Go to IAM console → Users → Create user. Attach the managed policy AmazonS3ReadOnlyAccess directly, or use a custom policy below.
Amazon S3 Connector
Connect your S3 bucket, select files or prefixes, and anonymise at scale.
S3 Credentials
Enter your bucket details and IAM access keys.
IAM Setup 3 steps
IAM → Users → your user → Security credentials → Create access key. Choose Application running outside AWS. Copy the Access Key ID and Secret immediately — the secret is shown only once.
If your bucket has a restrictive bucket policy, ensure it allows s3:GetObject and s3:ListBucket for your IAM user's ARN.
Credentials are used only for this session and are never stored permanently. We recommend using a read-only IAM user.
Select Files
Choose files or prefixes to pull and anonymise.
Processing
Pulling files from S3 and scanning for PII.
Anonymised Results
Select a file to preview, then download.
Download All Files
Download the complete anonymised dataset.
Provenance Record
Full lineage metadata for this run.