Cloud security findings that arrive with the fix attached.
Connect AWS or Azure with read-only access. Omniphylax audits your environment, ranks what matters, and writes the Terraform, Bicep or CLI change that closes each issue.
S3 bucket allows public read access
Cloud: AWSAccount: prod-data-euBucket: exports-2026
Anyone on the internet can list and download the files in this bucket.
resource "aws_s3_bucket_public_access_block" "exports" {bucket = aws_s3_bucket.exports.idRemoved: block_public_acls = falseRemoved: block_public_policy = falseAdded: block_public_acls = trueAdded: block_public_policy = truerestrict_public_buckets = true}Added: aws s3api put-public-access-block --bucket exports-2026 --public-access-block-configuration BlockPublicAcls=true,IgnorePublicAcls=true,BlockPublicPolicy=true,RestrictPublicBuckets=trueWhat you get
Security audit
Scan every account and subscription against recognized benchmarks and keep an inventory of what you run.
Included: configuration checks, identity and access review, network exposure, logging and encryption.
Vulnerability analysis
See which findings are actually exposed, and which sit behind private networks and tight permissions.
Included: risk score with a plain reason, exposure and privilege context, trend over time.
Guided remediation
Each finding comes with an explanation and a fix in the format your team already uses.
Included: Terraform, Bicep and CLI fixes, rollback notes, review before anything changes.
Compliance reporting
Map findings to controls and export evidence for audits.
Included: CIS, SOC 2 and ISO 27001 mapping, PDF and CSV export, history by control.
How it works
Step 1: Connect
Create a read-only role from our template. Nothing is installed in your cloud.
Step 2: Scan
Omniphylax checks your accounts on a schedule and whenever you ask.
Step 3: Prioritize
Findings are ranked by exposure and impact, with the reason shown.
Step 4: Fix
Review the suggested change, copy it or open a pull request, then rescan to confirm.
Where it runs
Beta means you can connect it today once invited. Planned means it is on the roadmap but not yet available.
Clouds
- AWSBeta
- AzureBeta
- Google CloudPlanned
- Oracle CloudPlanned
Frameworks
- CIS BenchmarksBeta
- SOC 2Beta
- ISO 27001Beta
- PCI DSSPlanned
- HIPAAPlanned
Features at a glance
Asset inventory
A current list of every resource across your accounts and subscriptions, with region, tags and when it was last seen.
Risk-ranked findings
Each finding gets a score built from exposure and impact, and a one-line reason you can check for yourself.
Fixes you can review
Terraform, Bicep or CLI changes written for the affected resource, with rollback notes. Nothing is applied for you.
Attack pathsPlanned
See how an exposed resource could lead to a privileged identity, so you can break the chain at the cheapest point.
Audit-ready reports
Findings mapped to CIS, SOC 2 and ISO 27001 controls, exported as PDF or CSV, with history by control.
Slack and Jira alerts
Send new critical findings to a Slack channel, or open a Jira issue with the fix already attached.
Built to be trusted with cloud access
Read-only roles only
We ask for permissions that can read configuration, and nothing that can change it.
No long-lived cloud secrets stored
Each scan uses short-lived credentials issued by your cloud provider. There are no access keys for us to keep.
Each customer's data isolated
Inventory, findings and reports are scoped to your organization on every request.
Get early access
We invite teams in batches, starting with AWS and Azure. Leave your work email and we'll be in touch.