Resources
Guides, documentation, and technical references for cloud security practitioners.
Four hops. Three tools blind. One breach.
Walk one real attack path — from a forgotten instance to your crown-jewel data — and watch a single fix break the whole chain. An animated, self-guided walkthrough.
Open the interactive deckWhitepapers, brochures & tools
Technical whitepapers, the capabilities brochure, illustrative calculators, and short explainer videos — free to download and share.
Technical whitepapers
Brochures & case studies
Capability one-pagers
How we compare
Interactive tools
Everything above is free to download, no form required. If you'd like the next whitepaper when it lands, leave an address.
Connect Your Cloud
Step-by-step onboarding guides for every supported cloud provider.
Security Capabilities
Deep-dives on each security engine — what it checks, how it works, and how to read results.
Architecture
How Onam scans, stores, and secures your data.
Compliance & Trust
Framework coverage and our security posture.
Latest posts
What to ask in a cloud security POC: 7 questions for Wiz, Orca, Prisma Cloud and Onam
Running a proof of concept against Wiz, Orca Security or Prisma Cloud? These are the seven questions to ask during the POC that actually separate the platforms — with Onam's answers on the record, and a checklist to score every vendor on your shortlist.
Beyond GuardDuty: how three-tier behavioral detection catches what rules miss
Rule-based detection catches known attack signatures. Statistical behavioral baselines catch incremental privilege escalation. ML anomaly detection catches the rest. Here's why you need all three.
The 5 AWS misconfigurations we find in 90% of first scans
After thousands of first-time AWS scans, the same five misconfigurations show up in nearly every environment. Here's what they are — and how to fix them fast.
Read the docs
Everything from onboarding your first account to tuning findings and hitting the API.