Ketch and Amazon DocumentDB

Discover and fulfill rights requests against a database that never has to leave your own network to be reached.

Amazon Documentdb

About Amazon DocumentDB

Amazon DocumentDB runs inside a VPC by design, which means any tool that wants to query it either needs inbound network access opened up to it, or needs to already be running somewhere inside that network boundary. Ketch takes the second approach: a Ketch Transponder, deployed inside the same VPC (or a peered one) as the DocumentDB cluster, does the connecting locally, so nothing about the database's network isolation has to change to make discovery and rights fulfillment possible.

Capabilities

How Ketch works with Amazon DocumentDB

The Ketch Amazon DocumentDB integration covers three capabilities: Discovery, and Rights Orchestration for both Right to Access and Right to Delete.All of this runs through a Ketch Transponder, deployed inside your own VPC using a service account with MongoDB-compatible permissions (read access for Discovery, extended to update and delete access if

Discovery

Automatically finds databases, collections, and fields by sampling collection data to infer schema, since DocumentDB's document structure doesn't have a fixed schema to read directly.

Rights Orchestration

Retrieves personal data from collections to fulfill access requests, and can delete or update personal data directly to fulfill erasure requests. Is authorized). Because DocumentDB is only reachable from within a VPC, the Transponder has to live inside that same network boundary, or a peered one, to connect at all.

With Ketch, teams can

  • Discover personal data across DocumentDB collections without opening the database up to inbound access from outside the VPC
  • Fulfill access and deletion requests directly against DocumentDB collections, verified through a test workflow run
  • Keep the database's existing network isolation completely unchanged, since the Transponder does the connecting from inside the boundary that already exists

The gap

The problem this integration solves

A VPC-isolated database is deliberately hard to reach from outside, and a privacy tool that requires opening that up creates a real security tradeoff:

01. Exposing a DocumentDB cluster to inbound connections from outside the VPC, just to enable a privacy tool, works against the network isolation that VPC deployment is meant to provide in the first place

02. Manually locating and updating or deleting a specific person's data across DocumentDB collections doesn't scale to real request volume

03. Sampling-based schema inference is necessary for a document database with no fixed schema, but needs an approach built for that, not a relational assumption

Ketch resolves the network exposure problem by deploying inside the VPC rather than reaching in from outside, and resolves the schema problem with discovery built around sampling rather than a fixed schema definition.

Why Ketch

Why teams choose Ketch for Amazon DocumentDB privacy compliance

Permissioning infrastructure that governs Amazon DocumentDB the same way it governs every other system in your stack — not a one-off connector bolted onto a banner.

  • Never has to leave your network boundary

    The Transponder runs inside your own VPC, so DocumentDB's existing network isolation doesn't need to change to support discovery or rights fulfillment.

  • Full rights fulfillment, not just discovery

    Both Right to Access and Right to Delete are supported directly against DocumentDB collections, not just a data inventory.

  • Backed by enforcement precedent

    Regulators increasingly expect businesses to prove technical enforcement, not just describe it on paper, the same underlying expectation that applies to knowing what personal data a database holds and being able to act on it.

Questions about the Amazon DocumentDB integration

Integrations

Pre-built APIs with 1,000+ systems, apps, and models

Ketch ships connectors and SDKs so consent, rights, and policy flow into your CDPs, warehouses, ad platforms, and AI stack — without a custom data pipeline.

Browse All Integrations

See Amazon DocumentDB permissioning running end to end

Book a demo to walk through rights, consent, and preference orchestration on your stack — or start free and connect Amazon DocumentDB yourself.

Get Started Free

Get started in less than 5 min