Protect what matters.Detect what changes.

tamper periodically audits your S3 Buckets to detect the first signs of Ransomware on your Objects.

4,8 4,7
bucket-prod-01
hover an object
audit #4127
watching
unchangedchanged since last audit1 square = 1 object · not to scale
Waiting for next audit

Compatible with any S3-Object Storage, Cloud or On-Prem.

  • AWS
  • Azure
  • Scaleway
  • OVHcloud
  • Backblaze
  • Wasabi
  • IBMCloud
  • Oracle
  • Outscale
  • Linode
  • Leviia
  • DigitalOcean
  • MinIO
  • Ceph
  • RustFS
  • Garage
  • Versity
  • Artesca

Ransomware goes where your data lives.

Object storage is the last line of recovery, and the first thing attackers corrupt. Most teams only find out when they try to restore.

107seconds

Average time to encrypt 100 GB once a cloud storage account is compromised.

82%

Of breaches involve cloud data in misconfigured S3 buckets.

€13,250

Average daily cost an SME absorbs after a ransomware attack.

Ransomware never announces itself. It starts with a handful of objects changing quietly, then your backups, then everything. tamper looks for that first change.

Anatomy of a ransomware attack

  1. 1/4

    Without tamper, backups are quietly encrypted over days.

    A stolen key, your backup bucket. Object after object gets encrypted silently, staying under the radar for weeks. By the time anyone looks, the recovery plan is gone.

  2. 2/4

    Rewind. Same attack, but tamper is watching.

    Same key, same bucket, same attack. This time every object is fingerprinted and audited every hour.

  3. 3/4

    Caught at the very first hour.

    The audit sees entropy jump on a handful of files within the hour, confirms encryption with AI and pages the on-call team.

  4. 4/4

    Restore a few files, not a whole company.

    Affected objects roll back to their last clean version. The rest of the bucket was never touched.

Elapsed
T+ 000.0 h
Objects encrypted
0 / 4,096
Data encrypted
0.0 GB
Status
Nobody watching
s3://prod-backups, 1 square per objectSimulation

Detect the first change, not the last file.

Your buckets hold backups, contracts, datasets and logs. tamper fingerprints every object and tells you when one changes in a way it shouldn't.

Catch the first encrypted object.

Audits run every hour and compare each object to its last known fingerprint. A few encrypted-looking objects are enough to raise the alarm, while most of your bucket is still intact.

27 objects changed
entropy 7.98
24 audits agolatest audit

Change provider. Keep your security.

tamper speaks the S3 protocol, not a vendor dialect. Move from a Storage Provider to a HyperScaler ; or vice-versa ; stay compliant, protected and your monitoring, policies and alerts stay exactly as they are.

tamperPoliciessameAlertssameHistorysame

Runs inside your perimeter.

Deploy tamper as a virtual machine on your existing infrastructure. Objects metadata and insights stay on your perimeter.

On-Premises Infrastructure tamper FIM - DSPM - DAM - DLPVisualisationsAlerting S3 API HyperScaler Cloud Storage Provider On-Premises Object Storage your buckets,wherever they sit

Know what changed, and how bad it is.

AI reads each modified object and scores its severity and integrity: a routine edit, sensitive data, or likely encryption. Your team gets a verdict, not a diff to decode.

logs/app-2026-09-24.loglowLines appended. Routine change.
exports/customers.csvcriticalEncrypted. Contains names, emails and IBANs.
assets/banner.pnglowMetadata updated.
Deployment
30 minutes
Throughput
1M objects / hour
Agents to install
None
Protocols
S3, R2, B2, Ceph
Ships as
.qcow2, .ova, AMI
UI UI UI UI UI UI
UI UI UI UI UI UI
UI UI UI UI UI UI
UI UI UI UI UI UI

Protect what matters.
Detect what changes.

Enhance object storage visibility. Discover tamper.

One solution to unlock insights about what's happening to your data, even when nothing should.

Global visibility on your Bucket's Data Metrics

tamper scans your buckets at every run, compiling high-level metrics so you get the right insights precisely when you need them.

Granular insights into your objects' lifecycle

At every audit, tamper logs object operations and uses AI to analyze modifications for potential tampering. With DLP reports, you instantly spot sensitive data exposure and detect corrupted files, early warnings of ransomware encryption.

Pinpoint every action and stop threats at the source

Leveraging our S3 Gateway and DAM module, tamper captures and correlates every single data access: who did what, when, from where, and how. tamper sees it all.

Boost your security posture in just a few clicks

Audit your configurations, raise your security score, and enforce robust safeguards instantly, no need to wrestle with convoluted dashboards or complex proprietary APIs.

Audit all your buckets and stay ahead of the curve

tamper monitors multiple buckets simultaneously, scanning up to a million objects per hour. With built-in canary objects, you'll be the first to know if anything touches buckets that should remain strictly untouched.

4 pillars. One solution.

Teams usually stitch a FIM, a DSPM, a DAM and a DLP together. tamper runs all four on the same audit.

From darkness to insights, every hour.

No agents, no changes to your processes, no workflow disruption. tamper only collects metadata from your resources to infer behaviours and deliver actionable insights.

Add your S3 Buckets

Point tamper at any S3-compatible bucket with your credentials. Setup takes about 3 minutes, and a baseline audit fingerprints everything already there.

Provider : Scaleway (S3) Bucket : bucket-prod-01 Status : Connected Baseline : 148,576 objects fingerprinted

Run your first audits

Every hour, up to a million objects, tamper lists every metadata, perform FIM diff checks and alert you if thresholds are exceeded.

Audit : #127 · 06:00 AM UTC Listed : 148,454 objects Options : AI Analysis - DAM Correlations using S3 Gateway Status : Completed - See findings

Evaluate the changes

See which Objects are added, deleted, modified, renamed or moved, let AI characterize changes on modified Object and evaluate DLP reports on Object's Severity & Integrity levels.

Added : 356 Modified : 27 Deleted : 122 Moved : 14 Renamed : 3

Let AI characterize the risks

Each modified object is checked for known indicators of compromise and for signs of encryption, then scored for severity and integrity.

Entropy : 3.9 → 7.98 Signature : .xlsx → .wannacry Severity : CRITICAL Verdict : Object corrupted

Get alerted after each audit

Findings reach Slack, PagerDuty, Jira, ServiceNow, ZenDesk, Grafana and more. Alerts are thresholded, so only what matters gets through.

Slack : Alert sent #sec-alerts PagerDuty : P1 - storage-team Grafana : 404 on metric tamperOne : Object timeline updated

Discover your objects lifecycles on tamperOne

A unified, single-pane-of-glass platform to gain deep visibility on each object. Actions, Access, AI Reports, Accountability, you get the full picture.

Object : investors-reports-Q124.pdf Lifecycle timeline : Added Nov 04, Modified March 12 Correlated events : 3 total download from 1 CN IP

See the whole life of every object.

After each audit, tamper pushes its findings to the tamperOne analytics platform. Follow any object from its first upload to its first alert.

Stay tuned for tamper One, coming soon !
tamper One Coming Soon

If it lives in a bucket, it can be tampered with.

Object storage now runs every industry. Four places where one silently changed object gets expensive.

  • E-commerce

    Secure product catalogs, pricing databases, and customer transaction logs against silent corruption and ransomware.

    s3://catalog-eu/pricing/
  • Creative

    Protect valuable digital assets, video renders, and design repositories from being held hostage or irreversibly modified.

    s3://assets-production/
  • Industry

    Ensure the integrity of IoT telemetry, manufacturing blueprints, and supply chain manifests essential for daily operations.

    s3://factory-telemetry/
  • Healthcare

    Maintain the absolute immutability of patient records, PHI, and medical imaging archives while adhering to strict compliance.

    s3://phi-archive/2026/
Plugs into PagerDuty ServiceNow Zendesk Slack Jira Trello Grafana Freshservice Email ... and more to follow !

Pick how far you want to see.

Every plan includes deployment support. Start with a 30-day trial license, then scale from one bucket to a dedicated appliance.

Genesis
Cloud data security, one click away.
€30per month · 1 bucket
Start 30-day trial
Monolith
Centralized data with automated AI monitoring.
from €200per month · 1-10 bucket
Start 30-day trial
Universe
Global visibility, on a dedicated appliance.
from €960per month · 10+ buckets
Talk to us
Coverage
Buckets11-1010+
Objects100K10M100M
Manual Audit possibleYesYesYes
Audit frequencyDailyUp to hourlyUp to every 15 minutes
At-Scale Analytics
tamperOne Access–✓✓
Response
Third-party integrations1Up to 3All
Detection - FIM
File Integrity Monitoring✓✓✓
IoC matching on audited objects✓✓✓
Data Metrics✓✓✓
Audits History✓✓✓
Characterisation - DLP
Entropy Check on Audited Objects–✓✓
AI analysis of modified objects–✓Unlimited, local
AI tagging of analyzed objects–✓✓
DLP reports–✓✓
Canary objects–✓✓
Access - DAM
Data Access Monitoring–✓✓
S3 Gateway–✓✓
Posture - DSPM
Configuration scoring✓✓✓
CIS benchmark✓✓✓
FinOps visibility✓✓✓
Optimization Opportunities–✓✓
Auto-Fix of security options–✓✓
Deployment and support
Where it runsYour VMYour VMDedicated appliance
Support5 days a week5 days a week7 days, dedicated contact
Hardware maintenance––✓
CommitmentMonthlyMonthly2 years minimum

Public prices adjust to your use case, constraints and storage setup. Every plan includes onboarding, and an extended prototyping phase when your S3 storage is on-premises.

Be first to see your objects’ full story.

Leave your email and we’ll write once, when the tamperOne Analytics plateform opens.

Questions, answered.

Why audit object storage on its own?

Since 2019, buckets have been a first target for attackers. Silent attacks corrupt your remote backups so you can't trigger a recovery plan. Auditing is how you know your backups are still viable.

How is tamper different from cloud-native tools?

Hyperscaler tools are proprietary and tied to their own platform. tamper works with any storage that speaks S3, an open standard, so you can change storage provider without changing security tools.

How does it catch ransomware?

Each audit lists every object that was added, modified, deleted, renamed or moved, checks for known indicators of compromise, and flags content that looks encrypted. You are alerted while the attack is still unfolding.

Does it help with GDPR, ISO 27001 and NIS2?

tamper scores your bucket configuration against CIS benchmarks, and its DLP module tracks personal and sensitive data in your files. Both give you evidence for audits.

Will it flood us with alerts?

No. Alerts fire on thresholds, configuration changes or affected files, and each rule can be tuned or turned off.

How does tamper accelerate incident response?

By tracking objects that suffered integrity alterations, you know exactly which files were corrupted, what sensitive data they contained, and the precise time of the attack. This information is crucial for forensic teams and allows you to retrace the cyberattack's path.

What is the deployment time and ROI?

Deployment is fast because attackers don't wait. Our team can install tamper remotely, configure it, and run the first audits in half a day. If you need dedicated access, our tamper Universe solution is ready to use within two hours after on-premise installation.

Who builds tamper?

tamper is developed by SIENNA, a cybersecurity company based in Lille, France, which also runs offline tape storage for sensitive data. The same team handles demos, deployment, maintenance and support.