Onam Security
Technology Engine

What technology is actually running in my cloud?

Shadow IT and forgotten services are everywhere. Let's find yours.

The technology engine discovers the actual runtime stack across your fleet — databases, operating systems, web servers, container runtimes, network appliances and SaaS platforms — and holds each one to the CIS benchmark written for that specific product, not to a generic cloud rule.

10,000+
security rules
7
cloud providers
< 5 min
to first finding
100%
agentless
Why this matters

The CMDB says you run PostgreSQL and Nginx.

Reality: three teams run Redis 4 that hit EOL in 2020, one team pinned Node 12 in a legacy Lambda, and a forgotten instance is running an outdated Elasticsearch open on port 9200. Every one of those has known exploits, and none of them are in your asset inventory.

The risk of not knowing

If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.

Real-time detection, not periodic audits
How does it actually work?

The mechanism, not the marketing

  1. 1

    Onam probes running workloads through cloud metadata, container image inspection, and process metadata — read-only, no agents.

  2. 2

    The engine identifies the technology running on each workload and evaluates it against the CIS benchmark for that specific product — 34 of them, from PostgreSQL and Nginx to RHEL, Docker, Cisco IOS XE and VMware ESXi.

  3. 3

    Each detected technology is checked against version-specific security rules covering defaults, hardening, and end-of-life status.

  4. 4

    Findings are joined to the identity, network, and vulnerability graph so an EOL database that is internet-reachable ranks appropriately.

  5. 5

    New technologies and versions are added continuously as they appear in customer environments — so shadow IT is discovered without a rule-writing sprint.

What do you actually get?

Specific outputs, measurable outcomes

Runtime technology inventory
what's actually running, not what was deployed
Version currency analysis
End-of-life detection
Default configuration checks (databases, web servers, frameworks)
34 CIS technology benchmarks
named products, not vague categories
8,991 technology control rows across those benchmarks
Shadow IT surface area
Technology risk scoring
See it live

Technology Engine in the real console.

Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.

Add Cloud Account
Docs
AWS · Production
Read-only • No agents
1
Create read-only IAM role
2
Paste Role ARN
3
Validated — scanning…
onam · console
$aws cloudformation create-stack --stack-name onam --template-url ...
Connect your first cloud account
Read-only IAM role — validated and scanning in under 3 minutes
Clip length
9s
Data
Demo account
FAQ

Questions we get a lot

CSPM checks cloud-provider configuration — is a bucket public, is an RDS encrypted. Technology Engine goes one layer deeper: given that you run PostgreSQL 12 on that instance, is the version supported, are the defaults hardened, and does it end-of-life next quarter. Together they cover both the cloud and what runs on top of it.
Ready to see it live

Ready to see Technology Engine in your cloud?

Connect a read-only role in three minutes. Your first findings surface in under five.