New#1 combined on ClickBench, untuned

The fastest data lake for AI agents.

One substrate for observability and security data on your object storage. Humans and agents query complete history in seconds, at PB Scale.

10 min → 500 ms
Production agent queries
125 TB CloudTrail Logs
Unique IP search in ~5 s
Infinite Cardinality Metrics
For AI systems
Open Parquet; No Lock-in
Inside your object store
Zepto
GoComet
Blitz
OnBe
NeverInstall
Coreworks
Zepto
GoComet
Blitz
OnBe
NeverInstall
Coreworks
Zepto
GoComet
Blitz
OnBe
NeverInstall
Coreworks

One Data Layer for All Your Telemetry.

Collectors feed in. Dashboards and agents query out. Logs, metrics, and traces stay on object storage you own — searchable in real time.

Agents & collectors
CtrlBCtrlB
Real-time observability on your data lake
Ingest & Index
Federated Query
Observability Engine
Patterns
Alerting
APM
Open & Extensible
FlowFlow
Dashboards & visualization
Apps, agents & clients
Object storage

Bring your Own Agent

Connect the agent you already use. One MCP endpoint sits over the whole lake, so the agent you already trust reads complete history directly, and we never charge for what it asks.

Any agent, yours or ours to name
Claude Code
Cursor
your in-house agent
vendor agent
CI pipeline
MCP
CtrlB substrate
logs · traces · metrics · security events · 365 days searchable · open Parquet in your bucket
reads unmetered500ms queries
Any agent. Questions are free.
your agent · ctrlb mcp
who touched the iam policy on the payments role in october
─ ctrlb.search_logs (dataset: cloudtrail, window: 365d)
─ ctrlb.get_pattern (pattern_id: p_4c19)
─ ctrlb.get_trace (trace_id: 91b2…7d40)
Three AttachRolePolicy calls on 14 Oct from a CI principal outside the deploy window. Same session issued a GetSessionToken 90 seconds earlier from an unseen ASN.
3 tool calls1.4 s totalread cost $0.00
History the agent can see
365 days
hot, unsampled, queryable in one hop
Cost per question
$0.00
reads are never metered, by design
How our customers actually query us
MCP first
more traffic arrives over MCP than through the UI. That is the proof we trust most, because it is behavioural.

One lake. Search, Analytics and AI Insights.

1,335 Events
03:3903:4103:43
Timestamp
|
Summary
15:44:36
Memory usage at 46%
15:44:36
Cache hit for key: 2220587f-7081-49f4-a5b0-11ef8c26478c
15:44:36
Cache hit for key: 37ec679c-5aa9-4875-8d83-2a13ca85d51c
15:44:36
Handled DELETE request in 424ms
15:44:36
Queue size reached 4986 messages
15:44:35
Successfully processed transaction cc4ba36c-f8c6-4c82-b
15:44:35
Tracing db execution plan for SELECT * FROM users
15:44:35
Connection timeout in primary DB cluster
15:44:35
Malformed payload received from external webhook
15:44:34
Updated user profile for emiejohns@turner.org
15:44:34
Queue size reached 289 messages
15:44:34
Handled POST request in 127ms

Built for PB Scale

Query logs, metrics, and traces with one stack — open storage you own, and performance that stays fast as volume grows.

Raw JSON
{"user": 921}
{"event": "click"}
{"os": "mac"}
Schema-less
Parquet

Schema-less ingestion

Send any JSON. New fields are indexed the moment they appear — no mapping to maintain, no rejected events, no migration when the shape changes.

ANALYTICS.SQL
1
2

Stateless queries

Query nodes keep no local state. Fan out to hundreds of spot instances for one heavy scan, then scale to zero when nobody is asking.

METRICS
0 dropped
http.request.duration
service
Unique series
12all queryable
no allowlists · no drop rules · cost tracks bytes, not series

Infinite cardinality metrics

Tag by user, tenant, device, or LLM call. Every dimension stays queryable — no allowlists, no drop rules, and no bill that punishes you for the tags you kept.

What Changed for Teams Using CtrlB.

The world’s most innovative companies are already in production with CtrlB.

01
Security
Zepto

Five-minute Athena queries became 500 ms searches.

Zepto searches 1.3 PB/month of WAF and CloudTrail directly on its own object storage.

1.3 PB/month5 min → 500 ms
02
Full-Stack OTel
GoComet

"CtrlB gives us real-time visibility into our logistics systems — I can see critical events as they unfold. It’s now woven into how we operate every day at GoComet." — Ayush Lodhi, CTO & Co-Founder

03
Full-Stack OTel
Blitz

"Tracing in CtrlB has completely changed how we debug issues at Blitz. We can follow requests across services in seconds instead of hours — it’s cut down our RCA time massively." — Gaurav Piyush, CTO

04
Log Consolidation
OnBe

Five production sources became one searchable lake.

Application, infrastructure, database, load balancer, and firewall logs share one data layer.

5 sources → 1 lake
05
Infrastructure
NeverInstall

"Scaling observability used to slow us down at NeverInstall. CtrlB handled that effortlessly — now our telemetry scales as fast as our infrastructure does." — Lakshman Pasala, CEO

06
Full-Stack OTel
Coreworks

Fully OTel native logs, traces, and metrics. By unifying the entire telemetry stack, Coreworks enables instant Root Cause Analysis by traversing connected data streams effortlessly.

Works where you do

Use CtrlB with your favorite cloud provider, data sources, and frameworks.

VS_CODE
VS_CODE
CURSOR
CURSOR
WINDSURF
WINDSURF
CLAUDE_CODE
CLAUDE_CODE
AZURE
AZURE
VS_CODE
VS_CODE
CURSOR
CURSOR
WINDSURF
WINDSURF
CLAUDE_CODE
CLAUDE_CODE
AZURE
AZURE
VS_CODE
VS_CODE
CURSOR
CURSOR
WINDSURF
WINDSURF
CLAUDE_CODE
CLAUDE_CODE
AZURE
AZURE
VS_CODE
VS_CODE
CURSOR
CURSOR
WINDSURF
WINDSURF
CLAUDE_CODE
CLAUDE_CODE
AZURE
AZURE
GCS
GCS
AWS
AWS
OTEL
OTEL
VECTOR
VECTOR
FLUENT_BIT
FLUENT_BIT
GCS
GCS
AWS
AWS
OTEL
OTEL
VECTOR
VECTOR
FLUENT_BIT
FLUENT_BIT
GCS
GCS
AWS
AWS
OTEL
OTEL
VECTOR
VECTOR
FLUENT_BIT
FLUENT_BIT
GCS
GCS
AWS
AWS
OTEL
OTEL
VECTOR
VECTOR
FLUENT_BIT
FLUENT_BIT

Enterprise Ready

The controls a security review actually asks about, on a platform that can run inside your own cloud account.

BYOC / VPC deployment

Run ingest and query inside your own AWS or GCP account.

SSO

Single sign-on through your existing identity provider.

RBAC

Control who can query which data, and who can change what.

Frequently Asked  Questions

CtrlB is a high-performance data lake for security and observability telemetry. It indexes logs, metrics, and traces on object storage you own and keeps them fast enough to investigate, for people and for agents. Existing tools can stay.