Skip to main content

What is Flare

Flare connects to your cloud and SaaS audit logs and uses AI to surface anomalous access patterns, privilege escalations, and unusual API behavior - ranked by severity and explained in plain English.

How it works

1

Connect your cloud

Connect GCP or Google Workspace with read-only OAuth, or AWS with a read-only IAM role. Workspace supports manual analysis, and GitHub audit logs are coming soon. Flare reads audit activity where it already lives and never asks for AWS access keys.
2

Flare analyzes your logs

Flare assesses access patterns using the current evidence and available historical observations, then surfaces findings ranked by severity (Critical, High, Medium, Low).
3

Investigate conversationally

Ask follow-up questions about any finding. Flare uses the retained summary, findings and conversation history to explain what happened, why it matters, and what to investigate next. Selected source-event excerpts remain available for your review in the results panel.

What Flare detects

Flare can surface suspicious patterns without requiring you to author detection rules:
  • Privilege escalations - unexpected IAM policy changes, role grants, service account key creation
  • Unusual access patterns - API calls from new source IP addresses or unfamiliar user agents
  • Permission anomalies - spikes in PERMISSION_DENIED errors that suggest reconnaissance
  • Behavioral shifts - service accounts acting outside their normal patterns
  • First-seen activity - field values that have never appeared in your environment before

Key principles

No complete-log retention

Flare does not retain complete raw log files after analysis. It keeps anomaly findings and up to five selected source-event excerpts per finding so you can review the evidence.

No ingestion fees

Unlike traditional SIEMs, Flare reads directly from your cloud provider. No log forwarding, no per-GB costs.

Plain English explanations

Every anomaly comes with a human-readable explanation of what happened and why it matters.

30-day historical context

Flare tracks field value frequencies across a rolling 30-day window. Frequency changes and first-seen values provide context for its assessment rather than determine a score by formula.

Log sources and availability

You can also upload log files directly (JSON, NDJSON, CSV, or plain text) from any source.

Next steps

Quickstart

Get up and running in 5 minutes

Live demo

See Flare analyze a GCP incident sample

Help Center

Find GCP, AWS, Workspace and GitHub setup, troubleshooting, and investigation guides