Sonrai Security provides a Cloud Permissions Firewall that automates permissions control across AWS, Azure, and Google Cloud, significantly reducing the attack surface without manual policy adjustments. This solution enables organizations to achieve least privilege access in days, streamlining policy management and enhancing security while minimizing operational workload.
Funding
$88.5M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.

Founders
Product
Problem
Organizations struggle to manage cloud permissions across multiple platforms like AWS, Azure, and Google Cloud, leading to an expanded attack surface and increased risk of breaches. Manually adjusting policies to adhere to the principle of least privilege is time-consuming and often results in delayed remediation of excessive permissions. This complexity is compounded by the need to balance security with the agility required by DevOps teams.
Solution
Sonrai Security's Cloud Permissions Firewall automates permissions control across multi-cloud environments, enabling organizations to rapidly achieve and maintain least privilege access. The solution analyzes sensitive permissions in use to determine necessary access, then applies global restrictions to remove unneeded permissions. Policy changes are managed centrally and automatically, reducing manual workload and potential for human error. By restricting only unused permissions, the Cloud Permissions Firewall ensures developers maintain uninterrupted access to the resources they need, while CloudOps teams retain complete control and visibility.
Target Audience
The primary users are CloudOps, DevOps, and security teams seeking to automate cloud permission management, reduce their attack surface, and achieve least privilege access across multi-cloud environments without disrupting developer workflows.
Features
- Automated analysis of permissions usage across AWS, Azure, and Google Cloud
- One-click global restrictions to remove excessive permissions
- Centralized policy management with automated updates
- Integration with ChatOps tools (Slack, Teams, Email) for access request workflows
- Support for least privilege, third-party access, and just-in-time access use cases
- CIEM+ capabilities to identify and disrupt attack paths formed by toxic permission combinations
- ROI calculator to estimate time and cost savings from automated permissions control