Solutions · Amazon Web Services

Stop AWS Misconfigurations Before Attackers Find Them First

AWS's breadth — 200+ services across global regions — creates a sprawling attack surface that traditional tools cannot keep pace with. Onam continuously monitors every IAM policy, S3 bucket, security group, and Lambda configuration across all your AWS accounts with 800+ purpose-built rules.

800+
AWS security rules
40+
AWS services monitored
< 5 min
to first finding
100%
agentless, read-only
Coverage

Services we monitor on AWS

Every service below is scanned continuously — no agents, no network changes, read-only.

IAM Users, Roles & Policies
S3 Buckets & Object ACLs
EC2 & Security Groups
RDS & Aurora
Lambda
CloudTrail & CloudWatch
KMS & Encryption
EKS Clusters
VPC Flow Logs & NACLs
Elastic Load Balancers
SNS / SQS
Secrets Manager & Parameter Store
GuardDuty & Security Hub
Route 53 & CloudFront

Plus: CloudFormation, CodeBuild, CodePipeline, SageMaker, Bedrock, Elastic Beanstalk, Inspector, Macie, and more.

Compliance

Compliance frameworks

Onam maps every AWS finding to the frameworks your auditors care about.

CIS AWS Foundations BenchmarkNIST CSF 2.0PCI-DSS v4.0SOC 2 Type IIFedRAMP Moderate
Onboarding

Connect in 3 steps

From consent to first finding in under five minutes.

1

Create a read-only IAM role

Use our CloudFormation template — one click, read-only, no destructive permissions. The role trusts Onam's AWS account with an external ID unique to your tenant.

2

Paste the Role ARN into Onam

Multi-account organizations connect in a single step via AWS Organizations: deploy a StackSet from the management account and every member account is onboarded automatically.

3

First findings in under 5 minutes

Onam assumes the role via STS and scans all in-scope regions. Findings arrive prioritized, mapped to CIS/NIST/PCI, and ready to route to your ticketing system.

See it live

AWS in the real console.

Not a mockup — the actual Onam console on a live demo account: connect, inventory and posture in one view.

Add Cloud Account
Docs
AWS · Production
Read-only • No agents
1
Create read-only IAM role
2
Paste Role ARN
3
Validated — scanning…
onam · console
$aws cloudformation create-stack --stack-name onam --template-url ...
Connect your first cloud account
Read-only IAM role — validated and scanning in under 3 minutes
Clip length
9s
Data
Demo account
Differentiators

What makes Onam different on AWS

Organizations-aware multi-account scanning

Onboard the AWS Organization once and every member account — current and future — is scanned automatically. SCPs, delegated admins, and OU structure are respected as first-class data.

IAM effective-permission graph

Onam resolves Service Control Policies, permission boundaries, identity policies, and resource policies into a single effective-access graph. See what a principal can actually do — not just what a policy says.

S3 public-exposure chain analysis

Every bucket is evaluated end-to-end: bucket policy, ACL, Block Public Access settings, and CloudFront origin. If any hop makes it reachable from the internet, Onam flags the full chain — not just the bucket.

FAQ

Questions we get a lot

Read-only. The managed SecurityAudit and ReadOnlyAccess policies attached to a role that trusts Onam's AWS account with a per-tenant external ID. No write, no destructive, no data-plane access to your S3 objects or database contents.

Ready to secure your AWS environment?

Connect a read-only role in three minutes. Your first findings surface in under five.