We utilize artificial intelligence for site translations, and while we strive for accuracy, they may not always be 100% precise. Your understanding is appreciated.
MetaDefender™ Storage Security

Multi-Layered Security
for Your Enterprise Storage

Protect your on-premises, hybrid, and cloud storage with a secure data storage solution designed to prevent breaches, minimize downtime, and support your compliance efforts.

  • Compliance Readiness
  • Broad Storage Coverage
  • Multi-Layered Protection

OPSWAT is Trusted by

0
Customers Worldwide
0
Technology Partners
0
Endpoint Cert. Members

Secure the Storage Platforms Your Business Relies On

AWS S3

Secure files uploaded to Amazon S3 with automated scanning, threat prevention, and policy-based remediation.

NetApp

Protect NetApp storage environments from malware, zero-day threats, and data breaches with integrated file security.

SharePoint

Scan files stored in SharePoint to help prevent malicious content from spreading across collaboration workflows.

A Product for Storage Trust

MetaDefender Storage Security connects to your existing storage and inspects files in real time, on a schedule, or on demand. Files are sent to MetaDefender Core, where the technologies scan, sanitize, and assess them. Based on the result, MetaDefender Storage Security allows, sanitizes, blocks, or quarantines the file and records the outcome for audit.

Protection for Enterprise Data Storage

Protect files at rest with a secure data storage solution that delivers robust malware and data security for both on-premises and cloud storage, keeping your critical workflows secure.

All-in-One Enterprise Data Protection Platform for Storage Security

  • Deliver real-time and continuous threat detection and prevention across on-prem, hybrid, and cloud environments 
  • Protect against zero-day threats and advanced attacks with Metascan™ Multiscanning, Deep CDR™ Technology, and Proactive DLP™ technology; File-Based Vulnerability Assessment and Adaptive Sandbox

Effortless Integration with Leading Storage Vendors and Collaboration Platforms

  • Seamlessly integrate real-time, scheduled and on-demand scanning across diverse storage environments—on-premises, hybrid, and cloud-native  
  • Integrate seamlessly with Amazon S3, SharePoint Online, Azure, NetApp, Wasabi, Scality RING… any SMB/NFS/SFTP/FTP or S3 compatible storage

Rapid Deployment within Your Existing Infrastructure

  • Deploy into infrastructure you already run, as virtual machines, on Kubernetes, or from a cloud marketplace image
  • Guided onboarding takes you from connecting your first storage unit to your first scan results the same day
  • Connect to SIEM and existing workflows through the web interface or the REST API

Automated File Privacy Controls for Regulatory Compliance

  • Customize policies and workflows to help meet stringent regulatory requirements for PCI DSS, HIPAA, GDPR  and more
  • Prevent sensitive data loss or leakage by detecting, blocking, quarantining, and controlling data entry, flow, and exit within the organization

Performant & Scalable Architecture with High Availability for Uninterrupted Protection

  • Scale horizontally with additional MDSS and MetaDefender Core instances as file volume grows
  • Automatic scaling on Kubernetes and MetaDefender Storage Security Cloud matches capacity to queue depth
  • Active-active configuration and high availability keep protection running through maintenance and failure
  • All-in-One Platform

    All-in-One Enterprise Data Protection Platform for Storage Security

    • Deliver real-time and continuous threat detection and prevention across on-prem, hybrid, and cloud environments 
    • Protect against zero-day threats and advanced attacks with Metascan™ Multiscanning, Deep CDR™ Technology, and Proactive DLP™ technology; File-Based Vulnerability Assessment and Adaptive Sandbox
  • Plug-and-Play Integrations

    Effortless Integration with Leading Storage Vendors and Collaboration Platforms

    • Seamlessly integrate real-time, scheduled and on-demand scanning across diverse storage environments—on-premises, hybrid, and cloud-native  
    • Integrate seamlessly with Amazon S3, SharePoint Online, Azure, NetApp, Wasabi, Scality RING… any SMB/NFS/SFTP/FTP or S3 compatible storage
  • Rapid Deployment

    Rapid Deployment within Your Existing Infrastructure

    • Deploy into infrastructure you already run, as virtual machines, on Kubernetes, or from a cloud marketplace image
    • Guided onboarding takes you from connecting your first storage unit to your first scan results the same day
    • Connect to SIEM and existing workflows through the web interface or the REST API
  • Automated Controls

    Automated File Privacy Controls for Regulatory Compliance

    • Customize policies and workflows to help meet stringent regulatory requirements for PCI DSS, HIPAA, GDPR  and more
    • Prevent sensitive data loss or leakage by detecting, blocking, quarantining, and controlling data entry, flow, and exit within the organization
  • Flexibility & High Availability

    Performant & Scalable Architecture with High Availability for Uninterrupted Protection

    • Scale horizontally with additional MDSS and MetaDefender Core instances as file volume grows
    • Automatic scaling on Kubernetes and MetaDefender Storage Security Cloud matches capacity to queue depth
    • Active-active configuration and high availability keep protection running through maintenance and failure

See It in Action

Learn how MetaDefender Storage Security protects data at rest across on-premises, hybrid, and cloud storage by applying Metascan Multiscanning, Deep CDR™ Technology, and automated scanning policies throughout the data lifecycle.

100,000 Files/Hour

in Tested Multi-Instance Deployments

100% Protection

Verified by SE Labs
Deep CDR™ Technology Testing

99.2%
Threat Detection

With Max Engines Package

Real-Time, Scheduled,
On-Demand Scanning

Across All Storage Types

Flexible

Deployment

25+

Storage Integrations

Stop Threats with Market-Leading Technologies

Deep CDR™ Technology

Stop Threats That Others Miss

  • Supports 200+ file formats
  • Recursively sanitize multi-level nested archives
  • Regenerate safe and usable files
100% Protection Score
from SE Labs
Metascan Multiscanning

More Engines Are Better Than One

  • Detect nearly 100% of malware
  • Scan simultaneously with 30+ leading AV engines
99.2% detection
with Max Engines package
Adaptive Sandbox

Detect Evasive Malware with Advanced Emulation-Based Sandboxing

  • Analyze files in a high-speed
  • Anti-evasion sandbox engine extracts IOCs
  • Identify zero-day threats
  • Enable deep malware classification via API or local integration
100x more resource efficient
than other sandboxes
< 1hr setup
and we’re working to help protect you from malware
Proactive DLP

Prevent Sensitive Data Loss

  • Utilize AI-powered models to locate and classify unstructured text into predefined categories
  • Automatically redact identified sensitive information like PII, PHI, PCI in 125+ file types
  • Support for Optical Character Recognition (OCR) in images
125+
Supported file types
OCR
image to text recognition
File-Based Vulnerability Assessment

Detect Application Vulnerabilities Before They Are Installed

  • Check software for known vulnerabilities before installation
  • Scan systems for known vulnerabilities when devices are at rest
  • Quickly examine running applications and their libraries for vulnerabilities
3M+
Data Points Collected from Active Devices
30K+
Associated CVEs with Severity Information
  • Deep CDR™ Technology

    Stop Threats That Others Miss

    • Supports [supportedFileTypeCount] file formats
    • Recursively sanitize multi-level nested archives
    • Regenerate safe and usable files
    100% Protection Score
    from SE Labs
  • Metascan Multiscanning

    More Engines Are Better Than One

    • Detect nearly 100% of malware
    • Scan simultaneously with 30+ leading AV engines
    99.2% detection
    with Max Engines package
  • Adaptive Sandbox

    Detect Evasive Malware with Advanced Emulation-Based Sandboxing

    • Analyze files in a high-speed
    • Anti-evasion sandbox engine extracts IOCs
    • Identify zero-day threats
    • Enable deep malware classification via API or local integration
    100x more resource efficient
    than other sandboxes
    < 1hr setup
    and we’re working to help protect you from malware
  • Proactive DLP

    Prevent Sensitive Data Loss

    • Utilize AI-powered models to locate and classify unstructured text into predefined categories
    • Automatically redact identified sensitive information like PII, PHI, PCI in 125+ file types
    • Support for Optical Character Recognition (OCR) in images
    125+
    Supported file types
    OCR
    image to text recognition
  • File-Based Vulnerability Assessment

    Detect Application Vulnerabilities Before They Are Installed

    • Check software for known vulnerabilities before installation
    • Scan systems for known vulnerabilities when devices are at rest
    • Quickly examine running applications and their libraries for vulnerabilities
    3M+
    Data Points Collected from Active Devices
    30K+
    Associated CVEs with Severity Information

Designed for Security-First Storage Environments

  • Partition-Based Real-Time Scanning

    Configure multiple scanning policies across different partitions within individual storage units. This granular approach allows enterprises to implement risk-based security policies that align with business requirements and data sensitivity levels.

    Efficient Rescanning of Large, Static Datasets

    Identity Scanning recognizes unchanged files and reuses previous scan results, significantly reducing scan time for large datasets. A configurable rescan interval ensures every file is periodically rescanned. Ideal for SMB/NFS backup repositories and available for on-demand and scheduled scans.

    Automated File Remediations for Comprehensive File Management

    Customize remediation workflows by combining Deep CDR™ Technology, and actions like copy, encrypt, block, move, or delete files. An optional "Delete empty folders after remediation" setting is added for SMB/NFS/SFTP shares.

    Customizable File Security Workflow

    Automated security pipeline with 5-stage processing (Scan Configuration → Advanced Threats → Vulnerabilities → Sanitization → File Tagging). Build custom, automated file processing pipelines tailored to your organization’s unique needs, all without additional API development.

    SharePoint Historical Version Scanning

    Scan all historical versions of SharePoint files, preventing threat actors from exploiting file versioning mechanisms to bypass security controls or maintain persistent access through restored infected versions.

    Multiple Workflow Destinations

    Remediation policies can specify up to five copy/move destinations, supporting complex data handling requirements common in regulated industries while ensuring business continuity through multiple backup locations.

    Cross-Domain Transfer for Classified Environments

    Compliant data transfer across classification domains with isolated handling of untrusted content. Shipped in 4.5.0.

    Native NetApp ONTAP Vscan Integration

    Native NetApp ONTAP Vscan integration, including AWS FSx for NetApp ONTAP, with multi-SVM support. Integration happens at the Vscan layer rather than by mounting a share.

    Storage Layer Scanning for OPSWAT MFT

    Scanning the storage layer of OPSWAT MFT for customers who run both products.

  • Enhanced File Tagging for Forensic Analysis and Tracking

    Tag files with processing details to support forensic analysis and tracking, enhancing your audit and compliance capabilities.

    Custom Scan Priority for Optimized Resource Allocation

    Adjust scanning priorities [High, Medium, Low] for storage unit scans. This flexibility enables users to tailor resource allocation based on specific security needs and time constraints.

    Cancel Scanning File for Enhanced Resource Control

    Stop processing individual files during active scans. This capability gives users greater control over resource allocation while preventing unnecessary processing of files that don't require scanning.

    Group Creation for Specialized Workflows 

    Organize storage units effectively with type-based grouping. Create dedicated groups for Object Storage and Network Attached Storage units to ensure security workflows perfectly match the specific features and requirements of each storage integration.

    Dual View Modes for More Clarity and Control

    Dual view system [Groups and Accounts] allows organizations to organize storage units through Groups and Accounts perspectives, accommodating different operational models and organizational structures.

    Cloud Bucket Autodiscovery

    Cloud Bucket Autodiscovery is available for AWS S3, SharePoint Online, Google Cloud Platform, and Azure Blob Storage. This new capability automatically detects and adds your cloud storage buckets to eliminate manual configuration errors, save administrative time, and simplify multi-cloud security management.

    Enhanced Integration Capabilities

    Include FTP support (along with SMB/NFS/SFTP), individual file webhooks, and secure syslog with TLS, enabling automated response procedures and secure audit data transmission to centralized log management systems.

  • Partition-Based Real-Time Scanning

    Configure multiple scanning policies across different partitions within individual storage units. This granular approach allows enterprises to implement risk-based security policies that align with business requirements and data sensitivity levels.

  • Efficient Rescanning of Large, Static Datasets

    Identity Scanning recognizes unchanged files and reuses previous scan results, significantly reducing scan time for large datasets. A configurable rescan interval ensures every file is periodically rescanned. Ideal for SMB/NFS backup repositories and available for on-demand and scheduled scans.

  • Automated File Remediations for Comprehensive File Management

    Customize remediation workflows by combining Deep CDR™ Technology, and actions like copy, encrypt, block, move, or delete files. An optional "Delete empty folders after remediation" setting is added for SMB/NFS/SFTP shares.

  • Customizable File Security Workflow

    Automated security pipeline with 5-stage processing (Scan Configuration → Advanced Threats → Vulnerabilities → Sanitization → File Tagging). Build custom, automated file processing pipelines tailored to your organization’s unique needs, all without additional API development.

  • SharePoint Historical Version Scanning

    Scan all historical versions of SharePoint files, preventing threat actors from exploiting file versioning mechanisms to bypass security controls or maintain persistent access through restored infected versions.

  • Multiple Workflow Destinations

    Remediation policies can specify up to five copy/move destinations, supporting complex data handling requirements common in regulated industries while ensuring business continuity through multiple backup locations.

  • Cross-Domain Transfer for Classified Environments

    Compliant data transfer across classification domains with isolated handling of untrusted content. Shipped in 4.5.0.

  • Native NetApp ONTAP Vscan Integration

    Native NetApp ONTAP Vscan integration, including AWS FSx for NetApp ONTAP, with multi-SVM support. Integration happens at the Vscan layer rather than by mounting a share.

  • Storage Layer Scanning for OPSWAT MFT

    Scanning the storage layer of OPSWAT MFT for customers who run both products.

  • Enhanced File Tagging for Forensic Analysis and Tracking

    Tag files with processing details to support forensic analysis and tracking, enhancing your audit and compliance capabilities.

  • Custom Scan Priority for Optimized Resource Allocation

    Adjust scanning priorities [High, Medium, Low] for storage unit scans. This flexibility enables users to tailor resource allocation based on specific security needs and time constraints.

  • Cancel Scanning File for Enhanced Resource Control

    Stop processing individual files during active scans. This capability gives users greater control over resource allocation while preventing unnecessary processing of files that don't require scanning.

  • Group Creation for Specialized Workflows 

    Organize storage units effectively with type-based grouping. Create dedicated groups for Object Storage and Network Attached Storage units to ensure security workflows perfectly match the specific features and requirements of each storage integration.

  • Dual View Modes for More Clarity and Control

    Dual view system [Groups and Accounts] allows organizations to organize storage units through Groups and Accounts perspectives, accommodating different operational models and organizational structures.

  • Cloud Bucket Autodiscovery

    Cloud Bucket Autodiscovery is available for AWS S3, SharePoint Online, Google Cloud Platform, and Azure Blob Storage. This new capability automatically detects and adds your cloud storage buckets to eliminate manual configuration errors, save administrative time, and simplify multi-cloud security management.

  • Enhanced Integration Capabilities

    Include FTP support (along with SMB/NFS/SFTP), individual file webhooks, and secure syslog with TLS, enabling automated response procedures and secure audit data transmission to centralized log management systems.

Deployment Flexibility: Choose the Right Model for Your Infrastructure

Integrate MetaDefender Storage Security with your existing IT infrastructure, whether on-premises, in microservices architectures, or through SaaS. Choose the deployment model that fits your needs for an enterprise data protection platform that adapts
to your environment.

On-Premises

Virtual machines on your own infrastructure, including fully air-gapped environments. You run MDSS, MetaDefender Core and the shared services (PostgreSQL, Redis, RabbitMQ). Scales by adding MDSS and Core instances. Suits regulated and classified environments where nothing leaves the network.

Hybrid

Deploy from AWS, Azure or Google Cloud marketplace images and hand the shared services to managed equivalents such as Amazon RDS, ElastiCache and Amazon MQ. Reduces operational overhead while keeping the deployment in your own cloud account. Containerised deployment on Kubernetes (EKS, AKS or GKE) adds automatic scaling that matches capacity to queue depth.

Cloud through MetaDefender Cloud

SaaS, no infrastructure to run, multi-tenant with tenant-level administration. The fastest route to protecting cloud storage such as SharePoint Online or S3 without standing anything up.

Trusted Globally to Defend What's Critical

ABOUT

HiBob is a global, cloud-native, human resources tech company with an application responsible for managing the entire employee lifecycle—onboarding, time and attendance, compensation, performance review, tasks, and offboarding.

USE CASE

HiBob established a hiring model called 'Bob Hiring,' allowing external candidates to submit applications via a portal. This raised concerns about file sanitization and data integrity. They needed a solution that integrated seamlessly with their AWS S3 cloud infrastructure. OPSWAT's MetaDefender Storage Security with Deep CDR™ Technology and Multiscanning technologies provided the necessary protection, significantly strengthening their defenses against malware and zero-day vulnerabilities.

ABOUT

A leading professional accounting organization operating across the APAC region with more than 50,000 employees, delivering audit, tax, advisory, and consulting services to public and private sector clients.

USE CASE

The organization relies on Microsoft SharePoint Online for daily collaboration, with employees uploading and sharing large volumes of documents, including sensitive financial records and client deliverables. This high level of file activity raised the risk of malware-infected or compromised files being downloaded, shared, or stored without automated inspection at the point of storage. The organization needed to verify that every file was safe without slowing collaboration or adding manual steps. OPSWAT's MetaDefender Storage Security Cloud provided automated, policy-driven protection integrated with SharePoint Online, using Metascan™ Multiscanning and Deep CDR™ Technology to detect threats and remove embedded malicious content.

ABOUT

A European aerospace manufacturer and global supplier of mission-critical satellite components and rocket structures, with more than 1,600 employees and a legacy spanning five decades of space missions. Its systems support satellite communications, Earth observation, weather forecasting, and planetary exploration.

USE CASE

During a critical data center migration, the manufacturer struggled to securely scan and transfer high volumes of sensitive files. Its existing script-based scanning approach lacked scalability and reliability, delaying operations and raising compliance concerns, while a strong preference for a Linux-based deployment added integration complexity. OPSWAT provided a tailored configuration of MetaDefender Storage Security on Linux, deploying two MetaDefender Storage Security instances and two MetaDefender Core engines to resolve integration issues, streamline scanning, and enable a secure, scalable migration.

ABOUT

A government defense agency in Southeast Asia focused on applying innovation and engineering expertise to enhance national security, working with industry leaders to integrate advanced technologies into mission-critical infrastructure.

USE CASE

The agency partnered with a technology contractor to build a classified data center, where strict security requirements, limited information sharing, and complex system integration made introducing new solutions difficult. OPSWAT implemented a phased deployment of MetaDefender Storage Security and MetaDefender Core instances, integrating a custom antivirus engine and embedded sandbox solutions for advanced threat analysis. This ensured incoming files were scanned and validated before entering the environment.

Support Your Compliance Requirements
with Confidence

MetaDefender Storage Security helps support a wide range of compliance efforts by scanning stored files for malware, sensitive data, and vulnerabilities, providing capabilities that can help address requirements associated with regulations such as HIPAA, GDPR
or PCI DSS.

Get Protected in Three Simple Steps

1

Connect with our Experts

1

Connect with our Experts

Have a short scoping conversation to map your storage estate and file volumes so the deployment is sized correctly from the start.

2

Integrate Seamlessly

2

Integrate Seamlessly

Connect your storage platforms, choose real-time, scheduled or on-demand scanning, and configure the workflow that decides what happens to a file based on its result.

3

Protect with Confidence

3

Protect with Confidence

Scanning runs continuously, files are handled according to the workflow you configured, and every outcome is recorded for audit and compliance reporting.

  • Connect with our Experts

    Have a short scoping conversation to map your storage estate and file volumes so the deployment is sized correctly from the start.

  • Integrate Seamlessly

    Connect your storage platforms, choose real-time, scheduled or on-demand scanning, and configure the workflow that decides what happens to a file based on its result.

  • Protect with Confidence

    Scanning runs continuously, files are handled according to the workflow you configured, and every outcome is recorded for audit and compliance reporting.

Flexible Integration Options for On-Premises and Cloud Storage 

Technical Documentation

Explore the full technical landscape of MetaDefender Storage Security — everything you need to understand, implement, and optimize.

Getting Started

Introduction
Plan architecture, deployment, system requirements, and licensing.
Installation
Deploy anywhere with step-by-step setup guidance.
Configuration and Management
Learn how to configure the product. Detailed information for each option.

Deployment & Usage

Integrations
Integration guides with other OPSWAT products and 3rd party products.
Operations
Detailed documentation on how to use the product.

Support

Knowledge Base
Answers to common questions about the product capabilities, and related articles on popular topics.
Troubleshooting Guide
How to investigate product issues.

Unlock the Full Potential of Our Products

Dive into OPSWAT Docs today for in-depth guides,troubleshooting tips, and valuable references.
OPSWAT Docs Logo

FAQs

MetaDefender Storage Security is an enterprise-grade file security platform that protects data at rest across on-premises, hybrid, and cloud storage environments. It applies multiple security technologies — including Metascan™ Multiscanning, Deep CDR™ Technology, Proactive DLP™, Vulnerability Assessment, and Adaptive Sandbox — to detect, remediate, and prevent threats in stored files.

Yes. MetaDefender Storage Security handles storage connectivity, file discovery, workflow and remediation, and MetaDefender Core performs the analysis. Every MetaDefender Storage Security package includes a MetaDefender Core engine package, so the scanning depth you need is sized and licensed together with the storage coverage. Core can be self-hosted, deployed from a cloud marketplace image, or consumed as MetaDefender Cloud.

It integrates with more than 25 storage platforms, including AWS S3, Microsoft Azure Blob Storage, Google Cloud, Alibaba Cloud, NetApp ONTAP, Dell EMC Isilon, SharePoint Online, OneDrive, Box, Wasabi, MinIO, and any SMB/NFS/SFTP or S3-compatible storage.

Deep CDR™ Technology processes files by removing potentially harmful content — such as embedded scripts and macros — from over 200 file types, then regenerates a clean, fully functional copy. This approach eliminates threats that evade signature-based detection without blocking the file from use.

Yes. MetaDefender Storage Security can help support your compliance efforts by scanning stored files for sensitive data and generating detailed reports that can be used as part of your audit and compliance documentation, relevant to frameworks such as HIPAA, GDPR, and PCI DSS.

MetaDefender Storage Security can be deployed as Virtual Machines for on-premises and hybrid environments, via Kubernetes (supporting EKS, AKS, and GKE), or as an IaaS/SaaS cloud-native solution requiring no dedicated hardware.

Protect Your Storage from Cyber Threats

Fill out the form and we’ll be in touch within 1 business day.
Trusted by 2,100+ businesses worldwide.