Services

Security observability

Pipelines that carry security telemetry from every cluster and account to the places you investigate from.

Retention should not be a pricing decision.

Security observability has to be cheap at scale, so you keep the data an investigation needs instead of the data you can afford. We design collection, filtering and storage so full-fidelity telemetry stays inexpensive, and only what needs an alert reaches your SIEM.

Runtime event pipelines

Export, filter, enrich and route process, file and network events from the runtime tools below, with cluster and account identity attached.

Carries data fromTetragonFalcoKubeArmor

Network flow pipelines

Flow export with field masking and filtering, landed in storage sized for the volume flows produce.

Carries data fromCilium and Hubble

Cloud audit pipelines

Organization-wide audit and finding streams ingested from S3 or EventBridge into one queryable store.

Carries data fromCloudTrailGuardDuty and Security Hub

Vector and Fluent Bit

Collection, transformation and routing, with disk buffering that survives an outage.

OpenTelemetry

Collector pipelines for logs, metrics and traces, including security signals.

Prometheus and Grafana

Monitoring for the pipeline and agents themselves, so a silent sensor does not go unnoticed.