Skip to main content
compliance · aws

SageMaker real-time endpoints that capture no inference requests or responses

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags an Amazon SageMaker endpoint whose `DataCaptureConfig` is explicitly disabled, so none of its inference inputs or outputs are written to S3. Without captured traffic there is nothing to audit a prediction against and nothing for drift monitoring to compare. The check stays silent when the setting is unknown, and the finding has a $0 saving.

Signal and threshold

How ZopNight evaluates SageMaker real-time endpoints that capture no inference requests or responses.
Field Value
Rule IDsRC-1622
Categorycompliance
Severitymedium
Metricnone — pure configuration read
ThresholdEnableCapture = false
SourceZopNight
Permissions usedsagemaker:ListEndpoints · sagemaker:DescribeEndpoint

What a model endpoint forgets without data capture

A SageMaker real-time endpoint returns a prediction and moves on. Unless data capture is turned on in the endpoint configuration, the request payload and the model’s answer are not kept anywhere you control. That matters in three situations: when a customer disputes a decision the model made, when a regulator asks how a model behaved on a given day, and when accuracy degrades slowly because live traffic no longer looks like the training data.

Captured records land in an S3 prefix you choose. SageMaker Model Monitor can read them to compare live traffic with a baseline, although AWS states Model Monitor is no longer open to new customers and will get no new features; the captured data is useful to any analysis tool either way.

Checking an endpoint’s capture setting

Terminal window
aws sagemaker list-endpoints --query 'Endpoints[].EndpointName' --output text
aws sagemaker describe-endpoint --endpoint-name my-endpoint \
--query 'DataCaptureConfig'

The block reports EnableCapture, a CaptureStatus of Started or Stopped, the current sampling percentage and the S3 destination. An empty result or "EnableCapture": false means nothing is recorded.

The evidence behind a finding

ZopNight records the data capture setting for each endpoint it discovers and flags an InService endpoint only when that setting is confirmed off. This is purely a configuration check; it does not look at traffic volume or metrics.

Endpoints left out

If the setting could not be read or parsed, the endpoint is not flagged, and endpoints in any status other than InService are not evaluated. The rule does not judge the sampling percentage either, so an endpoint capturing 1% of requests passes. AWS also notes that data capture pauses on its own when disk usage on the instance runs high, which this configuration check cannot see.

Cost and value of turning capture on

The finding reports $0. Capture itself adds S3 storage and request charges for the objects it writes, which scale with sampling rate and payload size. A modest sampling percentage and an S3 lifecycle rule usually keep that small.

Enabling capture on a live endpoint

Endpoint configurations cannot be edited, so the change is a new configuration plus an update:

  1. Create a configuration that copies the current production variants and adds capture:
Terminal window
aws sagemaker create-endpoint-config --endpoint-config-name my-endpoint-cfg-v2 \
--production-variants file://variants.json \
--data-capture-config '{"EnableCapture":true,"InitialSamplingPercentage":20,"DestinationS3Uri":"s3://my-capture-bucket/my-endpoint","CaptureOptions":[{"CaptureMode":"Input"},{"CaptureMode":"Output"}]}'
  1. Switch the endpoint to it with aws sagemaker update-endpoint --endpoint-name my-endpoint --endpoint-config-name my-endpoint-cfg-v2.
  2. Encrypt and restrict the capture bucket, since it now holds real inference payloads.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·