BlobRouter

Your data stays yours.

BlobRouter audits your AWS storage without downloading your object contents. Here's exactly what that means in practice.

Access

  • Every audit runs on a read-only IAM role — BlobRouter cannot modify your infrastructure during a scan.
  • Audits use AWS STS temporary credentials that expire after the scan completes. We never use long-lived access keys for auditing.
  • Executing an approved migration requires separate, explicitly-authorized credentials — never the audit role.
  • You review and approve the exact IAM policy before connecting an account.

Data

  • BlobRouter never downloads or stores your object bytes. Audits and recommendations are generated from metadata only — bucket and object listings, sizes, storage classes, timestamps, and access signals.
  • When you enable routing, provider credentials are encrypted at rest with AES-256-GCM before they're stored, and decrypted in memory only to generate presigned URLs.
  • Data in transit is encrypted via TLS.

Application

  • Rate limiting on the API to prevent abuse.
  • Audit logging of scan and migration actions taken on your account.
  • Approved migrations copy each object individually and verify it landed before moving on. Migration execution is currently in beta while we finish hardening it.

Customer control

  • Revoke BlobRouter's AWS role at any time from your own AWS console — it's your IAM role, not ours.
  • Disconnect a connected provider from your dashboard.
  • Request deletion of your account and associated data by contacting us below.

No tracking

This site does not use analytics, advertising pixels, or non-essential cookies. See our Cookie Policy for the specifics.

Questions? chiragdave1312@gmail.com

← Back home