Meet the Monad team at Black Hat
Join us in Vegas
Join us in Vegas
Resources / Blog / Monad + Scanner: The Security Data Foundation for the AI Era

July 28, 2026

Monad + Scanner: The Security Data Foundation for the AI Era

Christian Almenar

Co-founder & CEO

Cliff Crosland

Scanner Co-founder & CEO

Security teams are outgrowing the architecture their SOCs were built around. Data volumes keep rising, sources keep multiplying, and SIEM-only models force a tradeoff between cost, coverage, and speed. That architecture is also a weak foundation for the AI era. AI workflows inherit the coverage gaps, inconsistent data, missing context, and slow retrieval of the systems beneath them.

Monad and Scanner solve both sides of the problem. Monad collects, normalizes, enriches, filters, and routes data from 350+ integrations. Scanner provides instant search and threat hunting across years of retained logs, plus live detections as new data arrives.

Together, we give security teams the context needed for detection engineering, threat hunting, and AI-driven investigations while separating data retention from SIEM economics. Depending on data mix and retention needs, Monad and Scanner can deliver 50% to 70% lower ingestion and retention costs than a SIEM while keeping the data instantly searchable.

Lambda, which builds GPU supercomputers for large-scale AI training and inference, runs Monad and Scanner together. 

“We recently deployed Monad and Scanner to overhaul our security stack. Monad gives us access to a wide array of data sources, handles the normalization, and catches breaking changes before they become problems. Scanner turns that clean data into answers, enabling us to search and hunt across months of logs in seconds, be it via console, API, or MCP. Together, they've expanded our visibility, opened the door to agentic detection and response, and helped us investigate incidents faster with fewer people — outperforming traditional SIEMs for far less.” - Daniel Gilmartin, Staff Security Engineer @ Lambda

Monad supports security teams at Robinhood, CoreWeave, Rubrik and more. Scanner supports teams at Notion, Ramp, Postman and more.

The architecture is simple

Monad controls security data upstream. Scanner gives teams instant search over retained data downstream. The SIEM stays focused on the workflows where it still makes sense.

Retained data lives in your own S3 buckets, under your AWS account. Scanner indexes it, but never holds it. That gives teams a stronger ownership model than traditional security data platforms: you keep the data, control the storage, and still get fast search and detections across months or years of history.

Monad and Scanner reference architecture for routing clean, enriched security data into SIEM, S3, and searchable long-term retention.

Why this model wins

  1. Versus SIEM-only, teams keep more data useful at lower cost.
    The SIEM stays focused on alerting, dashboards, workflow, compliance, and case management. High-volume and long-retention data can move into a lower-cost path without becoming slow or unusable.
  2. Versus object storage alone, retained data stays operational.
    S3 lowers storage cost, but it does not normalize, enrich, route, search, or operationalize security data by itself. Monad shapes the data before it lands. Scanner makes years of retained data searchable in seconds.
  3. Versus DIY pipelines, teams avoid building and maintaining plumbing.
    Monad gives teams 300+ integrations, including AI and developer-tool sources like Claude Code, Cursor, Codex, and Glean, plus the normalization, enrichment, filtering, and routing needed to make that data useful downstream.
  4. Versus all-in-one platforms, teams reduce lock-in.
    Data can flow to the SIEM, Scanner, object storage, a warehouse, APIs, and agent workflows without one vendor deciding what teams can keep, search, build, or automate.
  5. Versus AI bolted onto bad data, humans and agents get a stronger foundation.
    Analysts, detection engineers, and AI agents all need clean telemetry, relevant context, fast retrieval, and enough history to investigate with confidence.

You can't search what you never kept

Raw logs are noisy, inconsistent, duplicated, and often missing the context analysts need. The same user, host, or cloud resource shows up differently across tools. Key fields are buried/heavily nested, absent, or renamed. That makes detections harder to write, investigations harder to trust, and AI agents less useful.

Normalization solves one problem. Fast retrieval solves another. When an investigation is live, “we retained it” is not enough. Humans and AI need to ask broad, iterative questions across months or years of data without waiting on long-running jobs, narrowing scope to control cost, or working from partial context.

That is where instant search at any scale changes the game. High-volume sources can move out of the SIEM without becoming cold storage. They stay usable for incident response, threat hunting, detection validation, forensic lookback, and AI-assisted investigation.

Ramp ran into this directly. Cost once limited them to 15 days of searchable logs. With Scanner, they now ingest around 4 TB a day of previously cost-prohibitive sources, and searches that took more than 30 minutes now finish in a minute or two.

The problem is most felt with high-volume log sources, the sources teams cut first because they are expensive to retain:

  • VPC Flow Logs rarely make it into the SIEM because of their volume, yet they record which hosts talked to which infrastructure, exactly what an analyst needs to investigate command and control activity.
  • DNS resolver query logs get dropped for the same reason, yet they record the domains every host tried to reach, the trail that makes phishing and command and control investigations fast.
  • CloudTrail data events, such as S3 object level activity, are disabled by default in AWS and billed separately once enabled, yet their access patterns can reveal an exfiltration campaign, whether the actor is an outsider or an insider.

These sources are noisy as alert streams but invaluable for incident response, threat hunting, detection engineering, and forensic lookback.

AI raises the stakes without changing the requirements. Agents need what analysts need: clean logs, relevant context, fast retrieval, deep history, and access to the systems where security data actually lives.

That is what Monad and Scanner deliver together: cleaner data upstream, searchable security context downstream, lower cost, and less dependency on any single platform.

See what this unlocks in your environment

Whether you are rethinking a SIEM renewal, expanding what you retain, or figuring out how AI agents fit into your security operations, the conversation is simple. In 30 minutes, we will walk through this architecture against your environment: the sources you could bring back, what that unlocks for incident response, detection engineering, threat hunting, and AI initiatives, and what it looks like at a fraction of your current cost.

Talk to MonadTalk to Scanner

This piece was written jointly by Cliff and Christian. Cliff is co-founder and CEO of Scanner. Christian is co-founder and CEO of Monad.

Related content

Monad + Scanner: The Security Data Foundation for the AI Era

Christian Almenar

|

July 28, 2026

Monad + Scanner: The Security Data Foundation for the AI Era

GitHub Copilot Audit Logs: What’s Emitted and Detection Opportunities

Darwin Salazar

|

July 22, 2026

GitHub Copilot Audit Logs: What’s Emitted and Detection Opportunities

Google Workspace Gemini Activity Logs: What’s Emitted and Detection Opportunities

Darwin Salazar

|

July 16, 2026

Google Workspace Gemini Activity Logs: What’s Emitted and Detection Opportunities

The backbone for
security telemetry.

Effortlessly transform, filter, and route your security data. Tune out the noise and surface the signal with Monad.