Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

11/18/2020
05:00 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Open Raven Launches Cloud-Native Data Protection Platform to Automate Security and Privacy Operations

Platform secures data lakes built on Amazon Web Services and S3.

LOS ANGELES, November 18, 2020/--Open Raven, the company transforming cloud data protection, today launched the Open Raven Cloud-Native Data Protection Platform to operationalize data security and privacy in the cloud. To prevent data breaches, it automates asset discovery and data classification, provides real-time mapping and policy-driven protection for Amazon Web Services and S3. The Open Raven Platform is generally available today. 

The Open Raven Platform auto-discovers where data is located in the cloud, what type of data it is -- personal, sensitive, or regulated, -- as well as who has access to it and where it can flow for full visibility, control, and protection. 

“Before COVID-19, security and cloud teams were already short-handed. The rapid shift to remote work driven by the pandemic only increased workload, further exacerbating the problem,” said Dave Cole, Co-founder and CEO of Open Raven. “We created the Open Raven Platform to help these teams restore visibility and protection of their cloud data, removing pain driven from approaches that are manual, time intensive and expensive.” 

With the Open Raven Cloud-Native Data Protection Platform, security and cloud teams now have a unified solution for the following actions: 

●      Discover all data and resources in a public cloud environment, including both native and non-native repositories. Real-time mapping highlights problem areas at a glance while search allows for pinpointing specific data and resources.

●      Classify data assets by identifying personal, sensitive and regulated data on a scheduled, event-driven or continuous basis. Open Raven uses a variety of techniques from pattern matching to machine learning to describe data while providing live verification via APIs to further boost accuracy. 

●      Monitor using default or custom policies based on Open Policy Agent that combine both cloud asset and data context in rules that enable continuous or point in time monitoring for a full range of security, privacy and compliance use cases.

●      Protect cloud data through proactive alerting on data risk events as they happen, harnessing a wide range of integrations (via firehose API, webhook), or generating reports.

Open Raven’s cloud native design is built to handle big data. Discovery and classification are performed using serverless functions – not agents or network scanners that are challenging to deploy and struggle to scale horizontally. Flexible configuration options allow for fine-tuning of performance, completeness and cost. Being able to assess even large environments for compliance eliminates previously painstaking manual efforts to report on data inventory, data transfer and other risk factors. It can be used to create the foundation for compliance in accordance with laws and standards such as FFIEC, GDPR, CCPA, PCI-DSS, HIPAA, and SOC2.

“Open Raven is helping us transform how we approach data security. Legacy tools only look at cloud resources or privacy, but don’t tell us if data is safe,” said Justin Dolly, Chief Security Officer of Sauce Labs.  “Open Raven is the first platform that gives us real-time visibility into the safety of our cloud data, helping us to close security gaps faster.”

Additional Information

●      The Open Raven Cloud-Native Data Protection Platform is a subscription-based service with annual and multi-year options available. Pricing is based on the amount of storage and number of data stores in the environment, such as the number of AWS S3 buckets and RDS instances. Included in the price of each data store is 10G of data.

●      Open Raven is also offering a free trial of The Open Raven Platform. 

●      For more information, please visit www.openraven.com.

About Open Raven

Open Raven is the cloud native data protection platform that automates security and privacy operations to prevent data breaches, leaks, and compliance incidents. The company was co-founded in 2019 by security veterans Dave Cole and Mark Curphey and is headquartered in Los Angeles. Open Raven has received funding from Kleiner Perkins and Upfront Ventures, as well as cybersecurity leaders, including Niloofar Razi Howe and Phil Venables. Connect with us on Twitter or LinkedIn

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Why Vulnerable Code Is Shipped Knowingly
Chris Eng, Chief Research Officer, Veracode,  11/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-23727
PUBLISHED: 2020-12-03
There is a local denial of service vulnerability in the Antiy Zhijia Terminal Defense System 5.0.2.10121559 and an attacker can cause a computer crash (BSOD).
CVE-2020-28175
PUBLISHED: 2020-12-03
There is a local privilege escalation vulnerability in Alfredo Milani Comparetti SpeedFan 4.52. Attackers can use constructed programs to increase user privileges
CVE-2020-13524
PUBLISHED: 2020-12-03
An out-of-bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 uses SPECS data from binary USD files. A specially crafted malformed file can trigger an out-of-bounds memory access and modification which results in memory corruption. To trigger this vulnerability, the victim n...
CVE-2020-13525
PUBLISHED: 2020-12-03
The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL injection in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
CVE-2020-23726
PUBLISHED: 2020-12-03
There is a local denial of service vulnerability in Wise Care 365 5.5.4, attackers can cause computer crash (BSOD).