Query
Query provides a Security Data Mesh platform enabling federated search and AI-powered security investigations across 50+ distributed data sources without ingestion. It serves enterprise SOC teams, CISOs, and compliance functions managing multi-cloud security environments.
- Company typePrivate
- Founded2021
- HeadquartersAtlanta, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Query does
Query.AI, Inc. operates a Security Data Mesh platform that enables federated search and AI-powered investigation across distributed security data sources without requiring data movement, ingestion, or ETL pipelines. Founded in 2021 and headquartered in Atlanta, Georgia, the company targets enterprise security operations teams — SOC analysts, detection engineers, threat hunters, and CISOs — alongside compliance and risk management functions at organizations operating across complex multi-cloud and hybrid environments. The platform is built on the Open Cybersecurity Schema Framework (OCSF), normalizing data from 50+ pre-built connectors at query time and supporting inputs from SIEMs (Splunk, Microsoft Sentinel), endpoint tools (CrowdStrike, SentinelOne, Defender), identity platforms (Okta, Entra ID), and data warehouses (Snowflake, Databricks, BigQuery).
The product portfolio consists of the foundational Security Data Mesh Platform, Query Workers (AI agents for automated alert triage, threat hunting, and identity threat assessment), Federated Detections (detection engine running rules directly against distributed data), Federated Search & Analytics (unified single-pane search interface), Query for Splunk (Splunk App extending Splunk's reach without ingestion), and Security Data Pipelines (data writing capability producing compressed Parquet to cloud storage with 80%+ footprint reduction). The proprietary Federated Search Query Language (FSQL) translates queries from natural language, SPL, KQL, and Sigma into source-native syntax and executes them in parallel, returning OCSF-normalized results. Founder Dhiraj Sharan holds more than 10 patents in cybersecurity and data analytics developed over 12 years engineering ArcSight.
Query generates revenue through SaaS subscriptions to the Security Data Mesh platform, with pricing not publicly disclosed and structured through consultative "Book a Demo" enterprise sales motions. The company also distributes its Query for Splunk App via Splunkbase and lists on AWS Marketplace as an APN Software Path Verified Solution, enabling AWS customers to provision Query for Amazon Security Lake. Distribution is augmented by a Splunk Services Partner Program for managed service providers and system integrators. The company has raised approximately $19.6 million across disclosed rounds — a $4.6M seed (May 2021), a $15M Series A led by SYN Ventures (October 2021), and an undisclosed strategic investment from Cisco Investments (September 2024) — and operates with 11-50 employees on a fully remote basis.
Query firmographics
Firmographics- Name
- Query
- Legal name
- Query.AI, Inc.
- Website
- https://query.ai
- Company type
- Private
- Founded year
- 2021
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Query provides a Security Data Mesh platform enabling federated search and AI-powered security investigations across 50+ distributed data sources without ingestion. It serves enterprise SOC teams, CISOs, and compliance functions managing multi-cloud security environments.
- Ownership category
- akta.pro rank
Query industry classification
Industry- Product category
- Security Operations Software
- NAICS
- Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (51821), Web Search Portals and All Other Information Services (519290)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Query Engines & SQL Analytics Layers for Warehouses/Lakes (HDAEABAI)
- akta.pro secondary industry
- Data Sharing, Data Exchange & Data Marketplace Platforms (HDAEABAH)
Keywords
Where Query is headquartered
LocationHeadquarters
- HQ city
- Atlanta
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
Query business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- Security Data Mesh Platform Subscription: SaaS subscription model for access to the Security Data Mesh platform, including Query Workers, Federated Search, Federated Detections, and connectors. Pricing is likely tiered by data sources connected and/or query volume. Not publicly disclosed.
- Query for Splunk App: Splunk App extending Splunk's reach to all Query-connected data sources without ingestion. Revenue generated through Splunkbase distribution with potential platform-level subscription.
- Security Data Pipelines: Pipeline orchestration service for writing normalized security telemetry to cloud storage. Likely bundled with platform subscription or offered as an add-on.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | No public pricing tiers disclosed |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels11 records
Query product offering
Product offeringCore offering
Query sells a Security Data Mesh Platform that connects 50+ distributed security data sources (SIEMs, data lakes, EDR, identity, cloud) via federated connectors and normalizes data to OCSF at query time, enabling federated search and AI-powered security investigations without data movement, ingestion, or ETL. The platform is delivered as a SaaS subscription and packaged with Query Workers (AI security agents), Federated Detections, Query for Splunk (Splunk App), and Security Data Pipelines.
Product overview
Query offers a unified Security Data Mesh Platform that provides federated search and AI-powered security operations across distributed data sources without requiring data centralization or ingestion. The core platform supports 50+ connectors and normalizes data to the Open Cybersecurity Schema Framework (OCSF) at query time. The product portfolio consists of: (1) the Security Data Mesh Platform as the foundational infrastructure layer with connectors and FSQL query engine; (2) Query Workers as AI agents that automate security operations tasks including alert triage, threat hunting, and identity assessments; (3) Federated Detections for running detection logic across distributed data without ingestion; (4) Federated Search for unified single-interface querying across all sources; (5) Query for Splunk as an integration module extending Splunk's visibility; and (6) Security Data Pipelines for writing normalized data to cloud storage destinations.
Differentiator
Problem solved
Functional benefit
Products and services
- Security Data Mesh Platform Foundational SaaS platform that connects 50+ distributed security data sources (SIEMs, data lakes, EDR, identity, network, cloud) via pre-built and dynamic connectors, normalizes data to OCSF at query time, and provides the execution substrate for Query Workers, Federated Detections, Federated Search, and Query for Splunk. Sold to enterprise SOCs and security operations teams on a subscription basis.
- Query Workers AI-powered security agents with specialist skills that automate alert triage, hypothesis-driven threat hunting, identity threat assessment, vulnerability prioritization, access review, and other security operations workflows across all connected data sources in the mesh. Workers investigate and recommend with full evidence chains (FSQL query logs, source citations, confidence ratings) rather than black-box verdicts. A typical Worker investigation takes ~15 minutes versus 8–12 hours manually. Sold to enterprise SOCs as part of the Query platform.
- Federated Detections Detection engine that runs detection logic directly against data wherever it lives (cloud services, SaaS, security tools, object storage, SIEMs) without requiring ingestion or centralization. Includes 1,000+ FSQL detection recipes and supports SPL/KQL/Sigma rule translation, scheduled execution, and auditable deterministic outputs. Sold to enterprise security operations teams to expand detection coverage beyond SIEM ingestion budgets.
- Federated Search Unified single-console search and analytics interface that lets analysts query 50+ connected security data sources in parallel with OCSF-normalized results, accepting natural language, SPL, KQL, and Sigma syntaxes translated to FSQL. Eliminates context loss from pivoting across 10+ consoles per investigation. Sold as part of the Query platform subscription to enterprise SOCs.
- Query for Splunk Splunk App that extends Splunk's reach to every source connected to the Query mesh without ingestion costs, letting analysts work in the familiar Splunk console while accessing data lakes, warehouses, identity, EDR, and cloud sources. Distributed via Splunkbase (App ID 4634) and supported through the Splunk Services Partner Program. Sold to Splunk-using enterprises seeking to reduce Splunk ingestion costs without losing visibility.
- Security Data Pipelines Data writing capability that moves and normalizes security telemetry from sources such as CrowdStrike, Entra ID, and GitHub into cloud storage destinations (Amazon S3, Azure Blob, Google Cloud Storage) as ZSTD-compressed partitioned Parquet, reducing storage footprint by 80%+ versus JSON/XML and enabling 85–95% reduction in incremental EDR/CrowdStrike storage costs. Orchestrated with cloud-native services and requiring no containers or custom code. Sold to enterprise security and data teams as an add-on to the Query platform.
Quantifiable outcome
- ~$1M+ avoided ingestion fees per customer, typical first-year impact
- +5 more outcomes
Companies that use Query
Customer profileNamed customers2 records
Segments2 records
Ideal customer profiles2 records
Query technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration33 records
AI capability7 records
Feature7 records
Query partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core and major.
- Splunk (Services Partner Program)coreQuery participates in the Splunk Services Partner Program, enabling managed service providers and SI professionals to deploy, implement, and manage Query for Splunk deployments. The Query Splunk App is distributed via Splunkbase (app ID 4634).
- Demetrios Lazarikos (Advisory Board)majorCybersecurity expert Demetrios Lazarikos, a veteran with extensive experience in cybersecurity strategy and operations, joined Query's advisory board in September 2024 to provide strategic guidance.
- Spencer Mott (Advisory Board)majorSpencer Mott joined Query's advisory board in August 2024, bringing deep cybersecurity industry expertise to guide product strategy and market positioning.
- AWS (Amazon Security Lake)coreQuery is an AWS Partner Network (APN) Software Path Verified Solution and Amazon Security Lake Subscriber Partner. Query provides search and analytics interface for data stored in Amazon Security Lake, with OCSF-native support for all event classes and automatic schema mapping.
Scale indicators8 records
Recent moves6 records
Expansion highlights6 records
Query competitors and assessment
Company assessmentDirect peers
- Cribl: Cribl provides a routing, search, and observability pipeline (Cribl Stream, Cribl Search) that processes log and security data without requiring ingestion into a SIEM. Most directly comparable to Query on architecture (federation, no-ETL) and target buyer (SOC/SecOps leaders seeking SIEM cost reduction).
- Panther Labs: Panther is a cloud-native SIEM built on a data lake (Snowflake/Databricks) with detection-as-code. Comparable to Query as a modern alternative to legacy SIEMs for security operations teams, though Panther centralizes data while Query federates.
- Hunters Security: Hunters provides a SOC automation platform that ingests data from multiple security sources and applies correlation and AI-driven detection. Comparable to Query's Query Workers layer on AI-driven alert triage and threat investigation across distributed sources.
- Devo Technology: Devo offers a cloud-native SIEM and security analytics platform serving enterprise SOCs. Comparable to Query on customer base (enterprise security operations) and adjacent on function (security data analytics and detection), though Devo centralizes data in its cloud-native architecture.
- Sumo Logic: Sumo Logic provides cloud-native log management and security analytics with continuous query. Comparable to Query on cloud-native security analytics for enterprise SOCs and on the value proposition of reducing on-prem SIEM dependence.
Broad incumbents
- Splunk: Splunk is the dominant enterprise SIEM/log analytics platform, now part of Cisco. Query's go-to-market is partly built around extending Splunk's reach via the Splunk App, making Splunk both partner and primary competitive incumbent at the broader platform level.
- Microsoft Sentinel: Microsoft Sentinel is a hyperscaler-native SIEM within the Microsoft security portfolio. Comparable to Query as an enterprise SIEM alternative but with first-party advantages of Azure integration, Defender telemetry, and enterprise E5 bundling.
- Google Security Operations (Chronicle): Google SecOps (formerly Chronicle) is Google Cloud's SIEM and security analytics platform. Comparable to Query on the federated security data value proposition at hyperscaler scale and as a competitor for enterprise SOC budgets.
- Datadog Cloud SIEM: Datadog Cloud SIEM extends the Datadog observability platform into security analytics. Comparable to Query on cloud-native security analytics for enterprises already using Datadog, though positioned as part of a much broader observability portfolio.
Emerging players
- Tarsal: Tarsal is an early-stage startup focused on security data movement and pipeline automation. Comparable to Query's Security Data Pipelines product in the adjacent space of moving and normalizing security telemetry across cloud destinations.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Query social profiles
Digital presenceQuery compliance and trust
Trust signalCompliance4 records
Query financial estimates
Financial estimateRevenue estimate
Valuation estimate
Query leadership team
Management profileNumber of profiles
Profiles11 records
Query funding detail
Funding detailFunding overview
Funding rounds3 records
Investors5 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Query M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Query
What does Query do?
Query sells a Security Data Mesh Platform that connects 50+ distributed security data sources (SIEMs, data lakes, EDR, identity, cloud) via federated connectors and normalizes data to OCSF at query time, enabling federated search and AI-powered security investigations without data movement, ingestion, or ETL. The platform is delivered as a SaaS subscription and packaged with Query Workers (AI security agents), Federated Detections, Query for Splunk (Splunk App), and Security Data Pipelines.
Is Query a public or private company?
Query is a private company. It is classified as venture growth investor backed and is currently operating.
When was Query founded?
Query was founded in 2021. It employs 11 to 50 people.
Where is Query based?
Query is headquartered in Atlanta, United States, in the North America region.
How does Query make money?
Three revenue lines are on record. Security Data Mesh Platform Subscription is the primary driver. The others are query for Splunk App and security Data Pipelines.
Who are Query's main competitors?
Direct peers on record are Cribl, Panther Labs, Hunters Security, Devo Technology and Sumo Logic. Broad incumbents are Splunk, Microsoft Sentinel, Google Security Operations (Chronicle) and Datadog Cloud SIEM. Tarsal is listed as an emerging player.
Does Query have an API?
Yes. Query provides a REST API (FSQL REST API) that enables developers to query distributed security data sources using the Federated Search Query Language. The API is used to power Query Workers, the Query Splunk App, CLI, and third-party agents/MCP tools. Developer documentation is at docs.query.ai/docs/fsql.
What industry is Query in?
Query's product category is Security Operations Software. Its primary akta.pro industry code is HDAEABAI, Query Engines & SQL Analytics Layers for Warehouses/Lakes, with a secondary code of HDAEABAH, Data Sharing, Data Exchange & Data Marketplace Platforms. Its NAICS code is 51821 and its SIC code is 7372.