Skip to content
Omniphylax

Cloud security findings that arrive with the fix attached.

Connect AWS or Azure with read-only access. Omniphylax audits your environment, ranks what matters, and writes the Terraform, Bicep or CLI change that closes each issue.

See how it worksRead-only access. No credit card.
Critical

S3 bucket allows public read access

Cloud: AWSAccount: prod-data-euBucket: exports-2026

Anyone on the internet can list and download the files in this bucket.

resource "aws_s3_bucket_public_access_block" "exports" {
bucket = aws_s3_bucket.exports.id
Removed: block_public_acls = false
Removed: block_public_policy = false
Added: block_public_acls = true
Added: block_public_policy = true
restrict_public_buckets = true
}
Open pull request (coming soon)
Example finding. Real findings include your resource details.

What you get

Security audit

Scan every account and subscription against recognized benchmarks and keep an inventory of what you run.

Included: configuration checks, identity and access review, network exposure, logging and encryption.

Vulnerability analysis

See which findings are actually exposed, and which sit behind private networks and tight permissions.

Included: risk score with a plain reason, exposure and privilege context, trend over time.

Guided remediation

Each finding comes with an explanation and a fix in the format your team already uses.

Included: Terraform, Bicep and CLI fixes, rollback notes, review before anything changes.

Compliance reporting

Map findings to controls and export evidence for audits.

Included: CIS, SOC 2 and ISO 27001 mapping, PDF and CSV export, history by control.

How it works

  1. Step 1: Connect

    Create a read-only role from our template. Nothing is installed in your cloud.

  2. Step 2: Scan

    Omniphylax checks your accounts on a schedule and whenever you ask.

  3. Step 3: Prioritize

    Findings are ranked by exposure and impact, with the reason shown.

  4. Step 4: Fix

    Review the suggested change, copy it or open a pull request, then rescan to confirm.

Where it runs

Beta means you can connect it today once invited. Planned means it is on the roadmap but not yet available.

Clouds

  • AWSBeta
  • AzureBeta
  • Google CloudPlanned
  • Oracle CloudPlanned

Frameworks

  • CIS BenchmarksBeta
  • SOC 2Beta
  • ISO 27001Beta
  • PCI DSSPlanned
  • HIPAAPlanned

Features at a glance

Asset inventory

A current list of every resource across your accounts and subscriptions, with region, tags and when it was last seen.

Risk-ranked findings

Each finding gets a score built from exposure and impact, and a one-line reason you can check for yourself.

Fixes you can review

Terraform, Bicep or CLI changes written for the affected resource, with rollback notes. Nothing is applied for you.

Attack pathsPlanned

See how an exposed resource could lead to a privileged identity, so you can break the chain at the cheapest point.

Audit-ready reports

Findings mapped to CIS, SOC 2 and ISO 27001 controls, exported as PDF or CSV, with history by control.

Slack and Jira alerts

Send new critical findings to a Slack channel, or open a Jira issue with the fix already attached.

See all features

Built to be trusted with cloud access

Read-only roles only

We ask for permissions that can read configuration, and nothing that can change it.

No long-lived cloud secrets stored

Each scan uses short-lived credentials issued by your cloud provider. There are no access keys for us to keep.

Each customer's data isolated

Inventory, findings and reports are scoped to your organization on every request.

How we handle access

Get early access

We invite teams in batches, starting with AWS and Azure. Leave your work email and we'll be in touch.