Sonrai Cloud Permissions Firewall - Automated IAM & Least Privilege
Sonrai Security · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
Get control of your cloud access by removing excessive permissions and unused services. The Sonrai Cloud Permissions Firewall transforms your cloud into a platform-wide state of least privilege and continuously maintains that state as usage expands across teams and cloud providers. Using AWS-native control plane policies-including Service Control Policies (SCPs) and Resource Control Policies (RCPs)-the solution enforces centralized, default-deny guardrails without slowing DevOps. With the Cloud Permissions Firewall, you significantly reduce the opportunity for attackers to steal sensitive data, disrupt business operations, or hijack your cloud once they gain a foothold.<br><br>
How does it work? <br><br>
Show the rest of the publisher’s description (5 more lines)
The Cloud Permissions Firewall is powered by deep permission usage intelligence that understands how human and machine identities actually operate-and which sensitive permissions they truly need.<br>
Using AWS-native policies such as SCPs and RCPs, Sonrai applies sweeping, global default-deny controls across your cloud environment. Excessive permissions are restricted, unused services are locked down, and dormant zombie identities are quarantined-without impacting workloads that rely on active access.<br>
When access needs arise, a frictionless Just-in-Time workflow automatically routes a request to the appropriate approver. Once approved, the underlying AWS policy is updated in real time to allow access, ensuring developers and operators get what they need quickly while maintaining least privilege and zero trust.<br>
The Cloud Permissions Firewall enables you to secure with confidence, accelerate productivity, and eliminate the time and risk associated with manually designing and managing cloud policies.<br>
Note: AWS customers must use AWS Organizations to deploy the Cloud Permissions Firewall, as enforcement relies on organization-level AWS-native policies such as SCPs and RCPs.<br>
Highlights
Highlighted by the publisher on AWS Marketplace.
Instant Risk Reduction: After your teams deploy the global policies in one-click, your attack surface is immediately reduced with quarantined zombie identities, restricted excessive permissions, and disabled unused services and regions.
Global Default Deny Without Disruption: Receive large-scale protection without restricting anything your identities actually need. As new identities appear in your cloud, the deny policy applies by default making least privilege continuous and sustainable.
ChatOps and ITSM Integration: No need to learn new tools or change your pre-existing workflows. The Cloud Permissions Firewall integrates with Slack, Google Teams, Email, Jira, ServiceNow, and more.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment
Plans and pricing as listed
7 listed- Units
- Units
- Units
- Units
- Units
- Units
- Units
Refund terms
As stated by the publisher on AWS Marketplace.
All fees are non-cancellable and non-refundable except as required by law.
Sources
Publisher resources
6 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

