# Fivetran and Amazon S3 Data Sharing

If using the Client’s AWS S3:

1. Client controls data security.
2. Client creates a role for CloudFactory’s Fivetran to access their AWS S3 bucket.&#x20;

<figure><img src="https://3598919924-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FeIDXlxW9gckrh95snvSB%2Fuploads%2FmBfW27zg5QFDIOMiaHCO%2Fimage.png?alt=media&#x26;token=993a6445-4a9b-4ea7-8444-5893f836c05f" alt=""><figcaption></figcaption></figure>

#### Note <a href="#h_01hxshzb0zvdj5jq6ahmx4cm1d" id="h_01hxshzb0zvdj5jq6ahmx4cm1d"></a>

Follow this setup guide to connect your AWS S3 bucket to Fivetran: [Fivetran S3 Setup Guide](https://fivetran.com/docs/files/aws-s3/setup-guide)

If using CloudFactory’s AWS S3:

1. CloudFactory controls data security.
2. Client sends data to CloudFactory’s AWS S3.&#x20;

<figure><img src="https://3598919924-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FeIDXlxW9gckrh95snvSB%2Fuploads%2FinsrZIPkvze1fbqV3rVT%2Fimage.png?alt=media&#x26;token=d5c902cf-640d-4228-86f9-c4e53194eacb" alt=""><figcaption></figcaption></figure>

#### Overview <a href="#uuid-990d1325-03a8-510f-004b-36e3b218b367_bridgehead-idm4665466328745633174867603492" id="uuid-990d1325-03a8-510f-004b-36e3b218b367_bridgehead-idm4665466328745633174867603492"></a>

1. Create an AWS policy with access to the correct S3 location.
2. Create an AWS role:
   1. Reference the AWS account number and external id (provided by CloudFactory).
   2. Attach the new policy from step 1.
3. Provide the resulting role ARN back to CloudFactory.
4. Provide any file naming conventions to CloudFactory.
