Get started

Open source · Cloud-native · Graph-first

The open cloud security graph for teams who need context, not noise

OpenSourceOM connects assets, identities, and exposures into a living security graph — surfacing attack paths and the vulnerabilities that actually put your data at risk.

  • Graph-native risk context
  • Multi-cloud AWS · Azure · GCP
  • Apache-2.0 open source

Graph-first

Every finding tied to reachability and impact

Self-hosted

Your data stays in your environment

Apache-2.0

Free to use, fork, and build on

Cloud security built around context

Traditional scanners flood you with alerts. OpenSourceOM connects the dots — showing which vulnerabilities sit on paths to sensitive data and privileged access.

The Security Graph

Continuously model relationships between workloads, identities, network paths, and data stores to expose reachable attack paths — not just isolated findings.

Risk that ranks itself

Prioritize CVEs and misconfigurations by exploitability, blast radius, and exposure — so your team fixes what attackers can actually reach first.

Multi-cloud inventory

Normalize assets across AWS, Azure, and GCP with a unified graph schema. Plug in Kubernetes, containers, and SaaS connectors as you grow.

Policy-as-code CSPM

Detect drift from CIS, PCI, and custom guardrails. Map failed controls to graph nodes so remediation has context, not just ticket IDs.

Self-hosted & auditable

Run OpenSourceOM in your VPC. No black-box scoring — inspect the graph, rules, and enrichment pipelines in plain code.

API-first integrations

Push prioritized findings to Jira, Slack, or SIEM. Pull context from CNAPP, EDR, and vulnerability scanners via open connectors.

The graph of vulns that matter to you

Inspired by graph-native CNAPP platforms, OpenSourceOM builds a queryable model of your environment. Ask questions like “Which critical CVEs are internet-exposed and can reach production databases?” — and get an answer in seconds.

  • Attack path analysis — trace lateral movement from ingress to crown jewels.
  • Identity blast radius — see what a compromised role can actually access.
  • Exposure-aware prioritization — deprioritize findings with no reachable path.
Learn how the graph works
Query reachable(critical_cve) → datastore(prod)

CVE-2024-1234 · OpenSSL

EC2 / web-tier · Internet exposed · Path length 3

S3 bucket policy · Public list

No path to prod data · Deprioritized

IAM user · Unused access key

Stale credential · Medium · No active path

From alert fatigue to attack-path clarity

CNAPP platforms proved that context beats volume. OpenSourceOM brings graph-native security to teams that want transparency, control, and community-driven innovation.

Traditional scanning OpenSourceOM
Risk context Flat lists of CVEs and misconfigurations Graph paths from exposure to sensitive assets
Prioritization CVSS score and severity alone Reachability, blast radius, and exploit signals
Deployment Vendor SaaS only Self-hosted in your cloud, auditable code
Extensibility Closed integrations Open connectors and policy-as-code

Build the future of open cloud security

Star the repo, join the community, and help shape a transparent alternative to proprietary CNAPP tools.