Skip to main content

Cloud and SaaS security for small teams

Make sense of
your audit logs.

Know what changed, why it matters, and where to look next. Flare turns cloud and SaaS audit activity into ranked findings with the evidence to investigate.

Read-only connections No credit card required

Sample data
2 source examples
G GCP Audit Logs ExampleA AWS CloudTrail Example
Prioritized for reviewImpact
02:14:03
GCPSetIamPolicy

Owner granted across 12 production projects

97
02:14:09
AWSCreateAccessKey

First seen for a dormant IAM identity

91
02:29:41
AWSConsoleLogin

New network and no recent sign-in history

76
Ask Flare

What should I investigate first?

From logs to a decision

Security work starts with context.

Flare combines current evidence with available field-frequency and first-seen context to help you choose what to investigate.

01 / Observe

Read where the logs live

Connect with read-only access. Use OAuth for Google Cloud or Workspace, and an IAM role for AWS. Workspace supports manual analysis. GitHub audit logs are coming soon.

02 / Understand

Put activity in context

A 2 a.m. IAM change by a usually read-only account may matter. Flare explains the current evidence and available history.

03 / Respond

Keep asking questions

Investigate each finding conversationally. Your saved findings and conversation history provide context for each follow-up.

Flare retains findings and selected supporting event excerpts, not complete raw log files.

Inside a finding

The evidence behind
every finding.

Flare connects the event to available historical context and identity fields in the selected evidence, then explains why it may matter.

CriticalprotoPayload.methodName → SetIamPolicy
97

What changed

A read-only service account granted Owner access to 12 production projects.

In this example, the operation happened at 2:14 a.m. and had not appeared in the available 30-day context.

First action

Verify the change in the source system. If it was unauthorized, follow your incident procedure to contain the identity and review affected projects.

Evidence

Normal3–4 / day
Observed847 / hour
Identity
deploy-reader@prod
Usual behavior
Storage reads only
First seen
Today, 02:14 UTC
Ask Flare

Show me every permission this identity changed.

Your logs already know. Flare helps you see it.

Start with GCP, AWS or Google Workspace in Connectors. Flare fetches audit activity on demand without storing complete raw log files after analysis. GitHub audit logs are coming soon.