Onam Security
SaaS Security (SSPM)

Who can reach your data in Microsoft 365, Google Workspace, and GitHub?

Your CSPM stops at the cloud account. Your attackers don't.

SaaS Security posture management extends the same rule graph to the platforms your company actually runs on — Microsoft 365, Google Workspace, GitHub, GitLab, Snowflake, SharePoint, Dynamics 365 and Okta — with 433 CIS Benchmark rules across six SaaS benchmarks.

10,000+
security rules
7
cloud providers
< 5 min
to first finding
100%
agentless
Why this matters

A cloud posture tool will tell you an S3 bucket is public.

It will say nothing about the SharePoint site shared with 'anyone with the link', the Microsoft 365 global admin without MFA, the stale Google Workspace guest account from a contractor who left in 2023, or the Snowflake service account holding ACCOUNTADMIN. These are the accounts attackers actually compromise — and on most platforms they are simply invisible.

The risk of not knowing

If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.

Real-time detection, not periodic audits
How does it actually work?

The mechanism, not the marketing

  1. 1

    Each SaaS platform is connected through a dedicated read-only connector — Microsoft Graph with OAuth 2.0, Google Admin SDK with service-account impersonation, Snowflake private-key JWT, GitHub and GitLab app tokens.

  2. 2

    Discovery enumerates tenants, users, admin roles, sharing settings, audit-log configuration, and data-exposure surfaces without any agent or browser extension.

  3. 3

    Findings are evaluated against 433 CIS rules — Microsoft 365 (130), GitLab (122), Google Workspace (89), Snowflake (39), SharePoint (37) and Dynamics 365 (16).

  4. 4

    SaaS findings write into the same findings model as cloud findings, so a SaaS identity risk and a cloud identity risk appear in one queue rather than two consoles.

  5. 5

    Because identity is shared, an Okta or Entra ID account that federates into AWS is traced through to the cloud permissions it unlocks on the attack-path graph.

What do you actually get?

Specific outputs, measurable outcomes

SaaS tenant inventory
every user, admin, guest, and service account across connected platforms
MFA and conditional-access gaps on privileged SaaS accounts
External sharing exposure
SharePoint, OneDrive and Google Drive links open to anyone
Audit-log configuration checks
M365 Unified Audit Log, GWS retention, Snowflake QUERY_HISTORY
DevOps platform posture
GitHub and GitLab org settings, branch protection, token hygiene
Data warehouse posture
Snowflake roles, network policies, and grant sprawl
CIS Benchmark scoring per SaaS platform with per-control evidence
Stale and orphaned SaaS identity report
See it live

SaaS Security (SSPM) in the real console.

Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.

Dashboard
Run Scan
0
Risk Score
▲ +4 this week
0
Critical Findings
▲ 3 new today
0
Cloud Assets
▲ 231 discovered
0%
Compliance Score
CIS · NIST · SOC 2
Engine Status
IAM
Network
Compliance
CDR
Risk
Encryption
Container
Data Sec
Vuln
Finding Severity
Critical12
High89
Medium234
Low512
Info1,204
Top Critical Findings
Correlating findings…
A
G
A
Your whole cloud on one screen
Risk score, engines, severity and connected clouds — 12,481 assets live
Clip length
12s
Data
Demo account
FAQ

Questions we get a lot

Microsoft 365, SharePoint, Google Workspace, GitHub, GitLab, Snowflake, Dynamics 365, and Okta. Each is a read-only connector using the platform's official API. Adding a platform is a connector plus a rule pack, so the list grows without changes to how you consume findings.
Ready to see it live

Ready to see SaaS Security (SSPM) in your cloud?

Connect a read-only role in three minutes. Your first findings surface in under five.