Services

Security observability

Collecting security telemetry from every cluster and account, and storing it somewhere cheap to keep and fast to search.

Retention should not be a pricing decision.

Security observability has to be cheap at scale, so you keep the data an investigation needs instead of the data you can afford. We design collection, filtering and storage so the telemetry you actually investigate with stays inexpensive, and only what needs an alert reaches your SIEM.

Collect

Runtime event pipelines

Export, filter, enrich and route process, file and network events from the runtime sensors we deploy, with cluster and account identity attached.

Carries data fromTetragonFalcoKubeArmor

Network flow pipelines

Flow export with field masking and filtering, landed in storage sized for the volume flows produce.

Carries data fromCilium and Hubble

Cloud audit pipelines

Organization-wide audit and finding streams ingested from S3 or EventBridge into one queryable store.

Carries data fromCloudTrailGuardDutySecurity Hub

Vector and Fluent Bit

Collection, transformation and routing, with disk buffering that survives an outage.

OpenTelemetry

Collector pipelines for logs, metrics and traces, including security signals.

Store and search

ClickHouse

High-volume security logs on low-cost storage: ingestion from S3, schemas, retention tiers and investigation queries.

Read the full service page →

Elasticsearch

Index design, ILM, ingest pipelines and cost control for security workloads.

OpenSearch

Self-managed or AWS-managed clusters sized and tuned for log retention and search.

OpenObserve

Logs, metrics and traces in one self-hosted store backed by S3, with dashboards and alerting set up for security use.

Keep it healthy

Prometheus and Grafana

Monitoring for the pipeline and sensors themselves, so a silent source does not go unnoticed.