Onam Security

DSPM coverage by cloud

Which data store types DSPM analyses on each cloud and for self-hosted databases, with per-service notes on what is checked and what is not.

The stores below receive the full set of DSPM checks. Other data services — on AWS, for example DocumentDB, Neptune, Timestream, Keyspaces, ElastiCache, SQS, SNS and MSK — are evaluated by the storage and database posture rules and their findings are grouped into DSPM modules, but they do not get the per-store classification and governance score.

AWS

StoreNotes
S3 bucketsFull checks; multi-signal public determination; bucket-policy cross-account analysis; object ownership; event-notification lineage
RDS instances and Aurora clustersEncryption (storage encryption or KMS key), public accessibility, log exports or enhanced monitoring, backup retention and deletion protection
DynamoDB tablesServer-side encryption, point-in-time recovery, streams; not publicly reachable by design
Redshift clustersEncrypted flag, public accessibility, audit logging, snapshot retention
Glue databasesEncryption and classification
OpenSearch domainsEncryption at rest, log publishing
Kinesis streamsTreated as encrypted; consumers recorded as lineage
Lake FormationBroad default and wildcard admin grants

Azure

Storage accounts, Data Lake Storage, Azure SQL servers, Cosmos DB, Synapse workspaces and Key Vault.

Google Cloud

Cloud Storage buckets, Cloud SQL instances, BigQuery datasets, Spanner instances, Firestore databases and Secret Manager secrets. Residency treats europe-* locations as EU and us-* as US.

Oracle Cloud (OCI)

Object Storage buckets, Autonomous Databases, NoSQL tables and Streaming streams.

Alibaba Cloud

OSS buckets, ApsaraDB RDS instances, PolarDB clusters, Tablestore instances and MaxCompute projects.

IBM Cloud

Cloud Object Storage buckets, IBM Cloud Databases instances (for example Databases for PostgreSQL), Cloudant and Event Streams.

Kubernetes

Secrets (always labelled confidential), ConfigMaps (confidential when a key name looks like a credential), persistent volume claims and StatefulSets.

Self-hosted databases

PostgreSQL, MySQL, MariaDB, SQL Server, MongoDB, Oracle, Cassandra, IBM Db2 and Snowflake, once onboarded as technology accounts. DSPM classifies them from their resource, database and schema names; it only adds labels and never overwrites a label from the cloud path. Engine-level hardening for the same databases is covered by Database Security through CIS benchmarks.

Not covered

  • Data inside SaaS applications other than Snowflake.
  • On-premises file shares and storage arrays.
  • Databricks.