What is Flare
Flare connects to your cloud and SaaS audit logs and uses AI to surface anomalous access patterns, privilege escalations, and unusual API behavior - ranked by severity and explained in plain English.How it works
1
Connect your cloud
Connect GCP or Google Workspace with read-only OAuth, or AWS with a read-only IAM role. Workspace supports manual analysis, and GitHub audit logs are coming soon. Flare reads audit activity where it already lives and never asks for AWS access keys.
2
Flare analyzes your logs
Flare assesses access patterns using the current evidence and available historical observations, then surfaces findings ranked by severity (Critical, High, Medium, Low).
3
Investigate conversationally
Ask follow-up questions about any finding. Flare uses the retained summary, findings and conversation history to explain what happened, why it matters, and what to investigate next. Selected source-event excerpts remain available for your review in the results panel.
What Flare detects
Flare can surface suspicious patterns without requiring you to author detection rules:- Privilege escalations - unexpected IAM policy changes, role grants, service account key creation
- Unusual access patterns - API calls from new source IP addresses or unfamiliar user agents
- Permission anomalies - spikes in PERMISSION_DENIED errors that suggest reconnaissance
- Behavioral shifts - service accounts acting outside their normal patterns
- First-seen activity - field values that have never appeared in your environment before
Key principles
No complete-log retention
Flare does not retain complete raw log files after analysis. It keeps anomaly findings and up to five selected source-event excerpts per finding so you can review the evidence.
No ingestion fees
Unlike traditional SIEMs, Flare reads directly from your cloud provider. No log forwarding, no per-GB costs.
Plain English explanations
Every anomaly comes with a human-readable explanation of what happened and why it matters.
30-day historical context
Flare tracks field value frequencies across a rolling 30-day window. Frequency changes and first-seen values provide context for its assessment rather than determine a score by formula.
Log sources and availability
You can also upload log files directly (JSON, NDJSON, CSV, or plain text) from any source.
Next steps
Quickstart
Get up and running in 5 minutes
Live demo
See Flare analyze a GCP incident sample
Help Center
Find GCP, AWS, Workspace and GitHub setup, troubleshooting, and investigation guides