Skip to content

Extending Least-Privilege AI Data Retrieval and Exposure to AWS and Microsoft customers

 

Executive Summary

ShardSecure is pleased to announce that the MCP Secure Gateway now includes native support for AWS S3 and Microsoft SharePoint.

This release fulfills a key item from our earlier roadmap and significantly broadens the range of enterprise data sources that AI agents and models can securely query at inference time. Organizations can now apply identity-aware data redaction and least-privilege data fragment retrieval directly against two of the most widely used repositories of unstructured data—without exposing raw objects, full documents, or sensitive content to users or AI systems.

The gateway continues to operate as a policy-driven data control layer compliant with the Model Context Protocol (MCP). It sits between authenticated users/agents and protected data stores, enforcing granular authorization and injecting only the minimum authorized data into the model context.


Why This Matters

Enterprise AI adoption is accelerating, yet most organizations still struggle with a fundamental tension: models need rich, relevant context to produce accurate results, while security and compliance teams cannot accept broad data exposure.

AWS S3 and Microsoft SharePoint hold vast volumes of unstructured content—contracts, reports, emails, presentations, images, and more. Traditional approaches force a choice between:

  • Manual file selection and upload (slow, error-prone, and incomplete)
  • Broad connector access that risks over-exposure of PII, PHI, or proprietary information
  • Heavy anonymization that degrades model performance

With the new integrations, the ShardSecure MCP Secure Gateway resolves this tension for S3 buckets and SharePoint sites/libraries.

How the New Integrations Work

An authenticated user or AI agent issues a natural-language prompt containing keywords, identifiers, or references. The AI queries the ShardSecure gateway via MCP. The gateway:

  1. Validates identity and applies authorization policies (via integrated or external IdPs such as Auth0, Okta, Ping Identity, Keycloak, ForgeRock, or the built-in IdP).
  2. Queries rich object-level metadata associated with objects in AWS S3 or Microsoft SharePoint.
  3. Retrieves and injects only the minimal authorized data fragments.
  4. Optionally applies dynamic, identity-aware redaction or masking.
  5. Returns the enriched, least-privilege context to the model—never the raw store or full documents.

Raw data remains protected in its original storage location (AWS S3 or Microsoft SharePoint). Neither the AI model nor the end user gains direct access to the underlying S3 objects or SharePoint files.

Key Benefits of the Expansion

  • Broader enterprise coverage — Securely leverage two of the most common repositories of business-critical unstructured data.
  • Consistent least-privilege data enforcement — The same identity-aware policies and fragment-level controls now apply across on-premises, hybrid, and cloud object storage as well as collaboration platforms.
  • Improved AI accuracy with lower risk — Models receive higher-quality, relevant context while data exposure is minimized.
  • Operational simplicity — No change to existing AI agent workflows or user experience; the gateway handles policy evaluation and selective retrieval transparently.
  • Deployment flexibility — Continues to be available as Docker containers or OVA virtual appliances for on-premises or cloud environments.

Looking Ahead

Support for Azure Blob Storage and Google Cloud Storage remains on the roadmap, along with deeper DLP/DSPM integration and policy-driven remediation. The addition of AWS S3 and Microsoft SharePoint represents a major step in making secure, production-grade AI context enrichment practical for the majority of enterprise data estates.

Get Started

ShardSecure MCP Secure Gateway with ShardSecure Storage, AWS S3 and Microsoft SharePoint support is available for no-cost evaluation by enterprise customers and partners. Contact your ShardSecure representative, visit shardsecure.com, or email info@shardsecure.com to schedule a demo or begin a proof of concept.


Secure by design. Least privilege by default. Ready for AI.

For more information on the original MCP Secure Gateway announcement and architecture, see the previous post: ShardSecure MCP Secure Gateway – Identity-Aware Data Redaction and Least-Privilege Context Enrichment for AI Inference.