Pylegon watches your restricted GCS buckets and alerts you the moment anyone reads them. Silent until touched. Loud the moment it matters.
Label the buckets that hold sensitive data. Pylegon only receives access metadata from your audit logs, never file contents.
Pylegon will suggest which buckets hold PII, financials, and secrets, for your legal and DPO teams to approve.
Any read on a restricted bucket triggers an alert with who, what, when, and from where. Email today; Slack and webhooks soon.
No dashboards to babysit. Pylegon stays invisible until someone reads what they shouldn't — then it tells you who, what, and exactly when.
Repeated reads by the same person are grouped, so one bulk download is one alert, not thousands.
Pylegon works from access audit logs. File contents never leave your project.
Alerts arrive within minutes of access, with the actor, object, time, and caller IP attached.
Google Cloud Storage first. More surfaces arrive on the roadmap.
Access alerts on restricted buckets, in early access.
Expanding across cloud storage surfaces.
Tripwires inside the data warehouse itself.
Join the waitlist for early access to restricted-endpoint detection and instant access alerts.
Request access