One data layer for security, observability, and AI agents.
CtrlB is one lake of open Parquet in object storage you own, and four stages over it. Collect what your fleet emits, search all of it in seconds, let the system surface what changed, and give your agents the same access your engineers have.
Core components
Collect & Control
Configure, update, and govern every collector and agent from one place.
Search & Investigate
Full-text search, SQL, metrics, and traces on object storage.
Analyze & Correlate
Patterns, anomalies, and correlations across your telemetry.
Agent Access
Give any agent fast access to complete operational history.
One Data Layer for All Your Telemetry.
Collectors feed in. Dashboards and agents query out. Logs, metrics, and traces stay on object storage you own — searchable in real time.











Collect & Control
One control plane for every collector and agent.
Configure, update, and govern every collector and agent from one place.
Collect & Control detailsSearch & Investigate
One engine for search, SQL, metrics, and traces.
Full-text search, SQL, metrics, and traces on object storage.
Search & Investigate detailsAnalyze & Correlate
Patterns, anomalies, and correlations across your telemetry.
Patterns, anomalies, and correlations across your telemetry.
Analyze & Correlate detailsAgent Access
One MCP endpoint over the whole lake.
Give any agent fast access to complete operational history.
Agent Access detailsSaaS, your bucket, or inside your cloud
The same platform runs in three shapes. The difference is where the storage and the compute live, not what the product can do.
BYOC · Managed UI
This part runs inside your cloud (your VPC / account)
Cluster #1
Cluster #2
CtrlB data plane — fully managed, in your account
Ingest, query, and Parquet never leave your account.
This part is on CtrlB's cloud
Managed experience
SaaS-simple UI queries your in-account data plane over an encrypted link. Telemetry stays in your VPC.
Auth
Strict data residency
Ingest, query, and Parquet run inside your VPC or cloud account — telemetry stays local.
Air-gap ready
Run the full stack including Flow and SSO entirely inside your account when required.
Managed UI option
Keep the data plane private while Flow and SSO stay on our cloud over encrypted links.
Regulated environments
Built for teams where every byte and every login must stay inside a boundary you control.
Security and enterprise controls
Most of these are consequences of the architecture rather than features bolted on top: if the lake is immutable Parquet in your own bucket, residency and chain of custody follow from where the bytes already are.
Encryption everywhere
Encryption at rest and in transit, with hierarchical keys and private networking between components.
Data residency
Choose the region, or run entirely inside your own account under BYOB or BYOC so telemetry never leaves it.
Immutable storage
Write-once Parquet with object-level locking and no compaction rewrites, so the audit trail stays intact.
One copy, two jobs
Compliance retention and live investigation read the same objects, removing an entire class of reconciliation work.
Reliability
Uptime SLAs and mission-critical support for scale-out deployments.
Compliance posture
Industry-standard security practices and compliance with privacy regulations; specifics available on request.
Query a real lake before you send anything.
The playground runs against live data. Type a query, watch what it scans, and see the latency for yourself.
