Onam Security
Asset Inventory & Discovery

What do you actually run — across every cloud, in one list?

You cannot secure what nobody has counted.

The discovery engine is the foundation every other engine reads from: continuous, read-only enumeration of every resource across seven clouds and 549 services, with the relationships between them modelled as a graph.

10,000+
security rules
7
cloud providers
< 5 min
to first finding
100%
agentless
Why this matters

Ask three teams how many cloud accounts the company has and you will get three numbers.

The spreadsheet is a year old, the tagging standard was adopted by two of nine teams, and the account someone opened for a proof of concept in 2022 is still running, still billed, and still has a production database in it. Every security control you own applies only to the resources you know about.

The risk of not knowing

If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.

Real-time detection, not periodic audits
How does it actually work?

The mechanism, not the marketing

  1. 1

    Discovery enumerates every resource across AWS, Azure, GCP, OCI, Alibaba Cloud, IBM Cloud and Kubernetes — 549 services in total — using read-only credentials.

  2. 2

    Each resource is normalised into a shared model, so an AWS security group and an Azure network security group are comparable objects rather than two vendor formats.

  3. 3

    Relationships are modelled explicitly — which instance sits in which subnet, which role is assumed by which function, which volume is attached where — forming the graph that attack-path analysis walks.

  4. 4

    Discovery runs continuously, so new resources appear in inventory within minutes of creation and deleted resources are retired rather than lingering.

  5. 5

    Every other engine reads from this inventory, which is why a resource cannot be evaluated by one engine and invisible to another.

What do you actually get?

Specific outputs, measurable outcomes

Unified inventory across seven clouds and 549 services
Normalised resource model
comparable objects across providers
Relationship graph
the dependency map attack paths are computed on
Continuous refresh with new-resource detection in minutes
Untagged, unowned and orphaned resource reports
Multi-account and multi-subscription rollup in one view
Resource history
what changed, and when
Coverage reporting
which accounts and regions are actually being scanned
See it live

Asset Inventory & Discovery in the real console.

Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.

Assets — Inventory
Export CSV
12,481
Total Assets
3
Clouds Connected
231
New (7 days)
3
Crown Jewels
Loading live data…
Every asset, every cloud, one inventory
12,481 resources across AWS, GCP and Azure — typed, tagged and risk-ranked
Clip length
10s
Data
Demo account
FAQ

Questions we get a lot

549 services across seven providers — 123 on AWS, 95 on Azure, 71 on GCP, 68 on Alibaba Cloud, 68 on Kubernetes, 63 on IBM Cloud and 61 on OCI. Coverage expands with each rule-catalogue release.
Ready to see it live

Ready to see Asset Inventory & Discovery in your cloud?

Connect a read-only role in three minutes. Your first findings surface in under five.