Welcome to Argus
Argus is a multi-tenant Data Security Posture Management (DSPM) platform. It deploys a lightweight agent into your own cloud account to discover, classify, and continuously monitor sensitive data - so you always know what sensitive data you hold, where it lives, how exposed it is, and whether it meets your compliance obligations. Your data never leaves your environment: the agent processes everything in place and sends back only structured findings.
What Argus does
Section titled “What Argus does”- Discovers every datastore in your account - S3, RDS, DynamoDB, and Redshift today, with Azure on the way - and keeps that inventory current as your environment changes.
- Classifies the sensitive data inside them: roughly seventy data types across seven categories (PII, financial, health, credentials, API keys, intellectual property, legal), validated with real checksums so a match is a match, not a lucky guess.
- Estimates exposure honestly. Instead of scanning every object, Argus samples intelligently and extrapolates with a statistical confidence interval, so a finding says “an estimated 12,000 records, 95% confident between 10,400 and 13,600” - never false precision.
- Scores risk on every datastore by content, configuration, and who can reach it, so your worst exposures rise to the top on their own.
- Maps to compliance - GDPR, HIPAA, PCI DSS, SOX, CCPA, ISO 27001, SOC 2, and GLBA - and turns your real posture into a score you can defend to an auditor.
- Watches your access surface - which identities are over-privileged, stale, or can reach sensitive data - and fits a security team’s real workflow with policies, alerts, remediation, and a full audit trail.
Why it is built this way: the agent makes outbound HTTPS calls only (no inbound ports, no shared credentials, no data egress), and every number it reports is backed by statistics you can inspect rather than a black box you have to trust.
Where to start
Section titled “Where to start”5-minute quickstart
Deploy your first agent and run your first scan. Terraform module included.
Deploy the agent
Fargate, EC2, or a local container - pick the runtime that matches your stack.
How Argus works
Discovery, sampling, classification, risk, and confidence - the engine behind every finding.
Compliance & scoring
How findings map to GDPR, HIPAA, PCI DSS and more, and how the score is built.
How these docs are organized
Section titled “How these docs are organized”Getting Started takes a new tenant from zero to a first scan, and Core concepts at a glance is the one-screen orientation if you prefer the vocabulary before the clicking. Deploy the Agent covers every way to run the lightweight scanner in your own cloud. How Argus Works explains the engine: discovery, sampling, classification, confidence, risk, identity, and compliance. Using Argus walks the product page by page and says what each action actually does. Administration covers tenancy, roles, users, and the audit log. Reference holds the consolidated statuses and lifecycles, the glossary, and the agent’s IAM permissions.
Use the search bar at the top (or press Ctrl K / Cmd K) to jump to anything.