Onam Security
Agentless Scanning

How do you scan every workload without deploying anything?

Nothing to install. Nothing to maintain. Nothing running in production.

Onam scans workloads using point-in-time volume snapshots orchestrated inside your own cloud account with native services — AWS Step Functions, Azure Logic Apps and GCP Workflows. Your data never leaves your environment, and no software ever runs on the workload being scanned.

10,000+
security rules
7
cloud providers
< 5 min
to first finding
100%
agentless
Why this matters

Agent rollouts are where security programmes go to die.

Every agent needs a package, a version, a rollout plan, an exception list for the machines that break, and a renewed argument with the platform team every quarter. Six months in, coverage sits at 60%, the uncovered 40% is the legacy estate that most needs scanning, and nobody can say which is which.

The risk of not knowing

If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.

Real-time detection, not periodic audits
How does it actually work?

The mechanism, not the marketing

  1. 1

    Onam assumes a read-only role and enumerates the volumes attached to every workload across your accounts.

  2. 2

    A snapshot is created and analysed by a short-lived scan worker that runs inside your own account — orchestrated by AWS Step Functions, Azure Logic Apps, or GCP Workflows depending on the cloud.

  3. 3

    Results are relayed through a storage bucket in your account; raw disk contents are never transferred to Onam. Only structured findings leave your environment.

  4. 4

    A capacity manager per cloud throttles concurrent snapshots so scanning never competes with production for quota or IOPS.

  5. 5

    Snapshots are deleted automatically once analysis completes, and a reconciler sweeps orphaned artefacts so nothing is left behind or billed.

What do you actually get?

Specific outputs, measurable outcomes

100% workload coverage without a deployment project
Package and OS inventory from every scanned volume
Vulnerability detection against the workload's real installed software
Host configuration signals
users, keys, services, and hardening state
Secrets and credential discovery on disk
Zero production impact
no agent, no CPU, no memory, no kernel module
Automatic snapshot cleanup with orphan reconciliation
Per-cloud capacity controls so scanning respects your quotas
See it live

Agentless Scanning in the real console.

Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.

Alerts
Export
All 0Critical 0High 0
Scanning 0 / 12,481 resources
SeverityFindingStatus
Analyzing resources across us-east-1, us-west-2, eu-west-1, ap-south-1…
Watch a full cloud scan
aws-prod-main → 12,481 resources → 1,051 findings ranked by severity
Clip length
11s
Data
Demo account
FAQ

Questions we get a lot

No. Snapshot analysis runs inside your own account and results are relayed through a bucket you own. Onam receives structured findings — package lists, configuration signals, finding records — never raw disk images or file contents.
Ready to see it live

Ready to see Agentless Scanning in your cloud?

Connect a read-only role in three minutes. Your first findings surface in under five.