Everything between a cloud misconfiguration and its fix.
Omniphylax finds what is misconfigured, tells you which issues are actually reachable, and hands you the change that closes each one. Here is what each part does today and what is still planned.
Asset inventory
BetaEvery scan refreshes a single inventory across your AWS accounts and Azure subscriptions. Search it by name, type, region or tag, and see when each resource was last seen.
Resources that disappear are kept in history, so you can tell what changed between two scans.
| Resource | Type | Region | Last seen |
|---|---|---|---|
| exports-2026 | S3 bucket | eu-west-1 | 4 min ago |
| vm-api-01 | Virtual machine | westeurope | 4 min ago |
| orders-db | RDS instance | eu-central-1 | 4 min ago |
| kv-shared | Key Vault | northeurope | 1 hr ago |
| ci-deployer | IAM role | global | 1 hr ago |
Risk-ranked findings
BetaA score combines how exposed a resource is with what an attacker could reach from it. Every score shows its reason in one line, so you can disagree with it quickly.
An open port on a private instance ranks below a public bucket full of customer data.
- Score 92
Storage account allows anonymous blob access
Reachable from the internet and holds customer exports.
- Score 78
IAM user has an unused admin access key
Key is 210 days old and can change any resource in the account.
- Score 31
Security group allows SSH from anywhere
Attached instance sits in a private subnet with no public address.
Remediation
BetaEach finding includes a plain explanation and a fix written for the affected resource, in Terraform, Bicep or the cloud CLI. Rollback notes come with it.
Nothing changes in your cloud until your team reviews the change and applies it.
resource exports 'Microsoft.Storage/storageAccounts@2023-05-01' = {name: 'stexportsprod'properties: {Removed: allowBlobPublicAccess: trueRemoved: minimumTlsVersion: 'TLS1_0'Added: allowBlobPublicAccess: falseAdded: minimumTlsVersion: 'TLS1_2'}}Attack paths
PlannedAttack paths will connect individual findings into the route an attacker could take, from an exposed entry point to a privileged identity.
The aim is to show the one change that breaks the whole chain, instead of five separate findings.
Internet
0.0.0.0/0
Load balancer
port 443 open
Virtual machine
vm-api-01
Admin role
Owner on subscription
Closing port 443 to the internet, or removing the role from the VM, breaks this path.
Compliance and reports
BetaFindings map to CIS Benchmarks, SOC 2 and ISO 27001 controls. Track the share of controls passing over time and export evidence as PDF or CSV when an auditor asks.
- CIS AWS Foundations82% passing
- SOC 267% passing
- ISO 2700158% passing
Integrations and team
BetaSend findings to the tools your team already watches. Slack and Jira are in the beta; GitHub pull requests are planned.
Four roles keep access simple: Owner, Admin, Analyst and Viewer.
- Beta
Slack
New critical findings to a channel
- Beta
Jira
One issue per finding, fix included
- Planned
GitHub
Fixes opened as pull requests
- Owner
- Billing, members and cloud connections
- Admin
- Connections, schedules and integrations
- Analyst
- Triage findings and export reports
- Viewer
- Read findings and reports
Get early access
We invite teams in batches, starting with AWS and Azure. Leave your work email and we'll be in touch.