Onam Security
Encryption & Key Management

Is everything actually encrypted — and who can decrypt it?

Encryption at rest is meaningless if the wrong principal holds the key.

The encryption engine evaluates 502 secrets and key-management rules across every cloud — KMS, Key Vault, Cloud KMS and OCI Vault — then answers the question that matters more than the checkbox: which identities can decrypt your data.

10,000+
security rules
7
cloud providers
< 5 min
to first finding
100%
agentless
Why this matters

Your compliance report says 100% encryption at rest.

It is technically true and nearly useless. The bucket is encrypted with an AWS-managed key that every principal in the account can use. The key that protects your customer database has no rotation policy and a key policy with a wildcard principal. A certificate on your main load balancer expires in nine days. 'Encrypted' passed the audit; none of this did.

The risk of not knowing

If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.

Real-time detection, not periodic audits
How does it actually work?

The mechanism, not the marketing

  1. 1

    Every key, vault, secret and certificate is discovered across AWS KMS, Azure Key Vault, GCP Cloud KMS, OCI Vault and their equivalents.

  2. 2

    A coverage analyzer walks the resource inventory and identifies which resources are unencrypted, encrypted with provider-managed keys, or encrypted with customer-managed keys.

  3. 3

    Key policies are resolved against the identity graph to compute the effective decrypt set — every principal that can actually use each key, including through role chains.

  4. 4

    Certificate inventory tracks issuer, algorithm, and expiry across ACM and equivalent services, with lead-time alerting before expiry.

  5. 5

    Rotation state, deletion protection, and key-material origin are checked against 502 secrets and key-management rules mapped to CIS, NIST and PCI-DSS controls.

What do you actually get?

Specific outputs, measurable outcomes

Encryption coverage report
unencrypted, provider-managed, and customer-managed, per resource
Effective decrypt set
every identity that can use each key
Key rotation compliance and overdue rotation alerts
Certificate inventory with expiry lead-time warnings
Key policy analysis
wildcard principals and cross-account grants
Secrets manager posture
rotation, versioning, and access scope
In-transit enforcement gaps
TLS policy on endpoints and load balancers
Framework mapping for encryption controls across CIS, NIST 800-53 and PCI-DSS v4
See it live

Encryption & Key Management in the real console.

Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.

Data Security — DSPM
Run Classification
847K
PII Records Found
3
Public Buckets
12
Unencrypted Stores
5
Cross-Region
Loading live data…
Know where your PII lives
847K PII records classified — public buckets and unencrypted stores flagged first
Clip length
10s
Data
Demo account
FAQ

Questions we get a lot

No. The engine reads key metadata and policy through read-only APIs — algorithm, rotation state, policy document, and expiry. It never requests decrypt permission and never handles key material or plaintext.
Ready to see it live

Ready to see Encryption & Key Management in your cloud?

Connect a read-only role in three minutes. Your first findings surface in under five.