Know which stores hold sensitive data
Atlas labels PII, PCI, PHI, secrets and credentials across S3, RDS, DynamoDB and Secrets Manager, then puts each label on the security graph. A public path to customer records ranks above the same path to an empty bucket.
- 1Scan the data inventory
24 stores carry a sensitive label, 18 are classified and 4 are not scanned or denied. Each row shows classes, source, record count and state.
- 2Open customer-exports
Amazon Macie results label it PII, with email and phone fields across 2.4M records. Exposure reads public path, 3 hops.
- 3Open the attack path
The path from the internet through checkout-api turns red and the store's priority rises from High to Critical.
Nobody can say where the card numbers live
PCI DSS, HIPAA and DPDP all start with the same question. Most teams answer it with a spreadsheet that is already out of date.
Bucket names don't describe contents
What usually happens: An export job wrote customer emails to a bucket called tmp-exports two years ago. Nothing about the name suggests it matters.
How CloudLens resolves it: Macie results and column-name inference label the bucket PII, and the label follows it onto the graph.
ResolvedSeverity ignores what's inside
What usually happens: Every public bucket is rated High, whether it holds product images or order history.
How CloudLens resolves it: Priority comes from what the store holds and what can reach it.
ResolvedUnscanned stores look clean
What usually happens: A table the scanner couldn't read reports zero sensitive columns and drops off the audit list.
How CloudLens resolves it: Not scanned and Denied are separate states. PCI DSS and HIPAA controls that depend on them read Not assessed.
ResolvedAnswering "where is our customer data?"
Aisha leads data protection at Lumora Retail. Every privacy review starts with the same question, and this is how she answered it this quarter.
Lumora Retail is a fictional company. The people, names and numbers are sample data.
Opens the data inventory
Follows the path to the bucket
Checks what wasn't scanned
claims-lake comes back Partial
Hands evidence to compliance
Find PII, PCI and PHI across your cloud
From "what's in this bucket?" to what can reach it
Classification tells you what a store holds. The graph tells you who can get to it. Atlas keeps both on the same resource.
Four sources feed one inventory
- Amazon Macie
- Glue catalog column names
- In-account scanner
- Owner-declared
- 1Macie and Glue label the first stores
customer-exports gets PII from Amazon Macie results. orders-db gets PII inferred from its Glue catalog column names.
- 2Scanner and owners label the rest
The in-account scanner marks claims-lake as PHI, and the owner declares ci-config as holding secrets. Each label keeps its source.
- 3support-tickets stays Not scanned
No source has read it, so it gets no label and stays on the list. It is never assumed clean.
- Classified: counts as evidence
- Partial: some prefixes read
- Not scanned: never counted clean
- Denied: permission missing
- 1Count stores by state
18 classified, 2 partial, 3 not scanned and 1 denied. The last two groups are marked as never clean.
- 2Run classification
While it runs, the PCI DSS and HIPAA controls that depend on it read Not assessed, with a progress bar.
- 3Controls get real results
When classification finishes, PCI DSS scores 72% with 2 controls still not assessed, and HIPAA scores 81%.
- Joined to attack paths
- Toxic combinations with data
- Owners and triage state
- 1Start with two identical public paths
Internet to marketing-site to static-assets, and internet to checkout-api to customer-exports. Both begin as Medium.
- 2The data labels arrive
static-assets holds no sensitive data. customer-exports carries PII across 2.4M records.
- 3The PII path moves to first
The checkout path becomes #1 and Critical. The marketing path drops to #2 and stays Medium.
Which laws care about this data, and what they expect
The class of data in a store decides which rules apply. Here is what the main ones ask for in practice, and what Atlas does about it today.
PCI DSS
Cardholder data, wherever it is stored, processed or sent- What it expects
- Protect stored account data, restrict access to people and systems with a business need, and keep it off public paths.
- In CloudLens
- PCI DSS controls are scored from live checks, with the failing resource named as evidence.
HIPAA Security Rule
Electronic protected health information (ePHI)- What it expects
- Administrative, physical and technical safeguards, and breach notification when PHI is exposed.
- In CloudLens
- HIPAA controls are scored. Until PHI stores are classified, the controls that depend on them read Not assessed.
DPDP Act, 2023
Digital personal data of individuals in India- What it expects
- Reasonable security safeguards, and reporting a personal data breach to the Data Protection Board of India and to the people affected.
- In CloudLens
- PII is classified and ranked by exposure today. Mapping findings to DPDP obligations is in early access.
GDPR
Personal data of people in the EU- What it expects
- Appropriate security for personal data, and notifying the supervisory authority of a breach, generally within 72 hours.
- In CloudLens
- PII classification and exposure ranking today. GDPR mapping is in early access.
A plain-language summary to help teams prioritise. It is not legal advice.
Not scanned is not clean.
When a permission is missing or a store hasn't been classified, Atlas says so. That store stays out of every clean count, every compliance pass and every empty list until there is evidence.
What you get for governing cloud data
Sensitive-data inventory
Every store with its classes, source, record count, state and owner across S3, RDS, DynamoDB and Secrets Manager.
Exposure-aware ranking
Public paths, external sharing and reachable workloads raise the priority of the data they touch.
Evidence for PCI DSS and HIPAA
Classification feeds the controls that need it. Those controls read Not assessed until it has run.
Owners, triage and Jira
Acknowledge, snooze or send to Jira. Triage is cleared when the evidence changes.
Data governance questions
PII, PCI, PHI, secrets and credentials. Each label records the source that produced it.
No. Macie is one of four sources. Glue catalog column names, the in-account scanner and owner-declared labels work without it.
It is shown as Not scanned or Denied, never as clean. If a permission is missing, Atlas names it so you can grant it.
PCI DSS and HIPAA controls that depend on data classification read Not assessed until classification has run, so missing evidence can't raise a score.
Amazon Macie and the in-account scanner run inside your own AWS account. CloudLens connects with a read-only role.
Find the sensitive data in your cloud
Connect a read-only AWS role or Azure service principal. We'll walk you through your bill, your security graph and the first things worth fixing.
