Your compliance report says 100% encryption at rest.
It is technically true and nearly useless. The bucket is encrypted with an AWS-managed key that every principal in the account can use. The key that protects your customer database has no rotation policy and a key policy with a wildcard principal. A certificate on your main load balancer expires in nine days. 'Encrypted' passed the audit; none of this did.
The risk of not knowing
If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.
The mechanism, not the marketing
- 1
Every key, vault, secret and certificate is discovered across AWS KMS, Azure Key Vault, GCP Cloud KMS, OCI Vault and their equivalents.
- 2
A coverage analyzer walks the resource inventory and identifies which resources are unencrypted, encrypted with provider-managed keys, or encrypted with customer-managed keys.
- 3
Key policies are resolved against the identity graph to compute the effective decrypt set — every principal that can actually use each key, including through role chains.
- 4
Certificate inventory tracks issuer, algorithm, and expiry across ACM and equivalent services, with lead-time alerting before expiry.
- 5
Rotation state, deletion protection, and key-material origin are checked against 502 secrets and key-management rules mapped to CIS, NIST and PCI-DSS controls.
Specific outputs, measurable outcomes
Encryption & Key Management in the real console.
Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.
Questions we get a lot
Ready to see Encryption & Key Management in your cloud?
Connect a read-only role in three minutes. Your first findings surface in under five.