Scanner.dev
- Company typePrivate
- Founded2021
- HeadquartersSan Francisco, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
Scanner.dev firmographics
Firmographics- Name
- Scanner.dev
- Legal name
- Scanner, Inc.
- Website
- https://scanner.dev
- Company type
- Private
- Founded year
- 2021
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Ownership category
- akta.pro rank
Scanner.dev industry classification
Industry- Product category
- Cloud-native Security Data Lake / SIEM Alternative
- NAICS
- Software Publishers (513210), Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (51821)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Cloud Security Logging, SIEM/SOAR & Threat Detection (HDABAHAL)
- akta.pro secondary industry
- Log Management & Analytics (HDABAJAC)
Keywords
Where Scanner.dev is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Scanner.dev business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Infrastructure, Marketing or Sales, Operations
Revenue model
- Managed Scanner (Multi-Tenant): Multi-tenant cloud deployment where Scanner runs the compute infrastructure. Best for fast-growing companies wanting zero-ops experience. Pricing based on daily log volume.
- Managed Scanner (Single-Tenant): Dedicated AWS account for each customer with Scanner control plane. Enhanced performance with dedicated resources. For mid-sized companies requiring compliance and dedicated SOC operations.
- Bring Your Own Cloud (BYOC): Scanner compute runs entirely within customer's own AWS account. All data and processing stays in AWS accounts owned by customer. For large organizations requiring enterprise-wide security operations and strict regulatory compliance.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Multi-Tenant Managed Scanner for 250-500 GB daily logs |
| Subscription | Annual | Single-Tenant Managed Scanner for 500 GB-2 TB daily logs |
| Subscription | Multi-year contract | Bring Your Own Cloud for 2-100+ TB daily logs |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels9 records
Scanner.dev product offering
Product offeringCore offering
Scanner.dev sells a cloud-native security data lake platform that indexes log data directly inside customer-owned Amazon S3 buckets using a proprietary S3-native inverted index. It delivers SIEM-grade search speed (up to 700x faster than Amazon Athena), continuous streaming threat detection with 400+ out-of-the-box rules, schema-less ingestion from 30+ sources, and native AI agent access via Model Context Protocol for incident response and threat hunting.
Product overview
Scanner.dev offers a unified security data lake platform built around a specialized inverted index designed for object storage (S3). The core platform consists of Scanner (the main product), complemented by four integrated modules: Scanner Collect for data ingestion from 30+ sources, Search & Investigate for hyper-fast full-text search across petabytes, Detections & Response for streaming threat detection with 400+ out-of-the-box rules, and MCP & APIs for AI agent integration. The platform supports three deployment models: Multi-Tenant Managed Scanner (shared infrastructure), Single-Tenant Managed Scanner (dedicated AWS account), and Bring Your Own Cloud (customer-controlled infrastructure). All models keep customer data in their own S3 buckets with full data sovereignty.
Differentiator
Problem solved
Functional benefit
Products and services
- Scanner Core Platform Cloud-native security data lake that indexes data directly in S3 where it already lives, enabling hyper-fast search across petabytes of logs, continuous threat detection, and AI agent integration. Replaces traditional SIEMs with unlimited retention at lower costs; targets SOC teams, detection engineers, and incident responders.
- Scanner Collect Data ingestion module that seamlessly ingests logs from 30+ pre-built integrations including AWS CloudTrail, Azure, GCP, Okta, GitHub, and more. Features schema-less architecture supporting JSON, CSV, plaintext, and Parquet formats without ETL requirements; for security and platform teams.
- Search & Investigate Lightning-fast full-text search engine that enables security teams to search petabytes of logs in seconds for indicators of compromise and threat hunting investigations; performance up to 700x faster than Amazon Athena.
- Detections & Response
Quantifiable outcome
- 84% reduction in investigation time using Scanner with AI agent
- +6 more outcomes
Companies that use Scanner.dev
Customer profileNamed customers8 records
Segments4 records
Ideal customer profiles3 records
Scanner.dev technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration26 records
AI capability7 records
Feature9 records
Scanner.dev partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered design partner, core infrastructure and core platform.
- Notiondesign partnerNotion uses Scanner as a core data source for their security AI agent 'Scruff', achieving 84% reduction in investigation time. Notion publicly wrote about their Scanner integration.
- AWS (Amazon Web Services)core infrastructureScanner is built on AWS and indexes data directly in customer S3 buckets. BYOC deployment option runs entirely within customer's AWS account. AWS re:Invent event participation.
- GitHubcore platformDetection-as-code implementation with GitHub CI/CD integration. Public GitHub repositories for detection rules (scanner-inc/detection-rules-*). Detection rules managed directly from GitHub repositories.
Scale indicators6 records
Recent moves6 records
Expansion highlights7 records
Scanner.dev competitors and assessment
Company assessmentBroad incumbents
- Exabeam: Exabeam is an established SIEM and security analytics vendor with a cloud-native data lake architecture and AI-driven detection capabilities. It competes with Scanner in mid-market and enterprise SOC replacement opportunities, with a much larger sales motion and broader product suite.
- Splunk: Splunk is the dominant enterprise SIEM that Scanner is explicitly positioned against. With Cisco's backing and a massive installed base, Splunk is the incumbent alternative whose cost and retention limitations Scanner attacks. Any Splunk product innovation in cheap long-term retention would directly compress Scanner's value proposition.
- Sumo Logic: Sumo Logic is a cloud-native SIEM and log analytics platform with significant overlap in customer base (security teams needing log search and threat detection). It competes with Scanner on the same 'modern SIEM' positioning but at significantly larger scale and with broader analytics coverage.
- Snowflake: Snowflake is a cloud data platform increasingly used as the foundation for security data lakes, and competes with Scanner when security teams choose to build on Snowflake's separation of storage and compute. It is a broader platform play rather than a security-specialized peer, but is often on the buyer's evaluation shortlist alongside Scanner.
- Microsoft Sentinel: Microsoft Sentinel is a cloud-native SIEM deeply integrated with the Azure ecosystem and increasingly with AWS data sources. It competes head-on with Scanner for cloud security data lake workloads, especially in Microsoft-heavy enterprise accounts, and benefits from a bundled go-to-market motion that Scanner cannot match.
Direct peers
- ChaosSearch: ChaosSearch indexes log data directly in S3 (the same architectural premise as Scanner) and provides a search/analytics layer on top of object storage. The two companies share the S3-native data lake thesis, though ChaosSearch historically focuses more on log analytics and compliance use cases than detection.
- Devo Technology: Devo offers a cloud-native SIEM with a security data lake at its core, targeting similar SOC and security operations use cases as Scanner. Both emphasize real-time analytics on large volumes of machine data, though Devo carries a more traditional enterprise go-to-market and broader product portfolio.
- Panther Labs: Panther offers a cloud-native SIEM built on top of a security data lake with detection-as-code, similar to Scanner's core proposition. Both target modern security teams looking to replace Splunk with a more scalable, code-driven architecture and serve overlapping buyer personas in fast-growing technology companies.
- Hunters Security: Hunters provides a cloud-native SIEM and security data lake platform that aggregates logs, runs detections, and feeds SOC workflows. It targets the same 'SIEM replacement' buyer as Scanner, with comparable emphasis on reducing Splunk-class costs while improving detection quality and analyst experience.
- Cribl: Cribl's log routing and observability pipeline (Stream, Edge) addresses the same SIEM cost and data routing pain points that Scanner targets. Both companies position around reducing SIEM spend and enabling flexible data flow into security data lakes, with Cribl historically the incumbent 'data reduction' layer that Scanner increasingly overlaps with on the security data lake side.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Scanner.dev social profiles
Digital presenceScanner.dev compliance and trust
Trust signalCompliance2 records
Scanner.dev financial estimates
Financial estimateRevenue estimate
Valuation estimate
Scanner.dev leadership team
Management profileNumber of profiles
Profiles2 records
Scanner.dev funding detail
Funding detailFunding overview
Funding rounds1 record
Investors3 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Scanner.dev M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Scanner.dev
What does Scanner.dev do?
Scanner.dev sells a cloud-native security data lake platform that indexes log data directly inside customer-owned Amazon S3 buckets using a proprietary S3-native inverted index. It delivers SIEM-grade search speed (up to 700x faster than Amazon Athena), continuous streaming threat detection with 400+ out-of-the-box rules, schema-less ingestion from 30+ sources, and native AI agent access via Model Context Protocol for incident response and threat hunting.
Is Scanner.dev a public or private company?
Scanner.dev is a private company. It is classified as venture growth investor backed and is currently operating.
When was Scanner.dev founded?
Scanner.dev was founded in 2021. It employs 11 to 50 people.
Where is Scanner.dev based?
Scanner.dev is headquartered in San Francisco, United States, in the North America region.
How does Scanner.dev make money?
Three revenue lines are on record. Managed Scanner (Multi-Tenant) is the primary driver. The others are managed Scanner (Single-Tenant) and bring Your Own Cloud (BYOC).
Who are Scanner.dev's main competitors?
Broad incumbents on record are Exabeam, Splunk, Sumo Logic, Snowflake and Microsoft Sentinel. Direct peers are ChaosSearch, Devo Technology, Panther Labs, Hunters Security and Cribl.
Does Scanner.dev have an API?
Yes. Scanner provides a public API that enables developers to search logs in S3, programmatically manage detections, and automate alert workflows. The API supports integrations with external tools for automated ticketing, enrichment, and agentic AI-driven investigations. The platform is API-first and every query and dataset is available programmatically. Scanner also supports Model Context Protocol (MCP) for AI agents to get structured access to security data through a standardized interface built for intelligence tools. The Scanner CLI (scanner-cli) supports YAML-based detection development. Developer documentation is at docs.scanner.dev/scanner.
What industry is Scanner.dev in?
Scanner.dev's product category is Cloud-native Security Data Lake / SIEM Alternative. Its primary akta.pro industry code is HDABAHAL, Cloud Security Logging, SIEM/SOAR & Threat Detection, with a secondary code of HDABAJAC, Log Management & Analytics. Its NAICS code is 513210 and its SIC code is 7372.