RunReveal

Security OperationsDetection Response acquired

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software.
Founded 2023
Last updated 2026-09-03

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

RunReveal is a SIEM replacement from two former Cloudflare and Segment security and data-engineering leaders that charges for stored data rather than ingested data and folds log pipelines, Sigma and SQL detections, and an autonomous investigation agent into one platform. It connects more than 100 log sources, can run inside a customer's own cloud, and its named customers are technology companies with engineering-led security teams, including Cursor, Sentry, Temporal and ClickHouse. ClickHouse, one of those customers, acquired RunReveal in September 2026 and says the platform and existing contracts continue.

Sourced Details

Description Security data platform that unifies security log ingestion, storage, detection, and response as an alternative to legacy SIEMs, with AI-powered investigation and an autonomous alert-triage agent. [f1]
Acquisition ClickHouse, announced 2026-09-01 [f2]
Founded 2023 [f3]
HQ Austin, TX [f4]
Latest funding Seed, $7M (August 2025) [f4]

Products

Product What it does
RunReveal SIEM and security log platform with more than 100 source integrations, pipelines, Sigma and SQL detections, AI chat with an MCP server, and an autonomous alert-investigation agent.

Matrix Coverage

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

RunReveal runs Sigma and SQL detections over endpoint, cloud workload, SaaS application, network, and identity telemetry, and its agent investigates the resulting alerts in case management. The product uses AI to defend conventional assets and is mapped to the Cyber Defense Matrix.

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 27 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 RunReveal names the security-engineer buyer and puts numbers on the pain, with Sentry's story headlined on $36,000 in annual savings and Cursor's lead describing a bill spike that pulled him into an internal incident. Both examples reach the record through customer stories RunReveal publishes, only the Sentry one carries a figure, and independent reporting stops at SiliconANGLE's account of daily false-positive volume, so the problem is documented rather than independently quantified. [s6, s7, s16, s1]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 4/5 The published surface is wide: a catalogue of over 100 connectors, in-line pipelines that reshape events before storage, detections written as Sigma or SQL, and three deployment shapes including one that runs on the buyer's own Kubernetes. RunReveal publishes pql, its pipelined query language, kawa, the library powering its event-processing daemon, and a public repository named sigmalite, so the query and detection machinery is open to inspection. SiliconANGLE's account of correlated alerting attributes the mechanism to RunReveal, so it relays the vendor's description rather than testing it. [s2, s10, s3, s14, s16]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 SIEM is an established product category, and 2024 coverage placed RunReveal in it as a simpler alternative to the established products, which is third-party category framing rather than evidence of buyer behavior. A database vendor buying the security application built on its engine is a market-structure signal too, and RFP language, analyst category notes, adoption data, and budget-line evidence all stay absent from the reviewed record. [s16, s24, s19, s20]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 Evan Johnson and Alan Braithwaite held senior security and engineering roles at Cloudflare and Segment and publish working open-source tooling. Selling the company to ClickHouse is an outcome on terms neither announcement discloses, and the public record still shows neither founder with an earlier exit or a sustained publication record. [s4, s17, s14, s19, s26]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 Cursor, Sentry, Temporal, ClickHouse, AngelList, and Lumos are named customers with fetchable stories carrying quoted practitioners and concrete outcomes, the blog carries a Harvey story on network threat detection, and the homepage wall adds Linear, DigitalOcean, Baseten, Together AI, Endor Labs, and others as logos. The acquisition converts ClickHouse from a reference into the owner, and the remaining references are all published by RunReveal, so the roster is broad and independent reporting on customer scale is still absent. [s6, s7, s5, s18, s22, s23, s1, s8, s19, s20]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 On two announced seed rounds, $2.5 million in 2024 and $7 million in 2025, RunReveal shipped a platform spanning ingestion to investigation, an autonomous agent, and a Kubernetes deployment. No revenue or margin figure is disclosed and the acquisition price is not stated, so output per dollar stays uncorroborated. [s16, s12, s25, s15, s2, s9, s8, s19]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 4/5 RunReveal calls itself a security data platform and sells against named SIEMs, press labels it a SIEM, and both acquisition accounts describe it in the same terms, so buyers map it to an existing budget line without vendor coaching. The category is established rather than newly defined. [s16, s24, s19, s20, s8]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 Stored log history, configured pipelines, and authored detections create the baseline stickiness of any log platform, and Sentry made RunReveal its primary logging source. ClickHouse's own security team replaced a self-built ingestion architecture with RunReveal, which argues the capability is more than a quick feature release, but storage-based pricing and AI triage stay copyable and bring-your-own-database keeps the data in the customer's cluster, so no structural moat is visible. [s6, s18, s3, s21, s19]
Business Risks ClickHouse could fold RunReveal's capabilities into its own platform and stop selling the security product separately, ending the standalone offering the acquisition announcements describe…
  • ClickHouse could fold RunReveal's capabilities into its own platform and stop selling the security product separately, ending the standalone offering the acquisition announcements describe.
  • Security vendors that build on ClickHouse could move off it, or stop recommending RunReveal, now that the engine vendor sells a security application of its own.
  • Incumbent SIEM vendors could match storage-based pricing in their own offerings, and RunReveal's own comparison posts place Panther in the same modern-SIEM contest, so the differentiation that leads RunReveal's pitch could compress to price.
  • A wide gap sits between the $200 self-serve plan and the five-figure floor of the paid deployments, so buyers whose needs fall in between could find no plan that fits and pick a competitor.
  • Regulated enterprises could keep buying incumbent SIEMs for procurement and certification reasons, capping RunReveal at the cloud-native segment its customer stories show.
  • Bring-your-own-database leaves a customer's log history in a cluster the customer controls, so retention depends on continued price and product advantage rather than on data custody.
Problem & Market RunReveal defines its problem as legacy SIEM economics that punish complete log collection…

RunReveal defines its problem as legacy SIEM economics that punish complete log collection. Its own pitch is that a customer pays for what it keeps rather than what it sends, and the Cursor case study shows the shape of the pain, where turning on logging for one additional account produced a bill spike large enough to open an internal incident.

Independent coverage corroborates the problem beyond vendor marketing. SiliconANGLE reports that erroneous alerts can reach hundreds per day at some companies and positions RunReveal as a simpler alternative to established SIEM products. The buyer persona is specific, security and detection engineers at cloud-native companies, and the customer stories quantify the pain in dollars, such as Sentry's $36,000 in annual savings after switching.

The acquisition restates the same problem from the other end of the stack. ClickHouse describes security as a workload that pushes a database harder than almost anything else, with continuous ingest, retention measured in years, and queries analysts run under time pressure, and says that is why security companies build on its engine. [s7, s3, s16, s6, s19, s1]

Product Capabilities The platform covers the whole SIEM workflow in one product…

The platform covers the whole SIEM workflow in one product. Documentation enumerates more than 100 log source integrations across cloud providers, SaaS applications, and infrastructure, pipelines that filter and route events before storage, Sigma and SQL detections, dashboards, and case-management investigations. ClickHouse provides the storage engine, which RunReveal operates as a hosted service, in the customer's own cloud account, or on any Kubernetes cluster.

The AI layer reaches further than a chat box. RunReveal ships an autonomous security operations agent that investigates alerts, responds to infrastructure changes, and attaches its full query history, tool usage, and reasoning to the case. The native AI chat and MCP server work with the customer's own model choice, including Anthropic, OpenAI, AWS Bedrock, and Google AI.

Open-source code lets outsiders check the capability claims. RunReveal publishes pql, its pipelined query language, kawa, the library powering its event-processing daemon, and a public repository named sigmalite, so anyone can inspect the code. [s10, s2, s3, s9, s11, s14, s19]

Competitive Positioning RunReveal positions head-on against incumbent SIEMs and attacks their pricing unit…

RunReveal positions head-on against incumbent SIEMs and attacks their pricing unit. Its CEO describes legacy platforms such as Splunk as too complicated, too expensive, and too noisy for even sophisticated teams, and the company publishes direct comparison posts against Splunk, Elastic, and Panther.

The modern-SIEM field is the closer contest. RunReveal's own comparison post sets its native pipelines and built-in AI against what it calls Panther's AI SOC platform, and data platforms with security tiers compete for the same log budgets. RunReveal differentiates through storage-based pricing with no ingest fees, pipelines built into the platform so buyers skip a separate data-engineering tool, and AI investigation built into the platform.

Ownership now cuts across that positioning. RunReveal argued that closed-source databases are what let SIEM vendors hold customer data hostage, and it has been bought by the vendor of the open database it named as the alternative. ClickHouse says it stays a neutral base for other companies building security products on its engine, which is the assurance a rival building on ClickHouse would want and the claim to watch. [s17, s8, s3, s21, s20]

Go-to-Market & Traction The named-customer roster spans well-known engineering brands…

The named-customer roster spans well-known engineering brands. Cursor, Sentry, Temporal, ClickHouse, AngelList, and Lumos appear with fetchable case studies linked from the homepage, the blog carries a Harvey story on network threat detection, and the displayed customer wall adds Linear, DigitalOcean, C1, Baseten, Together AI, CyberUp, Weights & Biases, Serval, Surge AI, Endor Labs, and THG as logos without stories. ClickHouse stands out because its security team replaced a self-built ingestion architecture with RunReveal, and because it has since bought the company.

The pricing page shows where the paid motion now sits. The hosted service is quoted at $10k-$150k depending on stored data volume and the customer-cloud deployment at $75k+, with the free Community edition and a $200 Teams plan kept below them as the self-serve entry. The pricing FAQ still advertises free 30-day trials for "Pro and Enterprise", labels that no longer match any plan name on the current pricing page.

Distribution beyond direct selling is still thin in the public record. No reseller program or MSSP channel appears in the reviewed materials, so buyers reach RunReveal through its content, comparison posts, and reputation. The acquisition adds a distribution question rather than an answer. ClickHouse points prospects at their account team for the combined experience, and both announcements otherwise describe continuity of contracts and support without setting out a joint sales motion. [s1, s6, s7, s5, s18, s22, s23, s3, s8, s19, s20]

Team & Credibility The founding pair brings operating history that matches the product exactly…

The founding pair brings operating history that matches the product exactly. Evan Johnson led security at Cloudflare and Segment, and Alan Braithwaite built and maintained the core data pipelines at those same two companies, so the team combines the security and data-engineering disciplines a log platform requires.

Public records support the pedigree. Seed press identifies the founders' background, the company publishes working open-source tools, and Costanoa Ventures led both announced rounds, with Runtime Ventures, Modern Technical Fund, and Okta Ventures joining the $7 million round.

The founders announced the sale themselves and framed it as continuity, saying support for new and existing customers continues and that more about the roadmap follows. Neither announcement states terms, and neither describes what happens to the team's reporting line inside ClickHouse. [s4, s17, s14, s12, s25, s15, s26]

Trust Readiness RunReveal publishes the attestations a log platform needs to clear security review…

RunReveal publishes the attestations a log platform needs to clear security review. The trust page states SOC 2 Type 2 certification along with GDPR and CCPA compliance, and customers can bring their own model provider so the AI features stay inside the buyer's existing governance.

RunReveal extends the trust story through deployment flexibility. The customer-cloud and Kubernetes options keep log data in the customer's own environment, the self-hosted path advertises air-gapped and GovCloud deployment, and bring-your-own-database puts the log history in a ClickHouse cluster the customer runs.

The acquisition puts a new party inside that story. A security-data platform's trust case rests partly on who the vendor is, and the vendor is now a database company rather than an independent startup, with the announcements committing to unchanged contract terms and continued support but not to a separate attestation scope. [s13, s3, s11, s21, s19, s20]

Competitors Splunk, Elastic, Panther…
Company Relationship Note Compare
Splunk competes with Named by RunReveal's CEO as the legacy SIEM that became too complicated and expensive, and the subject of a direct RunReveal comparison post. N/AWe scored these companies at different scopes, so the totals measure different things.
Elastic competes with Subject of a RunReveal comparison post arguing that a good search engine makes a complicated SIEM. N/AWe scored these companies at different scopes, so the totals measure different things.
Panther competes with Modern SIEM and AI SOC platform selling to the same detection-as-code buyer, and the subject of a direct RunReveal comparison post. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.

Add analyzed competitors to compare them side by side with RunReveal.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Exposed 11 /21 Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software. pivot urgently

RunReveal sells software features and gave up on purpose the lock-in other SIEM vendors rely on. Its own announcement called holding customer data hostage a bad competitive advantage, and bring-your-own-database leaves the log history in a ClickHouse cluster the customer runs, so leaving costs integration and detection rework rather than a rebuild. The acquisition does not change that arithmetic, since ClickHouse is open source, the deployment paths are unchanged, and contract terms stand. It changes who benefits from the buyer staying: a customer choosing RunReveal now also chooses its parent's database roadmap. The nearest thing to a compounding asset in evidence is still the normalized integration library, which a funded rival could rebuild.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Customers buy the platform as self-serve software, with a free Community edition and paid plans the customer's own team operates and owns the outcomes for. Managed detections and the investigation agent ship as product content rather than as judgment a vendor signs its name to.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Stored log history, configured pipelines, learned Sigma and SQL detections, and wired integrations create meaningful friction, and Sentry made RunReveal its primary logging source. Bring-your-own-database keeps that history in a ClickHouse cluster the customer runs on an engine the acquisition leaves open, and the cited record does not size what leaving would cost.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 SOC 2 Type 2, GDPR, and CCPA are commercial, table-stakes attestations that ease procurement, and air-gapped and GovCloud deployment are paths toward regulated buyers rather than authorizations. The reviewed record documents no authorization or mandate that would block a determined replacement.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 2/3 Real-time processing of terabyte-scale telemetry, such as Harvey's roughly 8 TB a day, takes serious engineering, and the open-source kawa and pql components show systems depth. The hardest layer, the storage engine, is open-source ClickHouse, which the acquirer says will keep serving as a neutral base for other companies building security products on it.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 Named customers are technology companies from startups to mid-size platforms, engineering-led buyers whose procurement rigor the cited record does not describe. Published pricing now opens at five-figure bands with a six-figure customer-cloud path, which points at larger accounts without naming a regulated or government buyer in the record.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 RunReveal runs as a platform with application features rather than a pure end-user tool, with pipelines feeding storage and an MCP server exposing the data to the customer's AI assistants. The layer whole ecosystems are built on is the database beneath it, which the acquisition puts in the parent's hands rather than RunReveal's.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 Log data belongs to each customer, bring-your-own-database keeps it in a cluster the customer controls, and no cross-customer telemetry advantage is claimed in the cited record. The detection library and normalized schemas are replicable content, and the core engine is open source.
Strategic Market Segmentation RunReveal targets security teams at cloud-native technology companies, and its customer stories describe small teams carrying broad responsibility…

RunReveal targets security teams at cloud-native technology companies, and its customer stories describe small teams carrying broad responsibility. Sentry's detection program ran through a senior engineer who also handled bug bounty triage, and Cursor's security lead describes turning on organization-wide logging as one of his first tasks. The named customers, including Cursor, Sentry, Temporal, ClickHouse, AngelList, and Lumos, fit one profile: technology companies with engineering-led security teams, and the blog puts one of them, Harvey, at roughly 8 TB of network data a day.

The persona is a detection engineer who writes SQL and treats detections as code. Customer stories emphasize code-first detection engineering and onboarding measured in hours, and the docs assume the buyer can route logs through object storage and webhooks without hand-holding.

The segment boundary is visible in what the record lacks, and the price list now marks it. No named customer is a bank, hospital, or government agency, while the published plans run from a free edition through a $200 team plan to hosted deployments quoted at $10k-$150k and a customer-cloud deployment at $75k+. That spread tracks company size inside the technology segment, with air-gapped and GovCloud deployment offered as groundwork for regulated buyers rather than presence among them.

Product Capabilities & AI Advantages The platform spans the whole security-data workflow that buyers otherwise assemble from separate tools…

The platform spans the whole security-data workflow that buyers otherwise assemble from separate tools. Documentation covers a catalogue of more than 100 log sources, pipelines that filter, transform, and enrich events before storage, a ClickHouse-backed data lake, Sigma and SQL detections, dashboards, investigations with case management, and notifications. Temporal's detection lead credits the pipelines with cutting irrelevant log volume, which is the job buyers otherwise hire a dedicated pipeline product to do.

The AI capabilities are concrete rather than decorative. An autonomous security operations agent investigates alerts, responds to infrastructure changes in real time, and attaches its full query history, tool usage, and reasoning to the case, so analysts can audit what it did. The chat and MCP server accept the customer's own model provider, including Anthropic, OpenAI, AWS Bedrock, and Google AI, so the AI features run inside the buyer's existing model relationships.

Open-source releases let outsiders inspect the company's code. The pql pipelined query language, the kawa library powering the event-processing daemon, and a repository named sigmalite are all public on GitHub. SiliconANGLE adds that correlated alerting weighs multiple data points before raising an alert, the company's stated answer to false-positive volume.

Sales Engagement & Go-to-Market RunReveal sells through self-serve adoption backed by founder-led publicity…

RunReveal sells through self-serve adoption backed by founder-led publicity. The free Community edition and the $200 team plan are the published entry points, paid plans carry free 30-day trials, and the founders front the company's public arguments against legacy SIEM pricing in funding announcements and blog posts. For a company at this stage, founders carrying the selling is the appropriate motion rather than a gap.

RunReveal generates demand through customer stories and comparison content. Recognizable engineering brands vouch for the product with named practitioners and concrete outcomes, and posts written against Splunk, Elastic, and Panther target buyers already searching for an exit from their current tool.

Distribution beyond direct self-serve stays thin in public materials, and the acquisition raises the question rather than answering it. No reseller program or MSSP channel appears in the reviewed pages. ClickHouse says the combined experience is something a prospect should ask an account team about, which is an early hint of a shared motion, while both announcements describe existing contracts and support as unchanged and neither describes a joint sales plan.

Pricing Model The pricing unit is the strategy…

The pricing unit is the strategy. RunReveal charges for data stored rather than data ingested, with no ingest fees and no query limits, which removes the exact penalty that made Cursor's one-account logging change a billing incident on its prior SIEM. Buyers who measure their pain in ingestion overage read the unit choice as the fix.

The published tiers now sit well above the self-serve entry. The hosted service carries a $10k-$150k range depending on stored data volume, the customer-cloud deployment starts at $75k+, and the Kubernetes deployment is custom-quoted, with the free Community edition at 20 GB and the $200 team plan at 100 GB kept below them as the self-serve on-ramp. Storage allowance and retention are separate dials: Enterprise advertises 550-day retention by default, which the FAQ defends as what compliance and investigation actually need.

The open margin question is whether cheap storage stays cheap for RunReveal itself. Customers such as Harvey push roughly 8 TB of network data per day, and queries are unlimited rather than metered, so the model depends on query and storage economics staying favorable as volumes grow. Ownership by the database vendor changes where that cost sits without the announcements saying how.

Product Delivery & Operations RunReveal delivers the same platform across three deployment shapes, a hosted service, a deployment into the customer's own AWS, GCP, or Azure account, and a Kubernetes install for on-premises or air-gapped environments, with ClickHouse as the storage engine in each…

RunReveal delivers the same platform across three deployment shapes, a hosted service, a deployment into the customer's own AWS, GCP, or Azure account, and a Kubernetes install for on-premises or air-gapped environments, with ClickHouse as the storage engine in each. The bring-your-own-database path goes further and writes into a ClickHouse cluster the customer already runs, which keeps log custody with the buyer and answers the data-residency objection a hosted SIEM otherwise faces.

Operational simplicity is the recurring customer claim. Sentry made RunReveal its primary logging source for all security data, and Cursor's lead describes delivering logs to object storage as the entire integration effort. The blog shows a steady cadence of platform change, including the Kubernetes deployment and pipeline-level masking of sensitive fields before storage.

The cost of this flexibility is operational surface, and the vendor's own write-up is candid about it. Supporting hosted, customer-cloud, on-premises, and customer-owned-database operation is a heavy commitment, and the bring-your-own-database post enumerates what the team took on: sizing the customer's cluster, staging writes when it goes down, batching inserts, and running schema migrations against infrastructure it does not control.

Earning Customers' Trust RunReveal documents the trust posture a security-data vendor needs…

RunReveal documents the trust posture a security-data vendor needs. The trust page states SOC 2 Type 2 certification along with GDPR and CCPA compliance, which are the attestations that support procurement review for a vendor handling broad security telemetry.

RunReveal builds trust into the architecture as well as the paperwork. The AI chat runs on provider keys the customer adds and the docs say no data leaves the workspace, the customer-cloud and Kubernetes options keep the logs in the customer's own environment, and the agent attaches its complete reasoning to every case so analysts can audit its conclusions. Sentry's engineer calls RunReveal the most transparent vendor he has worked with, praise from exactly the skeptical practitioner the company targets.

A new party now sits inside that posture. The vendor a buyer is trusting with its security telemetry is a database company rather than an independent startup, and the announcements commit to continued support and unchanged contract terms without addressing whether the attestation scope, subprocessor list, or data-handling terms move with the ownership.

Platform Strategy & Ecosystem Positioning RunReveal positions itself as the data layer beneath security operations rather than one tool among many…

RunReveal positions itself as the data layer beneath security operations rather than one tool among many. The platform does the jobs of a log pipeline, a SIEM, and an investigation console, and the MCP server exposes the stored data to whatever AI assistant the customer already uses, which makes RunReveal the substrate other tools query.

RunReveal grows its ecosystem inbound through integrations and outbound through open source. The catalogue of more than 100 sources connects the customer's existing vendors to RunReveal, and engineers can adopt pql and kawa before becoming customers. No partner marketplace or technology-alliance program appears in public materials, so the ecosystem is still code-led rather than business-development-led.

The risk running underneath this platform has now resolved, and not by competition. The engine RunReveal builds on is open source and available to any competitor, ClickHouse included, and rather than shipping a rival security product ClickHouse bought this one. The acquirer now tells other security vendors building on the same engine that it remains a neutral base for them, which is the assurance those vendors need and the claim worth watching.

Team & Execution Capability The founding team matches the problem with unusual precision…

The founding team matches the problem with unusual precision. CEO Evan Johnson previously led security at Cloudflare and Segment, and CTO Alan Braithwaite built and maintained the core data pipelines at those same companies, so the pair has operated both the security function that buys SIEMs and the data infrastructure that makes one work. The about page frames the company as a response to tooling they lived with in those roles.

Execution evidence supports the pedigree. On two announced seed rounds the team shipped a platform spanning ingestion to investigation, an autonomous investigation agent, and a steady release cadence, and Costanoa Ventures led both rounds with Runtime Ventures, Modern Technical Fund, and Okta Ventures joining the later one. Costanoa leading twice is a sign of conviction from the investor with the deepest view of the company.

The founders announced the sale in their own names and framed it as continuity, promising continued support and more about the roadmap at a user conference later in September. Public materials still leave team scale undisclosed, and neither announcement says how the team is organized inside ClickHouse, so the depth behind the founders remains the main execution unknown.

Sources

Company Detail Sources (4)
Id Source Tier Accessed
f1 RunReveal homepage official 2026-06-12
f2 ClickHouse: ClickHouse welcomes RunReveal official 2026-09-03
f3 SEC EDGAR: RunReveal, Inc. Form D signed 2023-03-09, stating year of incorporation 2023 (CIK 0001968741) regulatory 2026-09-03
f4 FinSMEs on the RunReveal $7M seed round press 2026-06-12
Profile Analysis Sources (26)
Id Source Tier Accessed
s1 RunReveal: Homepage
“RunReveal unifies your security data management with AI-powered detection and response. From ingestion through investigation, get complete visibility without the complexity or cost of legacy SIEMs.”
official 2026-09-03
s2 RunReveal: Docs introduction
“Built on ClickHouse so you retain full control of your data. Deploy in our cloud, your cloud, or on-prem—without sacrificing query performance.”
official 2026-09-03
s3 RunReveal: Pricing page
“Only pay for the data you store. No ingest fees. No query limits. No surprises.”
official 2026-09-03
s4 RunReveal: About page
“Evan and Alan spent years in security and data engineering at Cloudflare and Segment.”
official 2026-09-03
s5 RunReveal: Temporal customer story
“Data collection isn't the goal, detection is. Pipelines let us enrich what we need and cut what we don't, so we're not buried under terabytes of irrelevant logs.”
official 2026-09-03
s6 RunReveal: Sentry customer story
“How Sentry Transformed Detection Engineering While Saving $36,000 Annually”
official 2026-09-03
s7 RunReveal: Cursor customer story
“I can add a new [source], write the detection, read queries, find the data that I want, and wire it up to get alerts for it, all within an hour or two.”
official 2026-09-03
s8 RunReveal: Blog index
“RunReveal is joining ClickHouse”
official 2026-09-03
s9 RunReveal: Autonomous security operations agent announcement
“The agent's full query history, tool usage and reasoning is attached to the case.”
official 2026-09-03
s10 RunReveal: Log sources docs
“Connect your security logs and events from cloud providers, SaaS applications, and infrastructure to RunReveal's security data platform. Search by name or description, and filter by ingest method, category, or plan.”
official 2026-09-03
s11 RunReveal: AI chat and MCP docs
“The Model Context Protocol (MCP) allows you to connect AI assistants like Claude and Cursor to external data sources and tools.”
official 2026-09-03
s12 SEC EDGAR: RunReveal, Inc. Form D signed 2023-03-09 (CIK 0001968741)
“X Within Last Five Years (Specify Year) 2023”
regulatory 2026-09-03
s13 RunReveal: Trust and security page
“SOC 2 Type 2: We are fully SOC2 Type 2 certified.”
official 2026-09-03
s14 RunReveal: GitHub organization
“A blazingly fast event stream processing library powering the reveald event processing daemon.”
official 2026-09-03
s15 Return on Security: Security, Funded #205, week of 28 July 2025
“RunReveal, a United States-based security analytics and observability platform, raised a $7.0M Seed from Costanoa Ventures.”
press 2026-09-03
s16 SiliconANGLE: SIEM startup RunReveal reels in $2.5M to reduce cybersecurity false positives
“Cybersecurity startup RunReveal Inc. today launched its first product into general availability and disclosed the completion of a $2.5 million seed round.”
press 2026-09-03
s17 Yahoo Finance: RunReveal general-availability and seed release carried from GlobeNewswire
“Legacy SIEM platforms like Splunk have become too complicated, too expensive and too noisy for even the most sophisticated security teams to operate”
press 2026-09-03
s18 RunReveal: ClickHouse customer story
“ClickHouse leverages their own database technology with RunReveal to replace complex Lambda ETL pipelines and build a scalable SIEM with fast detection capabilities.”
official 2026-09-03
s19 ClickHouse: ClickHouse welcomes RunReveal
“RunReveal remains available, via its bring-your-own-database model, where security data lives in a ClickHouse cluster you control.”
official 2026-09-03
s20 ITBrief: ClickHouse buys RunReveal to boost security analytics
“ClickHouse has acquired security platform RunReveal, bringing a company built on its technology into the database group.”
press 2026-09-03
s21 RunReveal: Bring Your Own Database announcement
“The problem with SIEM is closed source databases and data-hoarding. Take control of your security data.”
official 2026-09-03
s22 RunReveal: AngelList customer story
“How AngelList is Automating Detection with RunReveal | Customer Stories”
official 2026-09-03
s23 RunReveal: Lumos customer story
“How Lumos Built an AI-Native Security Team with RunReveal | Customer Stories”
official 2026-09-03
s24 Pulse 2.0: RunReveal raises $2.5 million
“SIEM) built to detect threats faster, announced general availability and a $2.5 million seed round led by Costanoa Ventures.”
press 2026-09-03
s25 RunReveal: $7M seed round announcement
“Today we're announcing that RunReveal has raised $7 million in seed funding led by existing investor Costanoa Ventures, with new participation from Runtime Ventures, Modern Technical Fund, Okta Ventures, and several angel investors.”
official 2026-09-03
s26 RunReveal: RunReveal is joining ClickHouse
“We're excited to announce that RunReveal is joining ClickHouse! We built RunReveal on ClickHouse from day one because it was the only database that gave us the reliability, scalability, and performance we needed to help security teams solve their data problems.”
official 2026-09-03
Deep-Dive Sources (26)
Id Source Tier Accessed
s1 RunReveal: Homepage
“RunReveal unifies your security data management with AI-powered detection and response. From ingestion through investigation, get complete visibility without the complexity or cost of legacy SIEMs.”
official 2026-09-03
s2 RunReveal: Docs introduction
“Built on ClickHouse so you retain full control of your data. Deploy in our cloud, your cloud, or on-prem—without sacrificing query performance.”
official 2026-09-03
s3 RunReveal: Pricing page
“Only pay for the data you store. No ingest fees. No query limits. No surprises.”
official 2026-09-03
s4 RunReveal: About page
“Evan and Alan spent years in security and data engineering at Cloudflare and Segment.”
official 2026-09-03
s5 RunReveal: Temporal customer story
“Data collection isn't the goal, detection is. Pipelines let us enrich what we need and cut what we don't, so we're not buried under terabytes of irrelevant logs.”
official 2026-09-03
s6 RunReveal: Sentry customer story
“How Sentry Transformed Detection Engineering While Saving $36,000 Annually”
official 2026-09-03
s7 RunReveal: Cursor customer story
“I can add a new [source], write the detection, read queries, find the data that I want, and wire it up to get alerts for it, all within an hour or two.”
official 2026-09-03
s8 RunReveal: Blog index
“RunReveal is joining ClickHouse”
official 2026-09-03
s9 RunReveal: Autonomous security operations agent announcement
“The agent's full query history, tool usage and reasoning is attached to the case.”
official 2026-09-03
s10 RunReveal: Log sources docs
“Connect your security logs and events from cloud providers, SaaS applications, and infrastructure to RunReveal's security data platform. Search by name or description, and filter by ingest method, category, or plan.”
official 2026-09-03
s11 RunReveal: AI chat and MCP docs
“The Model Context Protocol (MCP) allows you to connect AI assistants like Claude and Cursor to external data sources and tools.”
official 2026-09-03
s12 SEC EDGAR: RunReveal, Inc. Form D signed 2023-03-09 (CIK 0001968741)
“X Within Last Five Years (Specify Year) 2023”
regulatory 2026-09-03
s13 RunReveal: Trust and security page
“SOC 2 Type 2: We are fully SOC2 Type 2 certified.”
official 2026-09-03
s14 RunReveal: GitHub organization
“A blazingly fast event stream processing library powering the reveald event processing daemon.”
official 2026-09-03
s15 Return on Security: Security, Funded #205, week of 28 July 2025
“RunReveal, a United States-based security analytics and observability platform, raised a $7.0M Seed from Costanoa Ventures.”
press 2026-09-03
s16 SiliconANGLE: SIEM startup RunReveal reels in $2.5M to reduce cybersecurity false positives
“Cybersecurity startup RunReveal Inc. today launched its first product into general availability and disclosed the completion of a $2.5 million seed round.”
press 2026-09-03
s17 Yahoo Finance: RunReveal general-availability and seed release carried from GlobeNewswire
“Legacy SIEM platforms like Splunk have become too complicated, too expensive and too noisy for even the most sophisticated security teams to operate”
press 2026-09-03
s18 RunReveal: ClickHouse customer story
“ClickHouse leverages their own database technology with RunReveal to replace complex Lambda ETL pipelines and build a scalable SIEM with fast detection capabilities.”
official 2026-09-03
s19 ClickHouse: ClickHouse welcomes RunReveal
“RunReveal remains available, via its bring-your-own-database model, where security data lives in a ClickHouse cluster you control.”
official 2026-09-03
s20 ITBrief: ClickHouse buys RunReveal to boost security analytics
“ClickHouse has acquired security platform RunReveal, bringing a company built on its technology into the database group.”
press 2026-09-03
s21 RunReveal: Bring Your Own Database announcement
“The problem with SIEM is closed source databases and data-hoarding. Take control of your security data.”
official 2026-09-03
s22 RunReveal: AngelList customer story
“How AngelList is Automating Detection with RunReveal | Customer Stories”
official 2026-09-03
s23 RunReveal: Lumos customer story
“How Lumos Built an AI-Native Security Team with RunReveal | Customer Stories”
official 2026-09-03
s24 Pulse 2.0: RunReveal raises $2.5 million
“SIEM) built to detect threats faster, announced general availability and a $2.5 million seed round led by Costanoa Ventures.”
press 2026-09-03
s25 RunReveal: $7M seed round announcement
“Today we're announcing that RunReveal has raised $7 million in seed funding led by existing investor Costanoa Ventures, with new participation from Runtime Ventures, Modern Technical Fund, Okta Ventures, and several angel investors.”
official 2026-09-03
s26 RunReveal: RunReveal is joining ClickHouse
“We're excited to announce that RunReveal is joining ClickHouse! We built RunReveal on ClickHouse from day one because it was the only database that gave us the reliability, scalability, and performance we needed to help security teams solve their data problems.”
official 2026-09-03

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.