
Highlights
- In-tenant, cloud-native malware scanning for Amazon S3, Amazon EBS, Amazon EFS, and Amazon FSx with no external file transfer.
- Multi-engine virus detection using Sophos, CSS Premium, and CSS Secure with event-based, retroactive, and API scanning models.
- Protect data lakes and application workflows with real-time and on-demand scanning that scales across multi-account AWS environments.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/GB |
|---|---|---|
FreeTrial Usage | FreeTrial Usage | $0.00 |
Monthly Subscription - includes 100GB of premium engine scanning | Monthly Subscription - includes 100GB of premium engine scanning | $99.00 |
Scan 101-500GB per month | Scan 101-500GB per month | $0.80 |
Scan 501-1500GB per month | Scan 501-1500GB per month | $0.80 |
Scan 1501-3000GB per month | Scan 1501-3000GB per month | $0.80 |
Scan >=3001GB per month | Scan >=3001GB per month | $0.80 |
Scan pre-existing objects | Scan pre-existing objects | $0.80 |
Premium Engine per GB Add-on - pre-existing objects - Sophos | Premium Engine per GB Add-on - pre-existing objects - Sophos | $0.10 |
Premium Engine per GB Add-on - Sophos | Premium Engine per GB Add-on - Sophos | $0.10 |
Cloud Detonation - Static Analysis (Per File) | Cloud Detonation - Static Analysis (Per File) | $0.05 |
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Console Deployment and Permission Setup
- Amazon ECS
Container image
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.
Version release notes
Additional details
Usage instructions
Subscribing to this product will take you through the sign-up and deployment process. Deployment consists of launching a CloudFormation Template provided to you on the last configuration page of signup (also located in the Help Docs). Once Stack creation is completed, look to the Stack Outputs for the Console access URL and open that in your browser. Any additional deployment and management tasks are performed from within the Console.
For detailed steps on how to subscribe, deploy and use the product, please review: http://help.cloudstoragesec.com/getting-started/how-to-subscribe/
Resources
Vendor resources
Support
Vendor support
If you need help during your 30-day free trial, we are happy to provide email support via support@cloudstoragesec.com . We respond to support requests via email during your 30-day free trial within 24 hours Monday through Friday. We can also provide more in-depth support via phone and web meetings for Proof of Concept (POC) engagements. If you would like more information about initiating a POC, please contact one of our experts at https://cloudstoragesec.com/contact . Cloud Storage Security also offers Premium Support and Professional Service plans for purchase in AWS Marketplace
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

Standard contract
Customer reviews
Automation has improved threat detection and reduced manual checks but pricing still needs work
What is our primary use case?
My main use case for Antivirus for Amazon S3 is to secure my S3 buckets in Amazon, which can easily be hacked. I want to secure it from malicious injections.
How has it helped my organization?
Antivirus for Amazon S3 has positively impacted my organization by reducing the number of people who need to monitor threats or malicious code injections. This solution replaces that manual monitoring and only sends alerts, so we do not need to wait or check every time if it is safe or if it is getting hacked.
It has saved one or two people and saved almost 10% to 30% of the time. It also improved efficiency by almost 70%.
What is most valuable?
The best features Antivirus for Amazon S3 offers are zero maintenance, zero server maintenance, and the alerts. If you are a small company or small organization, you can also get a good file size. The setup time is very low compared to other solutions, which can take 15 minutes to half an hour, but it takes under one minute.
It can easily be integrated with AWS . The alerts help my team because if something unusual occurs in our bucket or something happens that could not happen in the bucket, it will observe and understand the patterns sometimes and send us email alerts so that we can take a quick look at it and fix it immediately. The quick setup improves our workflow significantly.
The integration of Antivirus for Amazon S3 is very good and easily integrated with Amazon AWS because it is an Amazon AWS product.
What needs improvement?
Antivirus for Amazon S3 can be improved by implementing multiple buckets into one guard, enabling TBAC which can be automatically configured by Amazon GuardDuty, and adding multi-engine scanning.
Regarding needed improvements, I think pricing is a bit higher for people who are using it very low and for small organizations. Large organizations who will use it more will benefit from the price, but small organizations will face significant monetary loss. I think they should reduce the pricing and put event-based pricing related to the organization size or the usage. I understand it is pay-per-use, but sometimes it does not make sense.
For how long have I used the solution?
I have been using Antivirus for Amazon S3 for the last six to eight months.
What other advice do I have?
My advice to others looking into using Antivirus for Amazon S3 is that this is good for medium and large-sized organizations, considering the price and what it offers. It can reduce some people, but for small organizations, I think people should be there sometimes to monitor it to save money. The people who do multitasking should be the ones who monitor as well to reduce more costs rather than relying only on GuardDuty. I give this product a rating of 7.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Automated quarantine has reduced security risks and has removed manual incident handling
What is our primary use case?
My main use case for Antivirus for Amazon S3 is quarantine.
A specific example of how I use Antivirus for Amazon S3 for quarantine is that we use it from the black box that can recognize viruses immediately.
How has it helped my organization?
Antivirus for Amazon S3 has positively impacted my organization as it has reduced time to market and secured our operations.
There are no special specific improvements in my secure operations resulting from the reduction of time to market.
What is most valuable?
The best features Antivirus for Amazon S3 offers are advanced automatization and isolated quarantine bucket.
The advanced automatization and the isolated quarantine bucket have helped my workflow and security because I do not need to write my own scripts on Python and Lambda to operate with incidents, which saves us a lot of costs.
I think it is excluding the human factor of failure.
What needs improvement?
I think there is a problem with pricing while scaling, and it is a blocker for big corporations as there is a subscription for the instance plus volume of scanning.
It would be great to have more understandable billing dashboards.
For how long have I used the solution?
I have been using Antivirus for Amazon S3 for more than five years.
How are customer service and support?
I rate customer service as 3 out of 10.
What other advice do I have?
My advice to others looking into using Antivirus for Amazon S3 is to connect it immediately without hesitation. I rate this review as 9 out of 10.
Automatic file scanning has protected shared content and now requires richer, AI-driven checks
What is our primary use case?
As an API Integration Engineer, my main use case for Antivirus for Amazon S3 involves scanning partners' uploaded content that arrives via API. I deal with files that third parties push into S3 , such as media files like images or video files from channel managers or PMS partners that have API access to the Airbnb API source code.
Antivirus for Amazon S3 fits into my workflow by triggering scanning automatically at some point, while at other times, I perform manual scans depending on the load of the files that partners push towards our API.
In my main use case for Antivirus for Amazon S3, guests, hosts, and customer support agents eventually see these downloaded files, which may include malicious PDFs or host onboarding documentation that could feature a malicious customer support agent mechanism.
What is most valuable?
The best features Antivirus for Amazon S3 offers include native S3 event integration, which allows scanning to fire automatically, in-place scanning so files are not copied to another bucket, results attached as S3 object tags, IAM-based policy enforcement on scan results, large file support with streaming scans, archive and nested file scanning, multiple detection engines running in parallel, custom YARA rule support, quarantine or automated remediation actions, scan on demand, and retrospective scanning.
In my day-to-day work, I rely the most on in-place scanning, as it is the best feature of modern Antivirus for Amazon S3 that does not pull objects out of the bucket for scanning. For example, older solutions required copying files to an EC2 instance for scanning, which was slow, expensive, and doubled our data egress attack surface.
Antivirus for Amazon S3 has positively impacted my organization by making the entire organization much safer, allowing partners to safely upload their personal files, images, and videos to the Airbnb platform, which ensures that we as a company can be a reliable partner to our partners with safe integration.
What needs improvement?
I believe Antivirus for Amazon S3 can be improved by implementing some pre-writing features, such as synchronously scanning at the API layer.
I would like to see improvements in content-aware scanning not just for malware, but also for other content, such as PDF files or API request parameters and strings, along with prompt injection scanning with custom AI agents creating the skill direction.
For how long have I used the solution?
I have been using Antivirus for Amazon S3 for two years.
What do I think about the stability of the solution?
Antivirus for Amazon S3 is sufficiently stable.
What do I think about the scalability of the solution?
I would rate its scalability as nine out of ten, as S3 is one of the most scalable services AWS has built, providing a foundation upon which most other scalable AWS services rely. However, it does not achieve a perfect score of ten due to real scaling cliffs when operating at high volumes that can catch you off guard.
How are customer service and support?
Customer support for Antivirus for Amazon S3 has always been straightforward, and since they are globally distributed, I would rate them nine out of ten.
What was our ROI?
I would say we have seen money saved and time saved on a long-term basis with Antivirus for Amazon S3, although we did not reduce employee numbers.
After a couple of meetings with higher management, I believe there were negotiations, and the overall business terms were met, making my experience with pricing and compliance satisfactory.
What other advice do I have?
I would like to add that it would be beneficial to use AI as a parallel agent in the back end to fast-forward the malicious detection process for the large number of files being sent in various directions.
I advise others looking into using Antivirus for Amazon S3 to check the pricing and determine if this service is something that their company or organization truly needs. They should consider the downsides and upsides, check incident level metrics, and evaluate their overall long-term budgeting, which will help in making a final decision.
I would like to add that S3 is the gold standard for storage scalability and antivirus protection. Overall, it is a decent product. I would rate this review a seven out of ten.
Automated threat response has protected our cloud data and has improved security efficiency
What is our primary use case?
Antivirus for Amazon S3 has protected us many times. In a real scenario that I remember, there was access to an Amazon S3 bucket from unknown locations, including Russia and Ukraine. We immediately received an alert about suspicious account activity from unknown user locations, and an API call was activated. Once we received the alert, we quickly investigated and found that malicious Java code had been injected into the S3 bucket, which was causing infections when users downloaded it on their machines. The host was compromised, the AWS account was compromised, and we got a real-time malware alert.
What is most valuable?
The best feature is definitely the deployment. The deployment takes less than 10 minutes. The solution runs within the AWS account, ensuring the data remains secure and compliant. Automated threat mitigation is the second main feature. It automatically tags, deletes, and quarantines the infected file upon detection and provides robust defense against malware, protecting in real time.
The system can automatically delete and quarantine the infected files once they are found to be malicious. This antivirus solution has a robust defense against malware, ensuring it never reaches the end user's S3 bucket and S3 locations.
It has definitely impacted our business positively. It makes our complete S3 bucket and AWS account secure by ensuring that no malicious file can be uploaded or downloaded by any AWS account holder. All the data that is stored in the cloud is fully protected, fully compliant, and secure.
There is definitely a huge impact on the organization that we observed. There was an 80% efficiency increase with the deployment of this antivirus solution, which causes fewer incidents to be created whenever any alert is generated in real time. We saved a lot of time in terms of mitigating or identifying threats and quickly taking action on securing the AWS account from malware infection spread. It saves a lot of time and has improved the overall efficiency and effectiveness of the account and storage devices.
What needs improvement?
There are no major issues, but if the company could work on deployment features as well as cost-effectiveness and some specific features that require licensing needs, it would be really helpful.
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
Which solution did I use previously and why did I switch?
How was the initial setup?
What about the implementation team?
What was our ROI?
What's my experience with pricing, setup cost, and licensing?
What other advice do I have?
I think others should definitely go for Antivirus for Amazon S3. The reason is that it is not just about protecting from malicious files, but it takes action immediately by quarantining the file and deleting the file whenever needed. I can perform automated actions, automated alert investigation, and quickly block threats from the organization. It definitely works in a real-time scenario. Since it is integrated with the cloud, it is really easy to get support from the cloud storage. Additionally, the cloud signature gets updated every day, which is really helpful. I would rate this solution a nine out of ten.
Automated file scanning has improved security and now lets us focus more on core development work
What is our primary use case?
Antivirus for Amazon S3 is typically used for scanning files uploaded to S3 buckets for malware before they are consumed by downstream services. This is especially critical when handling user-generated content or third-party uploads.
What is most valuable?
One of the best features of Antivirus for Amazon S3 is automatic malware scanning on upload without needing to manage infrastructure. AWS native solutions such as GuardDuty Malware Protection provide fully managed agent-less scanning.
A key aspect of Antivirus for Amazon S3 that is worth mentioning is the ability to receive notifications and alerts when potential threats are detected, which allows my team to take swift action and ensure the security of our application.
Antivirus for Amazon S3 has improved our overall security posture, especially for compliance-heavy applications. My team became more confident handling external file uploads. We reduced custom infrastructure costs by around 30% since we did not need EC2-based scanning pipelines. Additionally, development times dropped by about 20% due to the managed service.
I have seen a significant improvement in my team's productivity since we implemented Antivirus for Amazon S3. The 20% reduction in development time has allowed us to focus on higher-priority tasks. With the managed service handling the scanning, our developers can now allocate more time to feature development and less time to infrastructure management.
What needs improvement?
One limitation I have identified is that advanced customizations can be tricky with fully managed solutions for Antivirus for Amazon S3. Sometimes we need more control over scanning logic or workflows.
For needed improvements, I would say documentation is good, but troubleshooting scan failures or false positives can still take time with Antivirus for Amazon S3. Better debugging tools would help.
One area I would like to see improved for Antivirus for Amazon S3 is the automation of certain security protocols, such as automatic updates and patch management to further enhance our security posture. I believe this would help us streamline our operations and reduce the risk of human error.
For how long have I used the solution?
I have been using Antivirus for Amazon S3 for about a year now, primarily in projects where users upload files such as documents or images. It became important when we started dealing with untrusted file uploads.
What do I think about the stability of the solution?
Antivirus for Amazon S3 is very stable, especially AWS-managed solutions. We have not experienced any major downtime or failures in our scanning workflows.
What do I think about the scalability of the solution?
Scalability for Antivirus for Amazon S3 is excellent. It can handle high volumes of uploads without performance degradation since it builds on S3 's event-driven architecture.
How are customer service and support?
Customer support for Antivirus for Amazon S3, specifically AWS native solutions, is solid if you have an enterprise plan. Community and documentation also cover most common issues.
Which solution did I use previously and why did I switch?
Earlier, we used a custom EC2-based antivirus pipeline, but it required maintenance and scaling efforts, which is why we switched to a managed solution for simplicity.
How was the initial setup?
The setup for Antivirus for Amazon S3 is relatively simple. We only need to enable scanning on buckets or deploy via CloudFormation . Pricing is usually pay-as-you-go based on the data scanned.
What was our ROI?
The return on investment for Antivirus for Amazon S3 is strong because it reduces security risk and eliminates the need for custom infrastructure. Overall efficiency improved by roughly 25%.
Which other solutions did I evaluate?
I evaluated custom Lambda-based scanning, third-party tools such as BucketAV and solutions using VirusTotal APIs before choosing Antivirus for Amazon S3.
What other advice do I have?
My advice for others looking into using Antivirus for Amazon S3 is that if your application accepts file uploads, you should definitely implement antivirus scanning for S3. I recommend starting with a managed solution to avoid unnecessary complexity.
Antivirus for Amazon S3 is essential for any system handling external file uploads. It is one of those things you would not think about until something goes wrong, so it is better to have it in place early. I rate this product an 8 out of 10.