Security, Identity, and Compliance
Amazon Macie
Amazon Macie discovers and classifies sensitive data in Amazon S3 using managed identifiers and custom data identifiers. It can stop unsuitable objects from entering a RAG or tuning corpus and monitor data-exposure posture.
Key points
- Discovery jobs inspect selected S3 objects and publish findings
- Managed identifiers recognize many common credential and personal-data formats
- Bucket-level findings flag public access and encryption risks
When to use it
- Quarantine documents containing regulated identifiers before ingestion
- Inventory sensitive training artifacts across S3 buckets
Exam tips
- Choose Macie for S3 data discovery and Comprehend for PII inside application text flows
- Route findings into an enforcement workflow; discovery by itself does not block ingestion