IAM-Driven Data Access

Who can reach
your AWS data?

Securitain analyzes IAM permissions and supported AWS resource configurations to identify identities with sensitive access, broad permissions, and risky combinations that increase data-exposure risk — without reading the contents of your data.

Sensitive permissionsResource-policy exposureRisky combinations
  • Read-only & agentless
  • Data content not scanned
  • IAM-driven analysis
Your datacontent not read
S3
GetObject
KMS
Decrypt
DynamoDB
Scan
Secrets
GetSecretValue
SQS
Resource policy
SNS
Resource policy
s3:GetObjectkms:Decryptdynamodb:Scansecretsmanager:GetSecretValues3:PutBucketPolicysqs:GetQueueAttributessns:GetTopicAttributesdynamodb:Querykms:GetKeyPolicylambda:UpdateFunctionCoderds:ModifyDBSnapshotAttributes3:GetBucketPolicy
s3:GetObjectkms:Decryptdynamodb:Scansecretsmanager:GetSecretValues3:PutBucketPolicysqs:GetQueueAttributessns:GetTopicAttributesdynamodb:Querykms:GetKeyPolicylambda:UpdateFunctionCoderds:ModifyDBSnapshotAttributes3:GetBucketPolicy
s3:GetObjectkms:Decryptdynamodb:Scansecretsmanager:GetSecretValues3:PutBucketPolicysqs:GetQueueAttributessns:GetTopicAttributesdynamodb:Querykms:GetKeyPolicylambda:UpdateFunctionCoderds:ModifyDBSnapshotAttributes3:GetBucketPolicy
s3:GetObjectkms:Decryptdynamodb:Scansecretsmanager:GetSecretValues3:PutBucketPolicysqs:GetQueueAttributessns:GetTopicAttributesdynamodb:Querykms:GetKeyPolicylambda:UpdateFunctionCoderds:ModifyDBSnapshotAttributes3:GetBucketPolicy
What it is

Data access & exposure intelligence

Over-privileged identities can create paths to sensitive AWS data. Securitain helps your team identify that access, and the riskier combinations of permissions, before they become a security problem.

Sensitive-permission detection

Identify identities with broad or sensitive data-access permissions — including S3 object access, KMS decrypt, and DynamoDB read, query, and scan access.

Resource-policy exposure

Analyze S3, KMS, SQS, SNS, and Secrets Manager resource policies for public principals, external accounts, and cross-account access.

Risky permission combinations

Identify supported combinations of permissions that increase risk when held by the same identity — such as KMS decrypt paired with S3 or Secrets Manager access, or Lambda code changes paired with secrets access.

Who can access what
S3KMSSecretsDDBRDSAdmin role
CI/CD role
Analyst
Lambda exec
Vendor role
access sensitive / decrypt
What a scan surfaces

High-risk access patterns

Securitain analyzes discovered identities and supported data-access permissions to show where sensitive access is concentrated.

  • Identities with broad s3:GetObject or kms:Decrypt access across many resources
  • Roles with DynamoDB GetItem, Query, or Scan access to sensitive tables
  • Principals with permissions that could export or share RDS and EBS snapshots
  • Cross-account roles holding sensitive data-access permissions

Securitain analyzes AWS configuration, IAM permissions, and supported resource policies. It does not download or inspect the contents of your S3 objects, databases, or secrets.

Resource exposure

Common exposure patterns

Resource policies on S3, KMS, SQS, SNS, and Secrets Manager are checked for public principals and cross-account access, so you can identify configuration that may expose data outside the intended account boundary.

  • S3 bucket policies open to the public or to external AWS accounts
  • KMS key policies allowing decrypt from outside the account
  • SQS and SNS resource policies with overly broad principals
  • Secrets Manager resource policies open to external accounts
Resource-policy exposure
S3 bucket
Public
KMS key
Scoped
SQS queue
Cross-acct
SNS topic
Scoped
Exposure path
account boundary
Your data
KMS decrypt
Outside the account
Why combinations matter

One permission may look harmless. Two together may not be.

Security risk is not always visible by reviewing one permission at a time. An identity may have read access to encrypted objects. A separate permission may let that same identity decrypt them. Securitain looks at supported combinations of permissions — not just individual ones — so your team can see the combined risk.

  • KMS decrypt paired with S3 or Secrets Manager read access
  • Lambda function-code changes paired with secrets access
  • RDS or EBS snapshot-sharing permissions that could expose a snapshot outside the account
  • S3 bucket-policy changes paired with object-read access
  • CloudTrail logging changes paired with IAM permission changes

With Securitain Data Security

  • Identify identities with permissions that may allow sensitive data access, decryption, or higher exposure risk
  • S3, KMS, SQS, SNS & Secrets Manager resource policies checked for public and cross-account exposure
  • Detection of supported permission combinations that increase data-exposure risk
  • Finding-to-control evidence to support HIPAA, SOC 2, PCI DSS, and other supported compliance frameworks
Compliance

Evidence to support your data-protection controls

Supported findings map to relevant control areas in the compliance frameworks available in Securitain — evidence and mapping support, not certification.

HIPAA
Access controls for ePHI
SOC 2
Logical & privileged access
PCI DSS
Restrict access to data
CIS AWS
Foundations Benchmark
ISO 27001
Annex A access control
NIST 800-53
Access control families
On the roadmap

Planned — not current capabilities

Securitain's current Data Security capability analyzes AWS access, permissions, and supported resource configurations. It does not currently inspect or classify the contents of customer data. The following are planned for future releases:

Sensitive-data discovery & content classification (PII/PHI/PCI)
Amazon Macie integration
Complete S3 & database posture management
Encryption-coverage & backup-compliance monitoring
Full data security posture management (DSPM)

See who can reach your data

Connect a read-only role and see which identities can access your data, which resource policies are externally exposed, and which permission combinations increase risk.