Solutions · Oracle Cloud Infrastructure

Enterprise-Grade OCI Security Monitoring That Matches Oracle's Complexity

OCI's compartment model and policy language offer granular control, but auditing nested compartments and cross-tenancy access manually is operationally prohibitive. Onam traverses every compartment, audits IAM policies against least-privilege baselines, and monitors database, network, and storage continuously.

220+
OCI security rules
25+
OCI services monitored
Nested
compartment traversal
100%
agentless, read-only
Coverage

Services we monitor on OCI

Every service below is scanned continuously — no agents, no network changes, read-only.

IAM Users, Groups & Policies
Compartments & Tenancies
Compute Instances & VCNs
Object Storage Buckets
Autonomous Database
MySQL & Database Cloud Service
OKE Kubernetes Clusters
Vault & KMS
Load Balancers
Security Zones
Cloud Guard
Logging & Audit

Plus: Functions, API Gateway, Streaming, Data Safe, Bastion, Web Application Firewall, and more.

Compliance

Compliance frameworks

Onam maps every OCI finding to the frameworks your auditors care about.

CIS Oracle Cloud Infrastructure BenchmarkISO 27001:2022SOC 2 Type IINIST 800-53 Rev 5
Onboarding

Connect in 3 steps

From consent to first finding in under five minutes.

1

Create a read-only OCI user & group

Provision an Onam user in the root tenancy, add it to a dedicated group, and attach a policy that grants inspect and read on all-resources across the tenancy.

2

Generate an API signing key

Upload the public key to the Onam user. The private key is stored in Onam's HSM-backed key vault — never exported, never accessible to humans.

3

First findings in under 5 minutes

Onam walks every compartment recursively — including nested and dynamic groups — and returns findings mapped to CIS OCI in real time.

See it live

OCI in the real console.

Not a mockup — the actual Onam console on a live demo account: connect, inventory and posture in one view.

Add Cloud Account
Docs
AWS · Production
Read-only • No agents
1
Create read-only IAM role
2
Paste Role ARN
3
Validated — scanning…
onam · console
$aws cloudformation create-stack --stack-name onam --template-url ...
Connect your first cloud account
Read-only IAM role — validated and scanning in under 3 minutes
Clip length
9s
Data
Demo account
Differentiators

What makes Onam different on OCI

Full compartment-tree traversal

Onam parses every parent, child, and cross-tenancy policy statement in Oracle's policy language and evaluates them against the compartment tree — including matching conditions and where clauses.

Autonomous Database posture

Data Safe risk levels, private-endpoint enforcement, wallet rotation, and access-control list drift — audited continuously alongside your Autonomous DB workloads.

VCN + Security List analysis

VCN topology, security lists, network security groups, and route tables are combined into one exposure graph so overly-permissive rules are surfaced with the resources they actually reach.

FAQ

Questions we get a lot

A read-only policy: `allow group Onam-Readers to inspect all-resources in tenancy` plus `read` on specific families needed for deep configuration analysis. No manage, no use.

Ready to secure your OCI environment?

Connect a read-only role in three minutes. Your first findings surface in under five.