Read where the logs live
Connect with read-only access. Use OAuth for Google Cloud or Workspace, and an IAM role for AWS. Workspace supports manual analysis. GitHub audit logs are coming soon.
Cloud and SaaS security for small teams
Know what changed, why it matters, and where to look next. Flare turns cloud and SaaS audit activity into ranked findings with the evidence to investigate.
Read-only connections No credit card required
Owner granted across 12 production projects
First seen for a dormant IAM identity
New network and no recent sign-in history
What should I investigate first?
Your audit trail is already there. Give it the context it needs.
Explore coverageFrom logs to a decision
Flare combines current evidence with available field-frequency and first-seen context to help you choose what to investigate.
Connect with read-only access. Use OAuth for Google Cloud or Workspace, and an IAM role for AWS. Workspace supports manual analysis. GitHub audit logs are coming soon.
A 2 a.m. IAM change by a usually read-only account may matter. Flare explains the current evidence and available history.
Investigate each finding conversationally. Your saved findings and conversation history provide context for each follow-up.
Flare retains findings and selected supporting event excerpts, not complete raw log files.
Inside a finding
Flare connects the event to available historical context and identity fields in the selected evidence, then explains why it may matter.
What changed
In this example, the operation happened at 2:14 a.m. and had not appeared in the available 30-day context.
Verify the change in the source system. If it was unauthorized, follow your incident procedure to contain the identity and review affected projects.
Evidence
Show me every permission this identity changed.
One layer, every workflow
Run Flare on a documented schedule, at the edge of a release, or while investigating an event sequence already in motion.
Compare cloud activity before and after every deploy. Surface risky IAM and infrastructure changes while the release context is still fresh.
Review Terraform and CloudFormation changes inside the pull request. Catch privilege expansion before it reaches production.
Choose a time window and reconstruct the sequence across services. Get the likely blast radius and next questions in one investigation.
Turn cloud audit activity into a concise weekly record of access, policy, and infrastructure changes your team can review.
Start with GCP, AWS or Google Workspace in Connectors. Flare fetches audit activity on demand without storing complete raw log files after analysis. GitHub audit logs are coming soon.