BYOK Object Store Plugin by Portal26 provides advanced cloud data protection for object stores like Amazon S3, Azure Blob, and Google Cloud Storage. It automatically encrypts data using NIST FIPS 140-2 validated encryption and builds an encrypted search index with metadata. For structured data, it allows encrypted data to be searchable without decryption. Data from object stores is retrieved via the Portal26 Proxy and can be released in privacy-preserving formats, following existing RBAC. Portal26 allows external data owners to supply encryption keys (BYOK) or hold their own keys (HYOK). Customers can disable the use of their data by turning off keys. Portal26’s cloud data protection platform enables enterprises using object stores, as well as those building products on top of them, to secure large volumes of data from insider threats, malicious attacks, and data privacy violations. Portal26’s cloud data protection solution secures against cloud platform admins and privileged users within the enterprise. Key capabilities include seamless encryption, where all files are encrypted before reaching the object store, using keys from external key vaults and released securely based on RBAC. Portal26’s advanced cloud data protection software foils typical ransomware attack patterns by ensuring attackers cannot exfiltrate large volumes of unencrypted data via privileged access to AWS S3, Azure Blob, or GCS. In addition to encrypting file contents, Portal26’s encryption-in-use capabilities enable the encryption of file names while allowing end users to search normally, further strengthening data security. Portal26 integrates with key vaults for key materials and supports Bring Your Own Key (BYOK) and Hold Your Own Key (HYOK). Keys can be applied on a per entity, department, user, or file basis for strong security and data segmentation. Keys can be across clouds or on-prem. Searchable Encryption allows unstructured data in Portal26 protected object stores to be fully searchable without decryption, enabling data to stay encrypted longer and limiting decryption to small subsets with tight privacy controls. Enhanced security beyond native platform encryption. Native platform encryption secures data against platform administrators or compromises at the cloud platform level. Portal26 Object Store Proxy Architecture. Portal26 Studio allows configuration and management of modules and services, with access to logs, dashboards, and reports. Portal26 encryption meets stringent data protection standards in major regulations and frameworks. Portal26 releases data in nine privacy preserving formats for configuration with downstream systems. Compared to traditional tokenization solutions, Portal26 secures extensive data while maintaining usability. The Portal26 plugin can be operational within half a day, and the Proxy takes a few days. In attack scenarios, Portal26 offers visibility into observed, accessed, or exfiltrated data.