Onam Security

Exposure, encryption and residency

DSPM's per-store protection checks: encryption at rest, access logging, versioning and backup, the 0–100 governance score, and region residency.

Encryption at rest

Each store's own encryption setting is checked: default encryption on S3 buckets, storage encryption or a KMS key on RDS, server-side encryption on DynamoDB, the encrypted flag on Redshift, encryption at rest on OpenSearch, and the equivalents on other clouds. Kinesis streams are treated as encrypted.

The Encryption & Keys engine goes further on the same stores: which key protects each one (provider-managed or customer-managed), whether the key rotates, who its policy lets in, and what depends on it. It reads DSPM's labels, so:

ConditionSeverity
Sensitive data on an unencrypted storeCritical
Sensitive data on a provider-managed key rather than a customer-managed oneHigh
Public store with sensitive data and no encryption in transitCritical

Activity logging

Server access logging on buckets, log exports or enhanced monitoring on RDS, streams or contributor insights on DynamoDB, audit logging on Redshift and OpenSearch. A store with no access log has no record of who read it.

Lifecycle and backup

Versioning or lifecycle rules on buckets; backup retention and deletion protection on RDS; point-in-time recovery on DynamoDB; automated snapshot retention on Redshift.

The governance score

Every store gets a 0–100 score from three checks of equal weight: encrypted at rest, not public, access logging on. The possible values are 0, 33, 66 and 100. A score below 80 — that is, any store missing one of the three — is a finding: high below 50, medium otherwise.

Residency

Every store's region is recorded and shown in the residency view. The default residency check in scheduled scans flags stores held outside EU and US regions. The engine also accepts an explicit list of allowed regions for residency evaluation, which flags any store outside that list instead.

Residency is about where the primary copy lives. Copies made by replication to another region are visible as cross-region hops in Data lineage.

The default EU-or-US rule will not suit every organisation — a team whose data must stay in one country needs an allowed-region list. Talk to us about setting your residency rules.