All Products
Search
Document Center

Data Security Center:Purchase Data Security Center

Last Updated:Aug 28, 2026

Data Security Center (DSC) supports end-to-end management of sensitive data, from discovery and detection to governance and auditing. This topic describes how to purchase a subscription instance of a paid DSC edition.

Before you begin

Before you purchase Data Security Center (DSC), take note of the following information:

  • Limits — Limits apply to some regions and some types of data assets. For more information, see Supported regions.

  • Free trial — DSC provides a Free Edition. To try out or evaluate the features before you purchase a paid edition, activate the Free Edition or the .

Compare paid editions

The following table compares the target scenarios and the base-price specifications of the paid DSC editions. Start from the base-price specifications: check whether the included quotas cover the scale of the data assets that you want to protect, whether you need Data Detection and Response, and whether you must meet MLPS compliance requirements. For a detailed edition comparison and billing information, see Edition comparison and Billing.

Item

Advanced Edition

Enterprise Edition

Value-added Plan

Database Auditing (MLPS-compliant Edition)

Scenarios

Designed for small customers. Provides basic security protection and supports only small-scale data identification and data auditing.

Designed for small and medium-sized enterprises that must meet data security and compliance requirements.

Lets you purchase individual value-added service capabilities on demand. Suitable for customized purchasing requirements in large-scale business scenarios.

Designed for MLPS compliance requirements. Replaces the legacy database auditing edition and supports data auditing for multiple data types, including databases, Object Storage Service (OSS), and big data.

Features included in the base price

Data Identification: 1 TB of storage for identification, 10,000 database tables; Data Auditing: 1 TB of storage, 1 database instance; Column Encryption: 1 column; Log Storage Capacity: 250 GB

Data Identification: 3 TB of storage for identification, 30,000 database tables; Data Auditing: 3 TB of storage, 3 database instances; Data Detection and Response: 3 TB of storage, 3 database instances; Image Masking: 10,000 images; Column Encryption: 10 columns; Log Storage Capacity: 1,500 GB

Not included

Data Auditing: 1 TB of storage, 3 database instances; Log Storage Capacity: 650 GB

Additional paid feature extensions

All features can be enabled or have their quotas extended for an additional fee.

See the parameter table for this edition in Feature extension parameters.

See the parameter table for this edition in Feature extension parameters.

See the parameter table for this edition in Feature extension parameters.

Quota rules and limits

The following rules determine how quickly your DSC quotas are consumed and which inputs are excluded from detection. Review them before you decide which quotas to purchase.

  • Repeated scans consume quota per scan — If the same data asset is scanned multiple times, the consumed Data Identification quota is calculated based on the actual number of scans. For example, if a single table is scanned three times, the quota for three database tables is deducted.

  • Repeated masking consumes quota per operation — A single image may be masked multiple times and consume multiple Image Masking quota units.

  • Column Encryption depends on Data Identification — Column Encryption relies on the sensitive data identification capability of Data Identification. Purchase a sufficient Data Identification quota.

  • Default log storage — DSC includes 200 GB of log storage for each authorized database instance and 50 GB for every 1 TB of authorized OSS protection. If the default storage is insufficient, extend the Log Storage Capacity quota when you place your order.

Warning

Reserve enough log storage space. When the log storage space is exhausted, new logs for the asset are no longer stored, which results in log loss.

Feature extension parameters

The following tables describe the parameters that you can configure on the buy page to enable additional features or to extend quotas beyond the base specifications of an edition. Use the table for the edition that you want to purchase.

Advanced Edition or Enterprise Edition

Parameter

Description

Data Detection and Response

Enables Data Detection and Response to discover and handle security events such as leaks of database credentials and AccessKey pairs. You can then specify Data Detection and Response - OSS Protection Capacity and Data Detection and Response - Number of Database Instances to extend the protection quota.

Data Auditing

Enables Data Auditing to collect logs and generate alerts for attacks and anomalous operations. You can then specify Data Auditing - OSS Protection Capacity and Data Auditing - Number of Database Instances to extend the audit quota.

Data Identification

Enables Data Identification to identify sensitive data and classify and grade it. You can then specify Data Identification - Database Table Quantity and Data Identification - Storage Identification Capacity to extend the identification quota.

Image Masking

Enables Image Masking. You can then specify Image Masking Count to extend the quota.

Column Encryption

Enables Column Encryption to encrypt sensitive information columns in databases. You can then specify Columns (unit: columns) to extend the quota.

Log Storage Capacity

If the default log storage is insufficient, enable this option and select Log Storage Capacity to extend the quota.

Value-added Plan

Parameter

Description

Data Detection and Response

Enables Data Detection and Response to discover and handle security events such as leaks of database credentials and AccessKey pairs. You can then specify the Data Detection and Response - OSS Protection Capacity and Data Detection and Response - Number of Database Instances protection quotas.

Data Auditing

Enables Data Auditing to collect logs and generate alerts for attacks and anomalous operations. You can then specify the Data Auditing - OSS Protection Capacity and Data Auditing - Number of Database Instances audit quotas.

Data Identification

Enables Data Identification to identify sensitive data and classify and grade it. You can then specify the Data Identification - Database Table Quantity and Data Identification - Storage Identification Capacity quotas.

Image Masking

Enables Image Masking. You can then specify the Image Masking Count quota.

Column Encryption

Enables Column Encryption to encrypt sensitive information columns in databases. You can then specify the Columns (unit: columns) quota.

Log Storage Capacity

If the default log storage is insufficient, enable this option and select Log Storage Capacity to extend the quota.

Database Auditing (MLPS-compliant Edition)

Parameter

Description

Data Auditing

Enables Data Auditing to collect logs and generate alerts for attacks and anomalous operations. You can then specify Data Auditing - OSS Protection Capacity and Data Auditing - Number of Database Instances to extend the audit quota.

Log Storage Capacity

If the default log storage is insufficient, enable this option and select Log Storage Capacity to extend the quota.

Purchase a paid edition

  1. Go to the DSC buy page.

  2. In the version section, select the edition that you want to purchase, and then specify Duration for the subscription. Renew the instance before it expires to avoid business impact. (Recommended) Select . After you enable this option, the system automatically renews the DSC instance on the day it expires.

    (Optional) To extend features beyond the specifications of the edition, configure the extension parameters for the edition that you selected. For parameter descriptions, see Feature extension parameters. If the base specifications meet your requirements, skip the extension parameters.

  3. Click Buy Now and complete the payment.

Next steps

After you purchase DSC, get started with the following steps:

  1. Authorize your assets in Asset Center. For instructions, see Asset Center (New).

  2. Configure the following features based on your business scenarios:

    • Classification and Grading (Recommended): Identifies sensitive information and grades it.

    • Configuration Risk (Recommended): Identifies configuration risks on the Alibaba Cloud platform.

    • Column Encryption: Encrypts sensitive information columns in databases. Unauthorized personnel can read only the ciphertext.

    • Image Masking: Masks sensitive information in images in OSS buckets.

    • Data Detection and Response: Discovers and handles security events such as leaks of database credentials and AccessKey pairs.

    • Data Auditing: Enables cloud-native log collection and generates alerts for attacks and anomalous operations.