Overview
This Privacy Policy explains how Onam Security ("Onam", "we", "us") collects, uses, and protects data when you visit our website, sign up for an account, or connect a cloud environment to the Onam platform. This page is maintained by Onam Security and is not an independent certification.
What data we collect
We collect three categories of data:
- Account data. Name, work email, company, and role you provide when creating an account or requesting a demo.
- Cloud configuration metadata. Onam reads configuration metadata from the cloud accounts you connect — for example, IAM policy documents, resource tags, security-group rules, and encryption settings. Onam does not read data-plane content (the objects inside your S3 buckets, the rows in your databases, or the payloads in your queues).
- Product usage data. Basic telemetry about how the Onam UI is used — page views, feature interactions, error events — used to improve the product.
How we use it
We use the data above to operate the Onam platform, deliver findings and reports to you, provide support, improve product quality, and communicate about your account. We do not sell your data. We do not use your cloud configuration data to train shared machine-learning models across customers.
Cloud connection data
When you connect a cloud account to Onam, we store the identifiers required to authenticate to that account — for example, role ARNs, service-principal IDs, and workload-identity federation trust configurations. We do not store static access keys, secret access keys, or long-lived passwords.
Every call Onam makes to your cloud is authenticated with a short-lived, tenant-scoped token and uses read-only permissions. Nothing Onam does can modify or delete resources in your environment.
Sub-processors
Onam uses a small number of sub-processors to operate the service. Current sub-processors include cloud infrastructure providers, email delivery, and identity providers used to sign in to Onam. A current list is available on request from privacy@onam.security.
Data retention
Findings and configuration snapshots are retained per the plan you're on — 30 days on Free, 1 year on Pro, and custom retention on Enterprise. Account data is retained while your account is active and deleted or anonymised within 90 days of account closure, subject to legal-hold obligations.
Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, port, or restrict processing of your personal data. To exercise any of these rights, email privacy@onam.security. We will respond within the timelines required by applicable law.
Security
We implement administrative, technical, and physical safeguards designed to protect the data we hold. See our Security page for details on encryption, access, and vulnerability disclosure.
Changes to this policy
We may update this policy from time to time. Material changes will be posted here and, where appropriate, communicated by email.
Contact
Questions about this policy or your data can be sent to privacy@onam.security.