Technical whitepapers
Five papers on how the platform actually works — the attack-path method, how a path gets priced, why everything writes into one graph, what we store and never store, and how one control evaluation reports against 78 frameworks. Written for engineers and architects who want the mechanism, not the pitch.
How Onam finds the paths that matter
Attack pathsFrom read-only telemetry to a verified, MITRE-mapped, priced attack path — the method, step by step.
- How primitives compose into a chain, rather than matching a pre-authored shape
- Verification: why an unreachable path is not a path
- MITRE ATT&CK mapping and how a path gets ranked
A methodology paper, not a benchmark. The examples come from a demo tenant and are illustrations, not customer results.
Cloud risk in dollars
FAIR / ALEHow Onam prices a verified attack path using FAIR — with named, external inputs a board can defend.
- Loss magnitude and frequency, and where each input comes from
- Per-record costs drawn from published external research, not our own numbers
- Why a priced path beats a severity label in a board conversation
An estimate is only as good as the data classification behind it. This prices exposure; it does not predict a breach.
One graph, one data model
ArchitectureWhy every engine writes the same finding contract into one store — and what that makes possible that a drawer of separate tools cannot.
- The shared finding contract every engine conforms to
- Why correlation is a property of the data model, not a feature bolted on later
- What a single graph buys you across posture, identity, data and runtime
One data model is an architectural choice with real trade-offs — it constrains how fast any single engine can diverge.
Security & trust
Trust modelHow Onam connects, what it stores, what it never stores, and how tenants stay isolated — the trust case for a read-only platform.
- Read-only, agentless connection model and the permissions it asks for
- What is stored, what is never stored, and where
- Tenant isolation and the boundaries between them
Read-only scanning cannot see what happens inside a running process. It is a posture and path view, not a runtime agent.
Compliance, mapped once
78 frameworksHow Onam evaluates a control once and reports it against 78 frameworks — and connects every gap to a priced attack path.
- One control evaluation, many framework projections
- 78 compliance frameworks over a single control set
- Why a compliance gap is more useful when it carries a path and a price
Framework mapping is evidence for an audit, not a substitute for one. Your auditor still decides what satisfies a control.
Why these aren’t gated
A whitepaper behind an email form gets read by nobody and cited by nobody. These are written to be forwarded to the colleague who actually has the question, quoted in a design review, and argued with. If the method holds up under that, it is worth more to us than your email address.