Get started

Open source · Cloud-native · Graph-first

The open cloud security graph for teams who need context, not noise

OpenSourceOM connects assets, identities, and exposures into a living security graph — surfacing attack paths and the vulnerabilities that actually put your data at risk.

  • Graph-native risk context
  • Multi-cloud AWS · Azure · GCP
  • Apache-2.0 open source

Graph-first

Every finding tied to reachability and impact

Self-hosted

Your data stays in your environment

Apache-2.0

Free to use, fork, and build on

Cloud security built around context

Traditional scanners flood you with alerts. OpenSourceOM connects the dots — showing which vulnerabilities sit on paths to sensitive data and privileged access.

The Security Graph

Continuously model relationships between workloads, identities, network paths, and data stores to expose reachable attack paths — not just isolated findings.

Risk that ranks itself

Prioritize CVEs and misconfigurations by exploitability, blast radius, and exposure — so your team fixes what attackers can actually reach first.

Multi-cloud inventory

Normalize assets across AWS, Azure, and GCP with a unified graph schema. Plug in Kubernetes, containers, and SaaS connectors as you grow.

Policy-as-code CSPM

Detect drift from CIS, PCI, and custom guardrails. Map failed controls to graph nodes so remediation has context, not just ticket IDs.

Self-hosted & auditable

Run OpenSourceOM in your VPC. No black-box scoring — inspect the graph, rules, and enrichment pipelines in plain code.

API-first integrations

Push prioritized findings to Jira, Slack, or SIEM. Pull context from CNAPP, EDR, and vulnerability scanners via open connectors.

The graph of vulns that matter to you

Inspired by graph-native CNAPP platforms, OpenSourceOM builds a queryable model of your environment. Ask questions like “Which critical CVEs are internet-exposed and can reach production databases?” — and get an answer in seconds.

  • Attack path analysis — trace lateral movement from ingress to crown jewels.
  • Identity blast radius — see what a compromised role can actually access.
  • Exposure-aware prioritization — deprioritize findings with no reachable path.
Learn how the graph works
Queryreachable(critical_cve) → datastore(prod)

CVE-2024-1234 · OpenSSL

EC2 / web-tier · Internet exposed · Path length 3

S3 bucket policy · Public list

No path to prod data · Deprioritized

IAM user · Unused access key

Stale credential · Medium · No active path

From alert fatigue to attack-path clarity

CNAPP platforms proved that context beats volume. OpenSourceOM brings graph-native security to teams that want transparency, control, and community-driven innovation.

Traditional scanningOpenSourceOM
Risk contextFlat lists of CVEs and misconfigurationsGraph paths from exposure to sensitive assets
PrioritizationCVSS score and severity aloneReachability, blast radius, and exploit signals
DeploymentVendor SaaS onlySelf-hosted in your cloud, auditable code
ExtensibilityClosed integrationsOpen connectors and policy-as-code

Early stage · Community-driven

Your support shapes what we build next

OpenSourceOM is just getting started. Community momentum — stars, feedback, and word of mouth — directly influences how fast we ship and what we prioritize. Here is how you can help today.

  1. Star the core repo

    A GitHub star is a small action with real impact — it helps others discover the project and signals that open cloud security deserves more attention.

    Star on GitHub
  2. Shape the roadmap

    Open issues for feature requests, bugs, or ideas. Upvote discussions that matter to you so we know what the community needs most.

    Browse issues
  3. Spread the word

    Visibility is the biggest lever right now. Write about OpenSourceOM on Reddit, Hacker News, X/Twitter, LinkedIn, or wherever your cloud security peers hang out.

  4. Community channels (coming soon)

    We plan to launch Slack and Discord spaces for contributors and early adopters. Watch this site and the GitHub repo for announcements.

    Coming soon

The more support we get, the harder we push this project forward. Thank you for being here this early.