DataSunrise Achieves AWS Data & Analytics Competency. Learn more →

Part ofPosture and Discovery

File and Object Storage Discovery

Find Sensitive Data Across Cloud and File Storage

Scan Amazon S3, Azure storage, Google Cloud Storage, local and network files, documents, images, and archives to see exactly where sensitive information lives.

  • Cloud Object Storage
  • Local and Network Files
  • Documents, Images, and Archives

Know what is stored outside the database

Sensitive data does not live only in databases. It also accumulates in buckets, shared folders, documents, images, and archives. DataSunrise finds it and shows the exact file or object behind every result.

Create a repeatable discovery task, choose what to inspect, apply built-in or custom Information Types, and review the findings in one place.

Use the results to investigate unexpected storage, prepare compliance evidence, and plan the next security action.

From Storage Connection to Actionable Findings

Run the same discovery process across object stores, shared files, documents, images, and archives.

  1. Connect storage

    Add credentials and choose the buckets, containers, shares, or paths to inspect.

  2. Define the scan

    Select content, classifiers, OCR, archive handling, and the amount of each file to analyze.

  3. Run discovery

    Start the task immediately or on a schedule. Incremental scans can focus on new and changed content where available.

  4. Review results

    See the path, Information Type, statistics, and processing status, then export reports or reuse findings in Object Groups.

Each run keeps its scope, settings, and findings together, so teams can repeat the scan and compare results over time.

See the workflow in DataSunrise

Product screens show how policy, evidence, and protection appear in practice.

Explore File and Object Storage Discovery

1 / 4

Connect the Storage You Use

Bring cloud object stores, shared file systems, and local paths into the same discovery workflow.

  • Cloud object storage: Amazon S3 and S3-compatible storage, Azure Blob, and Google Cloud Storage.
  • File shares and transfer: Azure File Shares, SMB2/3, NFS, and FTP/FTPS.
  • Local storage: Configured file-system paths available to DataSunrise.

Scope each task to the buckets, containers, shares, paths, tags, or files that matter to the review.

Inspect Files, Documents, and Archives

DataSunrise reads common data files and business documents, opens archives, and extracts text for classification.

ContentExamples
Data filesCSV, JSON, XML, Parquet, SAS, and Avro
DocumentsPDF, DOCX, PPTX, and additional formats handled through Apache Tika
Archives and compressionZIP, 7z, RAR, TAR, GZIP, BZIP2, XZ, Zstandard, and other documented formats

A task can inspect a complete file or a configured leading-byte range. Its processing report also identifies encrypted, damaged, oversized, or inaccessible content that needs attention.

Read Sensitive Text in Images

Documents often contain sensitive information as images rather than selectable text. DataSunrise uses OCR to read supported image formats and image-based content inside PDFs, Word files, and presentations.

Native OCR works across connected storage. Amazon Textract adds an S3 processing option, while built-in image analysis can recognize MRZ documents and payment cards.

Scale and Repeat Discovery

Run a task on demand or schedule it to keep the inventory current. For large stores, narrow the scan by path, tag, object filter, or file scope, and use incremental scanning to focus on new or changed content where available.

Large jobs can run across multiple DataSunrise servers. Results include scan statistics and processing errors, so teams can see what completed and what needs attention.

Using findings

Turn Findings Into a Clear Next Step

Each result shows the file or object path and the Information Type that matched. Security and privacy teams can use that evidence to investigate unexpected storage, plan cleanup, answer compliance requests, and prioritize protection.

Export selected findings to CSV or PDF, or add them to Object Groups for later DataSunrise policies.

Need protected file copies? Static Data Masking creates masked CSV, JSON, and XML files. Need broader cloud inventory and posture context? Active DSPM brings those findings into the same platform.

FAQ

Frequently Asked Questions

Can DataSunrise scan Google Cloud Storage?

Yes. DataSunrise connects directly to Google Cloud Storage with a service account and scans selected buckets and paths.

Can DataSunrise inspect archives?

Yes. DataSunrise processes ZIP, 7z, RAR, TAR, and other archive and compression formats, and reports files that need a different extraction approach.

What is the difference between native OCR and Amazon Textract?

Native OCR reads supported image content across connected storage. Amazon Textract adds an OCR option for content in Amazon S3.

Can DataSunrise create protected file copies?

Yes. File Static Data Masking writes protected CSV, JSON, and XML copies through a separate batch workflow.

Can DataSunrise review Amazon S3 access activity?

Yes. DataSunrise can collect Amazon S3 Server Access Logs for audit and investigation.

See how DataSunrise works with your technology stack

View Integration Examples