Compliance

The access record assessors ask for

One artifact: an object-level record of who accessed what in your cloud object storage, and when. Storage access only. Not a compliance platform, and not an assessment of your controls.

Object access history

s3://prod-billing/exports/2026-05/invoices-0412.parquet
Time (UTC)IdentityClientOperationSource
2026-05-14 02:11:04role/etl-billing-nightlyaws-sdk-javaPUTinternal
2026-05-14 06:40:22role/reporting-serviceboto3 1.34GETinternal
2026-06-02 09:17:51role/reporting-serviceboto3 1.34GETinternal
2026-07-28 23:52:10sso/AWSReservedSSO_analystMozilla, consoleGETexternal

4 accesses over 11 weeks, retained and queryable

Illustrative data.

What a record contains

Derived from S3 server access logs and S3 Inventory. Every field below comes from the log itself, not from inference.

RequesterIAM ARN or canonical user ID that made the request
Object keyThe specific object accessed, full prefix path
BucketBucket name and owning account
OperationGET, PUT, DELETE, LIST, HEAD, and the rest
TimestampRequest time, to the second
HTTP statusSuccess, 403, 404, and other response codes
Error codeAWS error code where the request failed
Bytes sentVolume moved on the request
Object sizeSize of the target object
Source IPRemote IP of the requester
User agentSDK, tool, or client string, including version
Authentication typeHow the request was signed
TLS versionTransport version used
Access point ARNWhere the request came through an S3 access point

Derived views

Built by correlating the above across time and identity. Still metadata only.

Access history per object, per prefix, per identity
Deviation from an identity's own historical access pattern
Volume, rate, and parallelism per identity
Dormant prefix reactivation, based on time since last read
Cross-account access
Enumeration behavior, including 403 and 404 sequences
SDK version and known CVE exposure, parsed from user agent
Source IP, subnet, region, and internal versus external classification

Coverage and limits

State these to your assessor before they find them.

Best-effort delivery

AWS logs the substantial majority of S3 requests but does not guarantee completeness, so reCost is an evidence and detection layer, not a substitute system of record where a framework demands provable completeness.

Data plane only

S3 access logs, not CloudTrail, so control-plane changes like bucket policy and IAM edits are out of scope.

Retention depends on plan tier

The twelve-month PCI requirement is met on higher tiers only.

No content classification

reCost records access to objects you have already classified. It does not determine whether an object holds cardholder data or ePHI.

Detection only

No blocking, no quarantine, no automated remediation. Findings output to your SIEM, DDR, or response process.

S3 today

Object storage on other cloud providers is not covered.

Framework mapping

Indicative. Validate against your own controls and your assessor.

PCI DSS v4.0

Requirement 10
Asked

Log all individual access to cardholder data. Retain audit log history for at least twelve months, with the most recent three months immediately available for analysis, meaning queryable without a restore.

reCost provides

Object-level record of every read and write against objects in your cardholder data environment, per identity, with source IP and timestamp. Three-month immediate availability is native and queryable. Twelve-month retention on higher plan tiers.

reCost does not provide

Control-plane changes. Completeness guarantees. Determination of which objects hold cardholder data.

HIPAA Security Rule

164.312(b), 164.308(a)(1)(ii)(D)
Asked

Mechanisms that record and examine activity in systems containing ePHI, and regular review of that activity. The rule sets no fixed retention period.

reCost provides

The recording and review layer for ePHI held in S3. Access history per object and identity, with deviation from historical pattern.

reCost does not provide

Determination of which objects contain ePHI. Control-plane audit.

SOC 2

CC6.1, CC7.2
Asked

Logical access controls over protected information, and monitoring for anomalies that could indicate a security event. Assessors want evidence the monitoring runs, not that it exists on paper.

reCost provides

Continuous, dated evidence that object storage access is monitored, with anomaly output an assessor can review.

reCost does not provide

Evidence for controls outside object storage.

Alternative note

SIEM with S3 data-plane logs ingested is the common answer. Most teams cut that feed for cost, which leaves the control evidenced by policy document only.

ISO 27001:2022

Annex A 8.15, 8.16
Asked

A 8.15 requires logs of user activities, exceptions, and information security events to be produced, kept, and protected. A 8.16 requires networks, systems, and applications to be monitored for anomalous behavior, with appropriate action taken on findings.

reCost provides

For 8.15, a retained per-identity access record over object storage, including failed and denied requests, which is the exceptions half of the control that log pipelines most often drop. For 8.16, behavioral baselines per identity and the deviation output that feeds your action process.

reCost does not provide

Log protection guarantees for the source logs themselves, coverage of systems outside object storage, or the action step in 8.16.

GDPR

Articles 32, 33
Asked

Security appropriate to risk, and breach notification within 72 hours. The notification requires knowing which personal data was accessed and by whom. Article 5(1)(e) requires you to define and justify your own log retention period rather than meeting a fixed one.

reCost provides

The object-level answer to what was actually read, by which identity, in what window. That is usually the question that stalls the 72-hour clock.

reCost does not provide

Identification of which objects hold personal data.

Alternative note

Reconstruct from CloudTrail, if data events were enabled before the incident. If they were not, the scope of the breach cannot be determined from logs after the fact.

Why organizations do not already have this

S3 server access logs are free to generate. You pay storage only. The cost is in reading them. At the scale where the record matters, the log volume is exactly what makes SIEM ingestion unaffordable, so the cheapest available source becomes the one nobody turns on.

reCost processes over 100 billion S3 requests per month across customers. The ingestion economics are the product.

Deployment

Agentless and read-only. reCost reads your existing S3 server access logs and S3 Inventory. Nothing is installed in your environment, no agent runs on your infrastructure, and no object contents are read.

Mapping is indicative and worth validating against your own controls and your assessor.

Talk to us
about an audit cycle.

Read-only role over logs and inventory. Metadata only. Multi-year queryable retention available.