Onam Security
Legal

Privacy Policy

Last updated: August 2026

Overview

This Privacy Policy explains how Onam Security ("Onam", "we", "us") collects, uses, and protects data when you visit our website, sign up for an account, or connect a cloud environment to the Onam platform. This page is maintained by Onam Security and is not an independent certification.

What data we collect

We collect three categories of data:

  • Account data. Name, work email, company, and role you provide when creating an account or requesting a demo.
  • Cloud configuration metadata. Onam reads configuration metadata from the cloud accounts you connect — for example, IAM policy documents, resource tags, security-group rules, and encryption settings. Onam does not read data-plane content (the objects inside your S3 buckets, the rows in your databases, or the payloads in your queues).
  • Product usage data. Basic telemetry about how the Onam UI is used — page views, feature interactions, error events — used to improve the product.
  • Website analytics data. If you consent, Google Analytics records how this marketing website is used — pages viewed, referring source, approximate location, and device type. This is separate from the product telemetry above and is covered in Cookies and website analytics.

How we use it

We use the data above to operate the Onam platform, deliver findings and reports to you, provide support, improve product quality, and communicate about your account. We do not sell your data. We do not use your cloud configuration data to train shared machine-learning models across customers.

Cookies and website analytics

This website uses Google Analytics 4 to understand which pages are useful — which content holds attention, which paths lead to a demo request, and which channels bring people here. Google Analytics sets cookies in your browser.

It does not load unless you accept it. On your first visit you are asked to accept or decline, and nothing analytics-related is requested or stored before you answer. Declining is a single click, the same as accepting. If you decline, no Google Analytics script is loaded, no cookies are set, and the site works exactly as it otherwise would. Your choice is remembered in your browser's local storage, so you are not asked again.

To change your mind, clear this site's local storage and cookies in your browser settings — the choice will be offered again on your next visit. This website sets no advertising, remarketing, or cross-site tracking cookies.

Cloud connection data

When you connect a cloud account to Onam, we store the identifiers required to authenticate to that account — for example, role ARNs, service-principal IDs, and workload-identity federation trust configurations. We do not store static access keys, secret access keys, or long-lived passwords.

Every call Onam makes to your cloud is authenticated with a short-lived, tenant-scoped token and uses read-only permissions. Nothing Onam does can modify or delete resources in your environment.

Sub-processors

Onam uses a small number of sub-processors to operate the service. Current sub-processors include cloud infrastructure providers, email delivery, identity providers used to sign in to Onam, and — for visitors to this website who consent to analytics — Google (Google Analytics 4). A current list is available on request from privacy@onam.security.

Data retention

Findings and configuration snapshots are retained per the plan you're on — 30 days on Free, 1 year on Pro, and custom retention on Enterprise. Account data is retained while your account is active and deleted or anonymised within 90 days of account closure, subject to legal-hold obligations.

Your rights

Depending on your jurisdiction, you may have the right to access, correct, delete, port, or restrict processing of your personal data. To exercise any of these rights, email privacy@onam.security. We will respond within the timelines required by applicable law.

Security

We implement administrative, technical, and physical safeguards designed to protect the data we hold. See our Security page for details on encryption, access, and vulnerability disclosure.

Changes to this policy

We may update this policy from time to time. Material changes will be posted here and, where appropriate, communicated by email.

Contact

Questions about this policy or your data can be sent to privacy@onam.security.