Solutions · Google Cloud Platform

Secure GCP Projects at Scale Without Slowing Down Engineering

GCP gives engineering teams enormous flexibility and security teams enormous blind spots. Onam continuously audits every project from IAM bindings and BigQuery permissions to GKE configs and VPC firewall rules.

300+
GCP security rules
30+
GCP services monitored
Org-wide
folder & project traversal
100%
agentless deployment
Coverage

Services we monitor on Google Cloud

Every service below is scanned continuously — no agents, no network changes, read-only.

IAM & Service Accounts
Organization, Folders & Projects
Compute Engine & Firewall
Cloud Storage Buckets
BigQuery Datasets & Tables
GKE Clusters
Cloud SQL & Spanner
Cloud KMS
VPC & Cloud NAT
Cloud Run & Cloud Functions
Secret Manager
Security Command Center

Plus: Pub/Sub, Cloud Build, Artifact Registry, Dataflow, Vertex AI, Cloud DNS, Load Balancing, and more.

Compliance

Compliance frameworks

Onam maps every Google Cloud finding to the frameworks your auditors care about.

CIS GCP Foundation BenchmarkNIST CSF 2.0ISO 27001:2022SOC 2 Type II
Onboarding

Connect in 3 steps

From consent to first finding in under five minutes.

1

Create an Onam service account

Provision a service account at the organization level with the Security Reviewer and Viewer roles. Terraform module included; runs in under a minute.

2

Grant org-level read access

One binding at the organization node inherits down through every folder and project. New projects — created by any engineer, at any time — are covered automatically.

3

First findings in under 5 minutes

Onam authenticates via workload identity federation, walks the resource hierarchy, and returns findings mapped to CIS GCP and your internal frameworks.

See it live

Google Cloud in the real console.

Not a mockup — the actual Onam console on a live demo account: connect, inventory and posture in one view.

Add Cloud Account
Docs
AWS · Production
Read-only • No agents
1
Create read-only IAM role
2
Paste Role ARN
3
Validated — scanning…
onam · console
$aws cloudformation create-stack --stack-name onam --template-url ...
Connect your first cloud account
Read-only IAM role — validated and scanning in under 3 minutes
Clip length
9s
Data
Demo account
Differentiators

What makes Onam different on GCP

Org → folder → project traversal

Onboard once at the org node. Onam discovers every folder and project, respects Organization Policy constraints, and never misses a shadow project created by a busy team.

IAM binding + BigQuery permission graph

Standard and conditional IAM bindings are correlated with BigQuery dataset ACLs and column-level policy tags. See exactly which principals can read your regulated data.

GKE cluster & VPC firewall depth

Autopilot and standard clusters are audited against CIS GKE — control plane, workload identity, PodSecurity, and network policies — alongside the VPC firewall rules that actually reach them.

FAQ

Questions we get a lot

Read-only. The predefined Security Reviewer and Viewer roles at the organization scope. No write, no data-plane access, no BigQuery query execution against your tables.

Ready to secure your Google Cloud environment?

Connect a read-only role in three minutes. Your first findings surface in under five.