Ketch and Amazon DynamoDB

Discover which DynamoDB tables hold personal data, with the choice to scope access to an entire region or lock it down to specific tables only.

Amazon Dynamodb

About Amazon DynamoDB

DynamoDB's key-value and document structure means personal data can live in tables with inconsistent schemas across an application, and different organizations reasonably want different levels of access for a discovery tool: some prefer full visibility across a region, others want to name specific tables explicitly and nothing more.

Ketch connects to DynamoDB through a Ketch Transponder with both options supported.

Capabilities

How Ketch works with Amazon DynamoDB

Discovery

Automatically finding tables and attributes within a region. The connected IAM policy can be scoped two ways. For full-region discovery, the policy grants `ListTables`, `Scan`, `GetItem`, and `DescribeEndpoints` across all tables (`Resource: "*"`). For discovery limited to specific tables, the same core actions apply but scoped to explicit table ARNs, without the `ListTables` action, so the Transponder only ever touches the named tables.

With Ketch, teams can

  • Choose full-region discovery or restrict Ketch's access to a named list of specific tables, matching an organization's own security posture
  • Discover personal data across DynamoDB tables using a minimal, explicit IAM policy either way
  • Connect through a Ketch Transponder rather than exposing DynamoDB to broader access than necessary

The gap

The problem this integration solves

A key-value database with per-table, often inconsistent schemas creates real discovery challenges, and organizations reasonably differ on how broad a discovery tool's access should be:

01. Table names alone don't reliably indicate whether a table holds personal data, especially across tables built by different teams over time

02. A one-size-fits-all IAM policy either grants more access than some security teams want, or requires manual re-scoping for organizations that want table-level control

03. Manually reviewing DynamoDB tables for personal data doesn't scale across a real production environment

Ketch resolves this by offering both a full-region and a table-scoped IAM policy, so the access granted matches what an organization is actually comfortable with.

Why Ketch

Why teams choose Ketch for Amazon DynamoDB privacy compliance

Permissioning infrastructure that governs Amazon DynamoDB the same way it governs every other system in your stack — not a one-off connector bolted onto a banner.

  • Scoping that matches your security posture

    Full-region or table-specific access, both documented and supported, rather than a single fixed policy.

  • Minimal, explicit IAM actions either way

    No broader permissions than `ListTables`, `Scan`, `GetItem`, and `DescribeEndpoints` require.

  • Backed by enforcement precedent

    Regulators increasingly expect businesses to prove technical enforcement, not just describe it on paper, the same underlying expectation that applies to knowing what personal data a database holds.

Questions about the Amazon DynamoDB integration

Integrations

Pre-built APIs with 1,000+ systems, apps, and models

Ketch ships connectors and SDKs so consent, rights, and policy flow into your CDPs, warehouses, ad platforms, and AI stack — without a custom data pipeline.

Browse All Integrations

See Amazon DynamoDB permissioning running end to end

Book a demo to walk through rights, consent, and preference orchestration on your stack — or start free and connect Amazon DynamoDB yourself.

Get Started Free

Get started in less than 5 min