Deploy SnapshotShield

Deploy in 5 minutes. Data never leaves your AWS account. Our CloudFormation template creates a secure, least-privilege role that validates your subscription and enables automated snapshot testing.

Deploy CloudFormation
Auto-detect snapshots
Validate & Alert

CloudFormation Deployment

Secure deployment that follows AWS best practices and keeps your data in your account

1

Choose Your Plan

Select the pricing tier that fits your needs. All plans use the same secure CloudFormation deployment.

Developer

€10
1 AWS account
100 validations/month
Perfect for dev/test
Most Popular

Team

€50
Up to 10 AWS accounts
1,000 validations/month
Production ready

Enterprise

€150
Unlimited AWS accounts
Unlimited validations
Full compliance

Prices shown HT (excluding taxes)

2

Deploy CloudFormation Role

Deploy our CloudFormation template to create a least-privilege IAM role in your AWS account. This role enables SnapshotShield to securely validate your snapshots while keeping all data in your account.

What the CloudFormation template creates:

  • Least-privilege IAM role with minimal required permissions
  • Cross-account trust policy for SnapshotShield access
  • Subscription validation mechanism
  • Resource tagging for cost tracking and cleanup
Security & Compliance

The deployed role follows AWS security best practices with least-privilege access. It validates your subscription status and enables secure resource deployment only within your AWS account. The role must remain deployed for the solution to function properly.

3

Automatic Snapshot Detection

Once deployed, SnapshotShield automatically detects new RDS snapshots in your account and validates them according to your plan limits.

How it works:
  • • Download CloudFormation from backoffice
  • • Execute to create IAM role on your account
  • • Launch deployment from backoffice interface
  • • We deploy resources by assuming the role
  • • EventBridge detects snapshots with "snapshotshield" tag
  • • Step Function validates in dedicated/specified VPC
Validation includes:
  • • Snapshot integrity verification
  • • Database restoration testing
  • • Connection and query validation
  • • Source DB comparison (Enterprise)

Security & Compliance

Data never leaves your AWS account. Our deployment follows security best practices.

Least-Privilege Access

The CloudFormation role has minimal permissions required only for snapshot validation. No access to production data or other AWS resources.

Data Residency

All validation happens within your AWS account. Your data never leaves your infrastructure, ensuring compliance with data residency requirements.

Subscription Validation

The deployed role validates your subscription status and enforces plan limits, ensuring secure and authorized access to SnapshotShield services.

Deployment Requirements

What you need to deploy SnapshotShield in your AWS account

AWS Permissions Required

  • CloudFormation Access: To deploy the IAM role
  • IAM Permissions: To create roles and policies
  • RDS Access: For snapshot validation

What's Included

  • CloudFormation Template: Pre-configured and tested
  • Step-by-step Guide: Detailed deployment instructions
  • Support: Technical assistance during deployment

Important: Role Must Remain Deployed

The CloudFormation role must remain deployed in your AWS account for SnapshotShield to function. Deleting the role will disable snapshot validation. The role validates your subscription and enables secure access to validation services.

Ready to Deploy?

Choose your plan and deploy SnapshotShield in your AWS account. Data never leaves your infrastructure.

5-Minute Setup
Quick CloudFormation deployment
Secure & Compliant
Data never leaves your account
Full Support
Technical assistance included

Developer plan includes a 14-day free trial