Solutions · Alibaba Cloud

Unified Security Posture for Your Alibaba Cloud Workloads, Region by Region

Alibaba Cloud's rapid regional expansion introduces security blind spots that Western-centric CSPM tools routinely miss. Onam brings the same continuous, rule-driven coverage to AliCloud — RAM policies, OSS buckets, RDS instances, and VPC configurations — that your AWS and Azure environments already have.

180+
AliCloud security rules
20+
AliCloud services monitored
All regions
China & international
100%
agentless deployment
Coverage

Services we monitor on Alibaba Cloud

Every service below is scanned continuously — no agents, no network changes, read-only.

RAM Users, Roles & Policies
OSS Buckets & ACLs
ECS Instances & Security Groups
RDS (MySQL / PostgreSQL / SQL Server)
VPC & VSwitch
ACK Kubernetes Clusters
KMS & Encryption
ActionTrail Audit
Server Load Balancer
PolarDB
Function Compute
Log Service (SLS)

Plus: MaxCompute, DataWorks, MSE, API Gateway, Container Registry, Anti-DDoS, and more.

Compliance

Compliance frameworks

Onam maps every Alibaba Cloud finding to the frameworks your auditors care about.

CIS-style Alibaba Cloud BenchmarkMLPS 2.0 (China Cybersecurity Classified Protection)ISO 27001:2022SOC 2 Type II
Onboarding

Connect in 3 steps

From consent to first finding in under five minutes.

1

Create a RAM role for Onam

Provision a read-only RAM role with the AliyunReadOnlyAccess and AliyunActionTrailReadOnlyAccess system policies. Trust policy pins Onam's account with a per-tenant external ID.

2

Paste the Role ARN into Onam

Multi-account Resource Directory customers connect once at the master account — every member account is discovered and onboarded automatically.

3

First findings in under 5 minutes

Onam assumes the RAM role across every enabled region — including China and international — and returns prioritized findings mapped to your frameworks.

See it live

Alibaba Cloud in the real console.

Not a mockup — the actual Onam console on a live demo account: connect, inventory and posture in one view.

Add Cloud Account
Docs
AWS · Production
Read-only • No agents
1
Create read-only IAM role
2
Paste Role ARN
3
Validated — scanning…
onam · console
$aws cloudformation create-stack --stack-name onam --template-url ...
Connect your first cloud account
Read-only IAM role — validated and scanning in under 3 minutes
Clip length
9s
Data
Demo account
Differentiators

What makes Onam different on Alibaba Cloud

China-region coverage without compromise

Onam operates in AliCloud's China regions with the same depth as international regions — including MLPS-relevant controls — while keeping your data plane inside your tenancy.

RAM effective-permission analysis

System policies, custom policies, and permission boundaries are combined into a single effective-access graph — so a user assumed to be scoped is proven, not trusted.

OSS + VPC exposure chain

OSS bucket ACLs, bucket policies, Block Public Access, and the CDN in front of them are evaluated together so any internet-reachable path is surfaced end to end.

FAQ

Questions we get a lot

Read-only. The AliyunReadOnlyAccess and AliyunActionTrailReadOnlyAccess system policies attached to a role that trusts Onam with a per-tenant external ID.

Ready to secure your Alibaba Cloud environment?

Connect a read-only role in three minutes. Your first findings surface in under five.