Security data at PB scale, without the SIEM bill
Security teams are the ones asked to search everything and given a budget to keep a fraction of it. CtrlB keeps CloudTrail, WAF, VPC flow, and audit logs on your own object storage and makes all of it searchable in seconds.
Needle in the haystack
One IP, three years of CloudTrail, in seconds
No hot/cold split and no restore step. A single principal or address is a targeted read against the whole retention window — the oldest day answers as fast as this morning.
The compromise you are making
01Ingest-priced SIEMs make the retention decision for you, so the noisy high-volume sources — WAF, flow logs, CloudTrail data events — are the first to be dropped.
02The data you did keep splits across a hot tier you can search and an archive tier you can only restore from.
03Querying the archive with Athena means a five-to-ten minute wait per question, which ends the investigation long before the questions do.
04Compliance retention and investigative retention end up as two different systems with two different copies.
What changes
Every security source lands in your own bucket at object storage prices, so keeping three years is a storage line item rather than a licensing negotiation.
One tier. The oldest day in the lake answers as fast as the newest, because the index is built at ingest for all of it.
A unique-IP search across 125 TB of CloudTrail returns in about five seconds, so an analyst follows the trail instead of batching questions.
Immutable Parquet with object-level locking gives the audit trail and the investigation surface the same copy of the data.
How it works
Point your sources at your bucket
CloudTrail, WAF, VPC flow, GuardDuty, Okta, and application audit logs land schema-less. New fields are indexed the moment they appear, so a provider adding a column never becomes a mapping incident.
Search the whole retention window
Compact inverted indexes make a needle query — one IP, one principal, one request id — a targeted read rather than a full scan, whether the event is from this morning or from two years ago.
Pivot at investigation speed
Sub-second responses mean an analyst can chase a lead across sources in one sitting, and an agent can do the same unattended.
What you get
Needle-in-a-haystack search
Schema-less audit sources
Immutable, tamper-evident
Detections over streams
One copy for audit and analysis
No ingest tax
Same security agent. Same S3 data. Only the query layer changed.
View customer storyQuestions
No. A common pattern is to keep the SIEM for the detections and workflows your team already runs, and move the high-volume sources and long-tail retention to CtrlB underneath it.
In your own S3 or GCS bucket, in open Parquet, in the region you choose. The index lives beside it in the same bucket.
As far back as you keep objects. There is no hot/cold split, so retention is a storage decision rather than a query-performance decision.
Zepto searches 1.3 PB a month of WAF and CloudTrail directly on its own object storage — the full story is on the customer page.
Put it on your own bucket and see.
Point a source at CtrlB, keep everything else where it is, and compare the same investigation side by side.