Install bucketAV powered by Sophos in just 15 minutes and detect malware like viruses, worms, and trojans in your S3 buckets. Choose when to scan and keep full data control within your AWS account.
Real-time, scheduled, on-demand, on-access, and API virus scanning;
Commercial antivirus engine (Sophos);
Maximum file size of 5 TB (maximum S3 object size);
Real-time notifications and periodic reports about your bucket's status;
Automated mitigation: bucketAV automatically tags, deletes, or quarantines infected files;
It supports multiple AWS accounts and multiple S3 buckets
Key Benefits
Highest security standards: scan your data immediately or when suits you best and stay informed with instant notifications to detect even the latest viruses;
Data sovereignty: you can keep full control over your data because they never leave your AWS account;
Scalable: automatically scan as many files as needed ensuring cost efficiency even for spiky workloads;
Cost efficient: bucketAV runs on EC2 spot instances, which provide compute capacity at reduced costs compared to on-demand instances;
Simple: there is no need for additional UI or access management;
Fast: bucketAV will scan uploaded files within seconds to immediately detect malware;
Up-to-date Malware Database: bucketAV continuously updates malware signatures to protect you against the latest threats;
Streamlined process: bucketAV automatically tags, deletes, quarantines, and moves your data and notifies you about infected files
Want to know more about bucketAV or want to try it for free?
Contact us at hello@bucketav.com, we will be more than happy to help you!
Keeping your data safe and ensuring compliance has never been so easy and will take you just 15 minutes.
This product optionally collects your e-mail address for sending operational alerts. Your e-mail address is stored and processed using Amazon SNS in your AWS Account and is not shared with bucketAV.
Highlights
**Just 15 minutes to install** with a clear step-by-step setup guide and efficient support;
**Runs on Sophos**: commercial antivirus engine ideal for enterprises and critical
**Automated and ready-to-deploy solution**: it immediately runs on your own cloud infrastructure for Real-time, Scheduled, On-demand, On-access, and API virus scanning
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay across two usage-based dimensions that combine to form your total cost. The first charges for each GB of data scanned, whether the file turns out clean or infected. The second charges per vCPU hour for the EC2 instances that run the scans. As you scan more data, the per-GB charge grows with volume. As those instances run longer or scale up, the vCPU-hour charge grows too. You only pay while instances run; charges stop once you uninstall. Underlying AWS infrastructure charges bill separately from these two dimensions.
Top-of-mind questions for buyers
What counts as one GB of scanned data for billing?
One GB is a binary gigabyte, meaning 2^30 bytes, also called a gibibyte (GiB). You are charged per GB whether the scanned file is clean or infected. The volume of data your scanners process each billing period determines this charge.
Which dimension drives most of my bill — scanned data or vCPU hours?
Both charges apply at the same time. The per-GB charge grows with the amount of data you scan. The vCPU-hour charge grows as scan instances run longer or scale up. Data-heavy workloads lean toward the per-GB charge; long-running or high-throughput setups raise the vCPU-hour charge.
Am I charged when no files are being scanned or when instances stop?
You pay for vCPU hours only while EC2 scan instances run. Once you uninstall the software, those charges stop. The per-GB charge applies only to data actually scanned. Underlying AWS resources like storage and queues bill separately from these two dimensions.
bucketav.com
Helpful?
Vendor refund policy
There is no refund policy, but you can try bucketAV for free to see if it meets all your needs.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
AWS CloudFormation templates are JSON or YAML-formatted text files that simplify provisioning and management on AWS. The templates describe the service or application architecture you want to deploy, and AWS CloudFormation uses those templates to provision and configure the required services (such as Amazon EC2 instances or Amazon RDS DB instances). The deployed application and associated resources are called a "stack."
Version release notes
Deprecating DeleteInfectedFiles parameter use Delete infected files add-on instead
bucketAV Amazon S3 Antivirus powered by Sophos - Quick and decisive support via email:hello@bucketav.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Commercial antivirus engine powered by Sophos for detecting viruses, worms, trojans, and latest malware threats
Scanning Modes
Real-time, scheduled, on-demand, on-access, and API-based virus scanning capabilities
Automated Threat Response
Automatic tagging, deletion, quarantine, or movement of infected files with immediate notifications
Multi-Channel Alerting
Real-time notifications and periodic reports via email, Slack, Microsoft Teams, AWS Security Hub, Systems Manager OpsCenter, and Amazon SNS
File Size Support
Support for scanning files up to 5 TB, matching maximum Amazon S3 object size limits
Multi-Engine Malware Detection
Support for Sophos, CSS Premium, and CSS Secure engines that can be used individually or simultaneously to optimize detection accuracy, performance, and operational fit across workloads.
Multiple Scanning Models
Event-based scanning on upload, retroactive scanning on demand or schedule, and API-based scanning before write operations across Amazon S3, EBS, EFS, and FSx.
In-Tenant Deployment Architecture
Installation and operation inside customer AWS account with data remaining within the environment or region, supporting private VPC endpoints and linked account management.
Automated Response and Remediation
Automated quarantine, tagging, deletion, and alerting capabilities with object tagging for downstream workflow automation and enforcement decisions.
Large File and Broad File Type Support
Support for virtually no file size or file type restrictions with CSS Premium engine, enabling protection across enterprise storage, data lakes, backups, and media workflows subject to AWS limits.
Multi-Engine Malware Detection
Utilizes 30+ anti-malware engines for malware threat detection across uploaded files.
Real-Time File Scanning
Scans files in real-time prior to upload to S3 buckets, triggered by S3 events.
Deep Content Disarm and Reconstruction
Employs Deep CDR technology to disarm active embedded threats and reconstruct sanitized file versions to prevent zero-day attacks.
Scheduled and On-Demand Scanning
Supports flexible scanning modes including real-time, scheduled weekly or monthly scans, and on-demand file inspections.
Sensitive Data Detection and Redaction
Automatically detects compliance violations and sensitive data within files, with capability to redact or report findings.
Reduced manual security overhead while file scanning integrates seamlessly into existing workflows
Reviewed on Sep 24, 2026
Review from a verified AWS customer
What is our primary use case?
Our main use case for bucket_av involves using the Scan on Access feature to scan files whenever they are accessed from our S3 buckets, specifically files that are provided by our customers.
bucket_av works for our team in a fully transparent manner, as we are using the Scan on Access functionality which allows us to use the S3 bucket as if it were a normal S3 bucket.
It fits very nicely into our workflow and required no changes in our application code.
What is most valuable?
The Scan on Access feature of bucket_av stands out especially for us because we did not have to make any changes to our application code, which was already using an S3 bucket.
That is the main feature we are using; we are not using any other features at the moment.
bucket_av has positively impacted our organization by giving us confidence that the files we are handling do not contain any malware or anything of that nature, so it definitely brings benefits to our security posture.
What needs improvement?
bucket_av has actually added the features that we wanted within a couple of days, showing they were very responsive and helpful.
My experience working with their team has been great, as the response times have always been very short and they have always taken any input seriously and acted on it.
For how long have I used the solution?
We have been using bucket_av for about two years.
What do I think about the stability of the solution?
bucket_av is stable with zero downtime, but there was one incident when it did not seem to scan the files; however, restarting the nodes helped and that has happened only once in two years.
What do I think about the scalability of the solution?
bucket_av's scalability is perfect, as the autoscaling group seems to work just fine and handle all the traffic we can throw at it.
How are customer service and support?
The customer support for bucket_av is perfect, as they usually answer within thirty minutes of an email and always provide very clear answers to the questions that we have.
Which solution did I use previously and why did I switch?
In a different project, we used a self-hosted ClamAV solution, which required continuous instances and maintenance, so I switched to bucket_av because it just works on spot instances for us.
How was the initial setup?
It was very straightforward to deploy bucket_av in my environment with Terraform, utilizing the Terraform CloudFormation they provided.
My experience with the configuration process was mostly easy, though the only issue was that they changed the subnet feature somewhat, which resulted in some update failures, but other than that, it was very straightforward.
What was our ROI?
I have seen a return on investment, as in a previous project where we managed our own antivirus solution, it was quite a bit more work and required effort almost monthly, if not weekly, so bucket_av is clearly saving us time and the pricing is perfect.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for bucket_av was as expected with no surprises; it is a very cost-effective way to perform this task.
Which other solutions did I evaluate?
We discovered bucket_av and it was the most convenient option right away, so there was no need to look for anything else.
What other advice do I have?
My experience with the procurement process was easy.
It was really easy to buy bucket_av through the AWS Marketplace; I encountered no problems.
My thoughts about the metering and billing experience are positive, as bucket_av provides their own dashboard for the volumes and data usage, so it is fairly easy to see how much data is going through and the amount of money it costs.
My advice to others looking into using bucket_av is that if you want a bolt-on solution to scan S3s, I think it is a perfect solution if you do not want to modify your application code that is already using an S3 bucket.
I give this product a rating of five out of five.
reviewer2866284
Secure file scanning has supported privacy compliance while pricing still needs improvement
Reviewed on Jun 30, 2026
Review from a verified AWS customer
What is our primary use case?
We use BucketAV for scanning S3 objects for potential malware and viruses.
How has it helped my organization?
BucketAV has helped our organization by assisting with privacy compliance when handling highly sensitive data.
What is most valuable?
The ease of set-up and configuration are valuable. The ability to scan S3 objects on upload and quarantine files if appropriate is very useful since it allows us to have a compliant architecture. In addition, the support from the BucketAV team has been quick and reliable. I trust that we can rely on this product for future maintenance.
What needs improvement?
The pricing is a little high. We still need to evaluate if pricing is acceptable once we start scanning more objects.
For how long have I used the solution?
I have been using the solution for 3 weeks.
Which solution did I use previously and why did I switch?
We did not use a different product before BucketAV.
What's my experience with pricing, setup cost, and licensing?
The pricing is competitive, but I wish it was a little cheaper.
Which other solutions did I evaluate?
We evaluated Cloud Storage Security.
What other advice do I have?
I don't have additional comments.
Jhair C.
Nice product
Reviewed on Nov 04, 2024
Review from a verified AWS customer
Easy to install and integrate. It also has a lot of configurations that makes very flexible. Quick technical support responses too.
It is really good for our use case.
Christoph E.
Good product
Reviewed on Jun 23, 2024
Review from a verified AWS customer
BucketAV conviced us regarding - slim infrastructure requirements and costs (at least one EC2 instance, SQS, SNS and Lambdas) prepared as handy CloudFormation stack templates. - setup modes (creates a dedicated VPC or re-use an existing one) - intuitive and comprehensible data flows and great documententation - dashboard tooling - easy to integrate into own applications with prepared SNS finding topics - it fits with GDPR - reduced maintenance (automated AV updates) - quick support responsive
Tanmay
Good product for most use cases
Reviewed on Jun 07, 2024
Review from a verified AWS customer
BucketAV has a comprehensive list of features and scan modes that can fulfill a wide variety of scanning needs - scheduled scans, on demand, realtime (on file upload) and on access (on file download) as well as reporting integrations and dashboards
Its not a perfect product as there is no "one shoe fits all sizes" in this category. Out of the box it will fulfill 95% of use cases. For the remaining 5% the user will find a really good base setup that they can build upon to get their custom solution
They are really fast with support, and organised a call with me within a day
Its a really good product and I hope that it keeps getting better