Every security tool reports its own number.
Posture says 74. The vulnerability scanner says 12,000 open CVEs. The compliance tool says 88% CIS. The identity tool says 400 over-privileged roles. None of them are wrong and none of them combine, so the answer to 'are we getting better' becomes a quarterly slide someone assembles by hand from four exports.
The risk of not knowing
If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.
The mechanism, not the marketing
- 1
Each of the seven pillars — CSPM, CIEM, CWPP, DSPM, network, threat and AppSec — is scored from the findings its engines produced, on a common 0–100 scale.
- 2
Pillar scores are weighted by severity and by exposure, so a critical finding on an internet-reachable resource moves the score more than the same finding on an isolated one.
- 3
Scores roll into one overall posture score with a risk band, trended over time so improvement is measurable rather than asserted.
- 4
Every score decomposes — click a pillar to see the findings behind it, click a finding to see the resource and the remediation.
- 5
Because all pillars read the same findings model, the same resource is never counted twice or scored inconsistently between views.
Specific outputs, measurable outcomes
CNAPP in the real console.
Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.
Questions we get a lot
Ready to see CNAPP in your cloud?
Connect a read-only role in three minutes. Your first findings surface in under five.