AI Security

Are my AI workloads introducing security risks I haven't thought about?

The SEC, EU AI Act, and NIST AI RMF now require AI security posture. Most CSPM tools don't check it.

SageMaker models, Bedrock endpoints, training pipelines, and inference workloads have a distinct security surface — misconfigured by default and invisible to standard CSPM rules. Onam checks all of it.

10,000+
security rules
7
cloud providers
< 5 min
to first finding
100%
agentless
Why this matters

A data scientist spins up a SageMaker endpoint to test a model.

It's public by default, the notebook has a full-admin execution role attached, and training data is being pulled from a bucket the security team has never seen. Multiply that by every experimental model in your organisation. Traditional CSPM doesn't have a rule for it — AI security is the shadow IT nobody is watching.

The risk of not knowing

If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.

Real-time detection, not periodic audits
How does it actually work?

The mechanism, not the marketing

  1. 1

    Onam enumerates AI-specific resources — SageMaker endpoints, notebooks, training jobs, Bedrock invocations, model artifacts — via read-only APIs.

  2. 2

    Each resource is evaluated against AI-native rules that cover network isolation, IAM scope on execution roles, encryption of artifacts, and logging of inference and training events.

  3. 3

    Training data lineage is walked back through the storage graph so you see which datasets flow into which models and who has access along the way.

  4. 4

    Findings integrate with the identity, network, and data engines, so an over-permissive endpoint reachable from the internet ranks alongside the equivalent web-app risk.

  5. 5

    Rules refresh continuously as new AI services and features ship, and compliance mappings track the EU AI Act and NIST AI RMF as those frameworks evolve.

What do you actually get?

Specific outputs, measurable outcomes

SageMaker endpoint access control
public vs VPC-only
Bedrock model invocation audit
Training job isolation (VPC + security groups)
Model artifact encryption at rest
Training data access analysis
SageMaker Studio network isolation
ML service role scoping
Logging and monitoring for inference and training
See it live

AI Security in the real console.

Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.

Alerts
Export
All 0Critical 0High 0
Scanning 0 / 12,481 resources
SeverityFindingStatus
Analyzing resources across us-east-1, us-west-2, eu-west-1, ap-south-1…
Watch a full cloud scan
aws-prod-main → 12,481 resources → 1,051 findings ranked by severity
Clip length
11s
Data
Demo account
FAQ

Questions we get a lot

SageMaker (endpoints, notebooks, Studio, training jobs, models, feature store), Bedrock (models, provisioned throughput, agents, knowledge bases), Comprehend, Textract, Rekognition, and Kendra. Coverage expands as new services and features ship.
Ready to see it live

Ready to see AI Security in your cloud?

Connect a read-only role in three minutes. Your first findings surface in under five.

Related capabilities