The access record assessors ask for
One artifact: an object-level record of who accessed what in your cloud object storage, and when. Storage access only. Not a compliance platform, and not an assessment of your controls.
Object access history
| Time (UTC) | Identity | Client | Operation | Source |
|---|---|---|---|---|
| 2026-05-14 02:11:04 | role/etl-billing-nightly | aws-sdk-java | PUT | internal |
| 2026-05-14 06:40:22 | role/reporting-service | boto3 1.34 | GET | internal |
| 2026-06-02 09:17:51 | role/reporting-service | boto3 1.34 | GET | internal |
| 2026-07-28 23:52:10 | sso/AWSReservedSSO_analyst | Mozilla, console | GET | external |
4 accesses over 11 weeks, retained and queryable
Illustrative data.
What a record contains
Derived from S3 server access logs and S3 Inventory. Every field below comes from the log itself, not from inference.
Derived views
Built by correlating the above across time and identity. Still metadata only.
Coverage and limits
State these to your assessor before they find them.
Best-effort delivery
AWS logs the substantial majority of S3 requests but does not guarantee completeness, so reCost is an evidence and detection layer, not a substitute system of record where a framework demands provable completeness.
Data plane only
S3 access logs, not CloudTrail, so control-plane changes like bucket policy and IAM edits are out of scope.
Retention depends on plan tier
The twelve-month PCI requirement is met on higher tiers only.
No content classification
reCost records access to objects you have already classified. It does not determine whether an object holds cardholder data or ePHI.
Detection only
No blocking, no quarantine, no automated remediation. Findings output to your SIEM, DDR, or response process.
S3 today
Object storage on other cloud providers is not covered.
Framework mapping
Indicative. Validate against your own controls and your assessor.
PCI DSS v4.0
Log all individual access to cardholder data. Retain audit log history for at least twelve months, with the most recent three months immediately available for analysis, meaning queryable without a restore.
Object-level record of every read and write against objects in your cardholder data environment, per identity, with source IP and timestamp. Three-month immediate availability is native and queryable. Twelve-month retention on higher plan tiers.
Control-plane changes. Completeness guarantees. Determination of which objects hold cardholder data.
HIPAA Security Rule
Mechanisms that record and examine activity in systems containing ePHI, and regular review of that activity. The rule sets no fixed retention period.
The recording and review layer for ePHI held in S3. Access history per object and identity, with deviation from historical pattern.
Determination of which objects contain ePHI. Control-plane audit.
SOC 2
Logical access controls over protected information, and monitoring for anomalies that could indicate a security event. Assessors want evidence the monitoring runs, not that it exists on paper.
Continuous, dated evidence that object storage access is monitored, with anomaly output an assessor can review.
Evidence for controls outside object storage.
SIEM with S3 data-plane logs ingested is the common answer. Most teams cut that feed for cost, which leaves the control evidenced by policy document only.
ISO 27001:2022
A 8.15 requires logs of user activities, exceptions, and information security events to be produced, kept, and protected. A 8.16 requires networks, systems, and applications to be monitored for anomalous behavior, with appropriate action taken on findings.
For 8.15, a retained per-identity access record over object storage, including failed and denied requests, which is the exceptions half of the control that log pipelines most often drop. For 8.16, behavioral baselines per identity and the deviation output that feeds your action process.
Log protection guarantees for the source logs themselves, coverage of systems outside object storage, or the action step in 8.16.
GDPR
Security appropriate to risk, and breach notification within 72 hours. The notification requires knowing which personal data was accessed and by whom. Article 5(1)(e) requires you to define and justify your own log retention period rather than meeting a fixed one.
The object-level answer to what was actually read, by which identity, in what window. That is usually the question that stalls the 72-hour clock.
Identification of which objects hold personal data.
Reconstruct from CloudTrail, if data events were enabled before the incident. If they were not, the scope of the breach cannot be determined from logs after the fact.
Why organizations do not already have this
S3 server access logs are free to generate. You pay storage only. The cost is in reading them. At the scale where the record matters, the log volume is exactly what makes SIEM ingestion unaffordable, so the cheapest available source becomes the one nobody turns on.
reCost processes over 100 billion S3 requests per month across customers. The ingestion economics are the product.
Agentless and read-only. reCost reads your existing S3 server access logs and S3 Inventory. Nothing is installed in your environment, no agent runs on your infrastructure, and no object contents are read.
Mapping is indicative and worth validating against your own controls and your assessor.
Talk to us
about an audit cycle.
Read-only role over logs and inventory. Metadata only. Multi-year queryable retention available.