October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Scanner Raises $22 Million for AI-Powered Threat Hunting: What the S3 Security-Data Platform Does

Scanner’s $22 million Series A funds an S3-based security-data layer for historical threat hunting and AI-agent investigations. Here’s what the platform does, what its benchmarks mean and where it fits beside a SIEM.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Scanner announced a $22 million Series A on March 10, 2026, led by Sequoia Capital, with CRV and Mantis VC participating. The San Francisco startup, founded in 2022 by Cliff Crosland and Steven Wu, is building a security-data layer that keeps logs in customer-controlled Amazon S3 buckets, indexes them for fast search, and exposes the data to detection tools and AI agents. SecurityWeek independently reported the financing on March 11, 2026.

The important distinction is that Scanner is not primarily an endpoint scanner or an AI model. It is infrastructure for retaining, searching and investigating large security datasets—especially data that organizations might otherwise move to inexpensive but difficult-to-search object storage.

What Scanner announced

Scanner’s funding announcement is dated March 10, 2026. The round is a $22 million Series A led by Sequoia Capital, with CRV, Mantis VC and angel investors also participating. SecurityWeek reported the round independently the following day.

The company says it will use the capital to expand infrastructure for high-volume security data, historical threat hunting and AI-assisted investigations. A secondary report says engineering, an AI-native search index and agentic security workflows are priorities, but Scanner has not published a detailed dollar-by-dollar use-of-proceeds plan.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

Scanner identifies San Francisco as its base and says it was founded in 2022. Public company materials identify Crosland and Wu as co-founders. The company says security teams at Notion, Ramp and BeyondTrust use the platform; its site also displays references to Ramp, Lemonade and FloQast. These are company-published customer references, not independent audits.

The security-data problem behind the round

Security teams routinely balance ingestion cost, retention, search speed and operational complexity. A conventional SIEM can make recent, high-value telemetry easy to query, but indexing every cloud, identity, application and endpoint event for years can become expensive. Teams may therefore send only selected data to the SIEM and place older or higher-volume logs in object storage.

Scanner describes its origins as a response to that trade-off: rising log-management bills can force a choice between expensive searchable retention and cheaper S3 storage that is slower or more cumbersome to investigate. The resulting gap matters during incidents, when analysts may need months of authentication, cloud or application history rather than only the most recent events. That origin story is the company’s own account, published at Scanner’s technical blog.

What Scanner actually sells

Scanner combines a security-data lake with search, detection and access layers. Its documentation describes raw logs and index files remaining in customer-owned S3 buckets while Scanner supplies the services around them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Collection and enrichment for security logs.
  • Indexed full-text and structured search.
  • Continuous detections and alerting.
  • Detection-as-code workflows, including GitHub-based management.
  • APIs for external tools and programmatic investigations.
  • AI-assisted explanations and investigations.
  • An MCP server for compatible AI agents.
  • An optional integration that lets Splunk query S3-resident logs through the Splunk interface.

A simple representation is: log sources → customer S3 bucket → Scanner indexes and query layer → detections, SIEM, APIs and MCP/AI agents. Scanner presents itself as an alternative or complement to conventional SIEM infrastructure, rather than necessarily a universal replacement.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

How the architecture works

According to Scanner’s architecture documentation, the service builds compact indexes over data stored in S3. Posting lists help locate text terms, while numeric ranges narrow searches on values such as timestamps or ports. A query uses those indexes to reduce the amount of data that must be scanned.

The documented design separates storage from query and indexing compute. Compute can scale for an investigation and scale down when idle, while the underlying logs remain in the customer’s bucket. The documentation lists semi-structured JSON, CSV, Parquet, plaintext and other log formats. Scanner also describes detections that can run continuously on incoming streams as well as searches over historical data.

Deployment options include a managed service and a customer-account model in which compute runs inside the customer’s AWS environment. Keeping data in a customer account can improve control, but it leaves the customer responsible for IAM, bucket policies, encryption, lifecycle rules, backups and regional design.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Where AI fits—and where it does not

Scanner’s MCP and API material positions AI agents as users of the data layer. An agent can submit exploratory searches, inspect results, investigate alerts and call detection or investigation APIs. Natural-language explanations are another stated feature.

This is different from an AI system that independently observes every endpoint and safely responds to incidents. MCP is an access and interoperability protocol; its presence does not prove autonomous detection or response. Agent conclusions still depend on telemetry coverage, field parsing, permissions, prompts, model behavior, detection logic and analyst review. Malicious log content can also create prompt-injection risk, while unrestricted query loops can expose sensitive data or generate unexpected costs.

Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

The company’s central thesis is that AI agents need inexpensive, low-latency, iterative access to large historical datasets. In that sense, the search and storage architecture is the product foundation; the AI layer is a major user of it.

Customer evidence and performance claims

The financing is independently reported, but most product-performance evidence remains first-party. Scanner’s public materials cite the following claims:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Claim How to interpret it
Search 100 TB in under 10 seconds Vendor-reported result; the query, hardware and data layout are not specified in the cited material.
Search petabytes in seconds Marketing positioning, not a universal guarantee for every query.
Up to 700 times faster than Amazon Athena Company benchmark; performance depends on workload and comparison conditions.
Up to 90% lower cost than SIEMs Requires a like-for-like accounting of storage, indexing, compute, egress, integrations and staffing.
More than 80% of recent query activity from AI agents Self-reported LinkedIn statistic; methodology is not provided.
1.4 PiB and 689 billion events indexed in 80 hours Company-reported scale example, not an independent benchmark.

Scanner also says a Ramp customer gained months of searchable history instead of two weeks; that testimonial is carried through secondary company databases and should not be treated as an audited measurement. Faster search can improve hunting only when the organization collected the right telemetry, retained it correctly and has detections or investigative methods capable of using it.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Public pricing and deployment economics

Scanner’s public pricing page shows usage-based charges, but prices and thresholds can change. The page displays a managed provisioned instance at $1,200 per month, provisioned indexing at $0.25 per GB, and on-demand indexing at $0.30 per GB. Provisioned pricing includes 20 TB of querying per 1 TB indexed, with additional tiers shown on the page. Self-hosted pricing is listed as contact sales.

An AWS Marketplace listing shows example 12-month contracts of $30,000 for 100 GB per day and $90,000 for 500 GB per day with 12-month retention. Those are contract examples, not universal list prices, and AWS infrastructure or additional usage charges may apply.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

A buyer should model S3 storage, indexing, query compute, data transfer, support, integrations, detection engineering and any reduction in existing SIEM spend. “Unlimited retention” means the ability to retain data in customer-controlled storage; it does not mean storage, indexing or retrieval is free.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who may benefit from Scanner

  • Organizations already storing substantial security data in S3.
  • Teams whose SIEM costs force short retention, sampling or selective logging.
  • Threat hunters who routinely need months or years of history.
  • AWS-centric companies that want customer-account deployment and data custody.
  • Detection engineers who prefer GitHub-managed rules and CI/CD workflows.
  • Teams experimenting with AI agents but lacking a fast, queryable security-data foundation.

Scanner may be a poor fit for a non-AWS environment, a low-volume operation, or a buyer seeking a turnkey SIEM with mature dashboards, case management, SOAR, UEBA and vendor-managed content. It also requires engineering capacity for pipelines, schemas, cloud permissions and governance.

How it compares with alternatives

Option Primary strength Key comparison with Scanner
Splunk Enterprise Security Mature SIEM and SecOps workflows, content, SOAR and integrations. Scanner can complement Splunk by searching S3-resident history through its integration; replacing an established Splunk program would involve much more than comparing query speed.
Elastic Security Flexible search, observability and security deployment choices. Compare operational burden, indexing economics, cloud-storage integration, detection content and AI functions.
Panther Cloud-focused security analytics and detection engineering. Compare supported sources, query model, deployment, data ownership, AI features and total cost.
Amazon Security Lake and native AWS services AWS-native centralization and security controls. Compare normalization, detection content, query performance, governance and operational effort.
Existing SIEM plus S3 Keep recent, high-value data in the SIEM and archive lower-priority data. Often the most realistic adoption path for Scanner, which adds searchable historical access without discarding existing workflows.

What the funding signals

The round validates investor interest in security-data infrastructure that supports long retention and AI-assisted investigations. It does not, by itself, validate Scanner’s speed, cost or detection-quality claims. The company’s likely priorities are engineering scale, broader integrations and enterprise capabilities, while the exact allocation remains undisclosed.

For prospective customers, the meaningful questions are practical: Can Scanner search the organization’s actual data fast enough? What does a complete AWS and licensing bill look like? Are detections reliable across the team’s formats? Can IAM, audit logging, query limits and human approvals constrain AI agents safely? And can the product coexist with the SIEM, workflows and compliance controls already in place?

The Bottom Line

Bottom line: Scanner’s $22 million Series A supports a clear thesis: AI threat hunting is only useful when security teams can afford to retain and rapidly query the data behind it. Scanner’s S3-based storage and indexing approach could be valuable for historical hunting and hybrid SIEM deployments, but its headline performance and savings figures remain vendor claims. Buyers should validate them on representative workloads and include AWS, governance and engineering costs in the decision.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.