Onam Security
Onam Estate

What do we actually run, and how is it wired together?

You cannot secure, bill, or decommission a resource nobody knows exists.

Onam Estate discovers every resource across your cloud accounts, records the relationships between them, and keeps that picture current run after run — so the inventory is a live system of record rather than a spreadsheet somebody exported in March.

10,000+
security rules
7
cloud providers
< 5 min
to first finding
100%
agentless
Why this matters

Someone asks a question that should take a minute: how many production databases do we have, in which accounts, and who pays for them.

Four hours later there are three answers — one from the CMDB, one from a Terraform state file, one from a billing export — and none of them agree. The CMDB was last reconciled by hand, the state file only covers what was provisioned through the pipeline, and the billing export knows cost but not what a resource is connected to. The gap between those three is where forgotten infrastructure lives, and it is where both the security surprise and the cost surprise come from.

The risk of not knowing

If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.

Real-time detection, not periodic audits
How does it actually work?

The mechanism, not the marketing

  1. 1

    A discovery pipeline enumerates resources across your connected accounts and regions using read-only credentials, and records what it found as assets with provider, region, account, state and last-seen time.

  2. 2

    Relationships are captured as first-class edges rather than inferred later — containment edges describe what lives inside what, external edges describe what reaches outside the boundary.

  3. 3

    Every run is recorded with its trigger, status, start and completion, so the inventory carries its own provenance and a stale or partial run is visible instead of silently degrading the picture.

  4. 4

    Assets are stamped with monthly cost as they are discovered, which is what makes the estate answerable to a finance question and not only to an engineering one.

  5. 5

    The same discovery output feeds Onam Security's graph, so an account entitled to both products gets one inventory rather than two that disagree.

What do you actually get?

Specific outputs, measurable outcomes

Asset inventory
every discovered resource with provider, region, account, state and last-seen time
Monthly cost on every asset row, so the estate answers finance questions as well as engineering ones
Architecture view
per-account topology with assets, edges, containment edges and external edges
Relationship graph
what contains what, and what reaches outside the account boundary
Pipeline history
every discovery run with its trigger, status and duration
Asset type breakdown per account, so sprawl is visible by shape and not just by count
Read-only discovery
no agents, no write permissions, nothing installed on a workload
One shared inventory with Onam Security for organisations entitled to both
See it live

Onam Estate in the real console.

Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.

Dashboard
Run Scan
0
Risk Score
▲ +4 this week
0
Critical Findings
▲ 3 new today
0
Cloud Assets
▲ 231 discovered
0%
Compliance Score
CIS · NIST · SOC 2
Engine Status
IAM
Network
Compliance
CDR
Risk
Encryption
Container
Data Sec
Vuln
Finding Severity
Critical12
High89
Medium234
Low512
Info1,204
Top Critical Findings
Correlating findings…
A
G
A
Your whole cloud on one screen
Risk score, engines, severity and connected clouds — 12,481 assets live
Clip length
12s
Data
Demo account
FAQ

Questions we get a lot

It is the same discovery, sold as its own product. Onam Security's inventory exists to answer security questions — what is exposed, what is over-permissioned, what sits on an attack path. Onam Estate is the estate of record: what exists, how it is connected, what it costs, and when it was last seen. Organisations entitled to both get one inventory feeding both, which is the point — a second inventory that disagrees with the first is worse than none.
Ready to see it live

Ready to see Onam Estate in your cloud?

Connect a read-only role in three minutes. Your first findings surface in under five.