Your security group review says port 22 is closed.
But the instance sits in a public subnet, behind a load balancer that terminates TLS, in a VPC peered to a shared network where a jump host has SSH open to the world. On paper you are safe. In practice a single hop reaches the database. Rules alone lie; only reachability tells the truth.
The risk of not knowing
If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.
The mechanism, not the marketing
- 1
Onam pulls every network object across your clouds — VPCs, subnets, route tables, NACLs, security groups, load balancers, WAFs, transit gateways, peerings.
- 2
The engine models them as a graph and runs reachability analysis: given an internet source, what resources can actually receive traffic, on which ports, over how many hops.
- 3
Each resource gets an effective exposure score that reflects the true path, not just the closest security group.
- 4
Coverage gaps — subnets without flow logs, load balancers without WAFs, missing TLS enforcement — are surfaced separately.
- 5
Findings refresh continuously as networks change, so a new peering or a shifted route table shows up within minutes.
Specific outputs, measurable outcomes
Network Security in the real console.
Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.
Questions we get a lot
Ready to see Network Security in your cloud?
Connect a read-only role in three minutes. Your first findings surface in under five.