New Savings Proposals: approve, test and roll back cost changesLearn more Sign in|Talk to a cloud engineer

Know which stores hold sensitive data

Atlas labels PII, PCI, PHI, secrets and credentials across S3, RDS, DynamoDB and Secrets Manager, then puts each label on the security graph. A public path to customer records ranks above the same path to an empty bucket.

What you're watching
  1. 1
    Scan the data inventory

    24 stores carry a sensitive label, 18 are classified and 4 are not scanned or denied. Each row shows classes, source, record count and state.

  2. 2
    Open customer-exports

    Amazon Macie results label it PII, with email and phone fields across 2.4M records. Exposure reads public path, 3 hops.

  3. 3
    Open the attack path

    The path from the internet through checkout-api turns red and the store's priority rises from High to Critical.

Who does thisData protection lead, with the cloud security engineer who owns the pathWhat you getA list of where PII sits, ordered by which stores the internet can actually reach.
0
data classes: PII, PCI, PHI, secrets and credentials
0
classification sources, from Macie to owner-declared
0
sensitive data stores at Lumora Retail (sample data)
0
store not scanned yet, listed on its own

Nobody can say where the card numbers live

PCI DSS, HIPAA and DPDP all start with the same question. Most teams answer it with a spreadsheet that is already out of date.

Data

Bucket names don't describe contents

What usually happens: An export job wrote customer emails to a bucket called tmp-exports two years ago. Nothing about the name suggests it matters.

How CloudLens resolves it: Macie results and column-name inference label the bucket PII, and the label follows it onto the graph.

Resolved
Priority

Severity ignores what's inside

What usually happens: Every public bucket is rated High, whether it holds product images or order history.

How CloudLens resolves it: Priority comes from what the store holds and what can reach it.

Resolved
Coverage

Unscanned stores look clean

What usually happens: A table the scanner couldn't read reports zero sensitive columns and drops off the audit list.

How CloudLens resolves it: Not scanned and Denied are separate states. PCI DSS and HIPAA controls that depend on them read Not assessed.

Resolved

Answering "where is our customer data?"

Aisha leads data protection at Lumora Retail. Every privacy review starts with the same question, and this is how she answered it this quarter.

ARAisha RahmanData protection lead, Lumora Retail

Lumora Retail is a fictional company. The people, names and numbers are sample data.

    1
    Mon 10:00PII

    Opens the data inventory

    24 stores carry a sensitive label. customer-exports is at the top: PII from Amazon Macie, 2.4M records and a public path.
    2
    Mon 10:15

    Follows the path to the bucket

    The label is joined to the attack path through checkout-api and checkout-task-role. She links the store to SEC-77, which security already opened.
    3
    Tue 13:30

    Checks what wasn't scanned

    support-tickets in DynamoDB shows Not scanned, so it isn't counted as clean. She asks the Data Platform team to declare what it holds.
    4
    Wed 09:00Partial

    claims-lake comes back Partial

    The scanner read some prefixes and was denied others. The store is labelled PHI with the state Partial until the bucket policy allows a full read.
    5
    Fri 16:00

    Hands evidence to compliance

    PCI DSS and HIPAA controls for the stores that finished classification now show results instead of Not assessed.
Not sure where personal data lives?

Find PII, PCI and PHI across your cloud

From "what's in this bucket?" to what can reach it

Classification tells you what a store holds. The graph tells you who can get to it. Atlas keeps both on the same resource.

Four sources feed one inventory

Atlas reads Amazon Macie results, infers sensitive columns from Glue catalog names, runs an in-account scanner where you allow it, and lets owners declare what a store holds. Every label keeps its source, so you can see why a store is marked PII.
  • Amazon Macie
  • Glue catalog column names
  • In-account scanner
  • Owner-declared
What you're watching
  1. 1
    Macie and Glue label the first stores

    customer-exports gets PII from Amazon Macie results. orders-db gets PII inferred from its Glue catalog column names.

  2. 2
    Scanner and owners label the rest

    The in-account scanner marks claims-lake as PHI, and the owner declares ci-config as holding secrets. Each label keeps its source.

  3. 3
    support-tickets stays Not scanned

    No source has read it, so it gets no label and stays on the list. It is never assumed clean.

Who does thisData protection lead, with the data platform team that owns the storesWhat you getEvery sensitive label traces to the source that produced it, and every gap is listed by name.

Not scanned stays on the list

How compliance is scored
A store Atlas couldn't read is not a store with nothing in it. Classified, Partial, Not scanned and Denied are separate states, and the last two are never counted as clean. PCI DSS and HIPAA controls that depend on classification read Not assessed until it has run.
  • Classified: counts as evidence
  • Partial: some prefixes read
  • Not scanned: never counted clean
  • Denied: permission missing
What you're watching
  1. 1
    Count stores by state

    18 classified, 2 partial, 3 not scanned and 1 denied. The last two groups are marked as never clean.

  2. 2
    Run classification

    While it runs, the PCI DSS and HIPAA controls that depend on it read Not assessed, with a progress bar.

  3. 3
    Controls get real results

    When classification finishes, PCI DSS scores 72% with 2 controls still not assessed, and HIPAA scores 81%.

Who does thisGRC lead and data protection lead, ahead of an assessmentWhat you getPCI DSS and HIPAA scores that move only when classification evidence exists.

Priority follows the data at the end

Explore attack paths
Data labels live on the same graph that draws attack paths. Two identical public paths are not equal: the one ending at 2.4M customer records is Critical, and the one ending at static assets is not.
  • Joined to attack paths
  • Toxic combinations with data
  • Owners and triage state
What you're watching
  1. 1
    Start with two identical public paths

    Internet to marketing-site to static-assets, and internet to checkout-api to customer-exports. Both begin as Medium.

  2. 2
    The data labels arrive

    static-assets holds no sensitive data. customer-exports carries PII across 2.4M records.

  3. 3
    The PII path moves to first

    The checkout path becomes #1 and Critical. The marketing path drops to #2 and stays Medium.

Who does thisCloud security engineer setting the week's prioritiesWhat you getExposure work ordered by what an attacker would get, so the static-assets bucket waits its turn.

Which laws care about this data, and what they expect

The class of data in a store decides which rules apply. Here is what the main ones ask for in practice, and what Atlas does about it today.

PCIScored in Atlas

PCI DSS

Cardholder data, wherever it is stored, processed or sent
What it expects
Protect stored account data, restrict access to people and systems with a business need, and keep it off public paths.
In CloudLens
PCI DSS controls are scored from live checks, with the failing resource named as evidence.
PHIScored in Atlas

HIPAA Security Rule

Electronic protected health information (ePHI)
What it expects
Administrative, physical and technical safeguards, and breach notification when PHI is exposed.
In CloudLens
HIPAA controls are scored. Until PHI stores are classified, the controls that depend on them read Not assessed.
PIIEarly access

DPDP Act, 2023

Digital personal data of individuals in India
What it expects
Reasonable security safeguards, and reporting a personal data breach to the Data Protection Board of India and to the people affected.
In CloudLens
PII is classified and ranked by exposure today. Mapping findings to DPDP obligations is in early access.
PIIEarly access

GDPR

Personal data of people in the EU
What it expects
Appropriate security for personal data, and notifying the supervisory authority of a breach, generally within 72 hours.
In CloudLens
PII classification and exposure ranking today. GDPR mapping is in early access.

Not scanned is not clean.

When a permission is missing or a store hasn't been classified, Atlas says so. That store stays out of every clean count, every compliance pass and every empty list until there is evidence.

What you get for governing cloud data

Sensitive-data inventory

Every store with its classes, source, record count, state and owner across S3, RDS, DynamoDB and Secrets Manager.

Exposure-aware ranking

Public paths, external sharing and reachable workloads raise the priority of the data they touch.

Evidence for PCI DSS and HIPAA

Classification feeds the controls that need it. Those controls read Not assessed until it has run.

Owners, triage and Jira

Acknowledge, snooze or send to Jira. Triage is cleared when the evidence changes.

Data governance questions

PII, PCI, PHI, secrets and credentials. Each label records the source that produced it.

No. Macie is one of four sources. Glue catalog column names, the in-account scanner and owner-declared labels work without it.

It is shown as Not scanned or Denied, never as clean. If a permission is missing, Atlas names it so you can grant it.

PCI DSS and HIPAA controls that depend on data classification read Not assessed until classification has run, so missing evidence can't raise a score.

Amazon Macie and the in-account scanner run inside your own AWS account. CloudLens connects with a read-only role.

Find the sensitive data in your cloud

Connect a read-only AWS role or Azure service principal. We'll walk you through your bill, your security graph and the first things worth fixing.