The security data lake platform built for AI agents and modern security teams. Search and detect across petabytes in seconds. Retain everything forever. Power the next generation of detection & response.
Traditional SIEMs break at cloud scale. Modern cloud infrastructure generates more data than legacy tools can handle. The result:
Your Queries Get Slower
As your data grows, query times balloon from seconds to minutes - and then to hours. When every second counts during an incident, waiting isn't an option.
You're Forced to Drop Data
Retention windows shrink to days or weeks. Logs get sampled. The choice between visibility and cost creates blind spots attackers exploit.
Your AI Tools Can't Run
AI needs complete historical context to work effectively. Slow queries and limited retention mean your security copilots sit idle or timeout.
Scanner unlocks the power of your security data - A cloud-native security data lake that never slows down, never drops data, and gives you complete control.
Highlights
Collect & Enrich: Build your security data lake in an afternoon with schema-less ingestion from any source.
- Enrich logs with threat intel, custom transformations, and lookup tables
- Data stays in your S3 buckets - you own it, no vendor lock-in
Search & Investigate: Lightning-fast full-text search across petabytes. 100x faster than Athena.
- Find IP addresses, file hashes, or suspicious patterns in under 10 seconds
- Search years of historical logs as fast as yesterday's data
Detections & Response: Streaming query engine that continuously evaluates rules - alerting in minutes.
- 400+ out-of-the-box rules covering 40+ log sources and MITRE ATT&CK
- Manage and customize rules in GitHub, deploy through CI/CD
MCP & APIs: First security data lake with native Model Context Protocol support.
- API-first architecture for AI agents and automation tools
- Turn your logs into endpoints for programmatic access
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
Pricing scales by the volume of log data you process each day, with three contract tiers based on daily throughput. The 100 GB Per Day tier runs on a multi-tenant instance with 12-month retention and 100 detection rules. The 500 GB Per Day tier gives you a single-tenant instance with the same retention and rule count. The 5 TB Per Day tier deploys within your own cloud account and includes unlimited detection rules with 12-month retention. If you exceed your contracted volume, additional usage is billed as defined by your contract.
Top-of-mind questions for buyers
What does the daily volume unit measure, and how is my log data counted?
Each tier caps the volume of log data you index per day, measured in gigabytes or terabytes. Scanner indexes logs stored in your own object storage or pulled from connected sources. Index files add roughly 15% storage overhead and stay in your buckets. Counting is based on daily ingested log volume, not rule count.
What happens to my bill if my daily log volume exceeds the contracted tier?
Additional usage beyond your contracted daily volume is billed as defined by your contract. Adding detection rules does not raise cost, since all rules share the same indexing pass. Cost scales with log volume, not the number of rules you run.
How do the deployment models differ across the tiers, and what does each mean for me?
The 100 GB tier uses a multi-tenant instance sharing infrastructure with other customers. The 500 GB tier gives you a single-tenant instance with dedicated resources. The 5 TB tier is Bring-Your-Own-Cloud, running Scanner compute inside your own AWS account, so data and processing stay under your control.
docs.scanner.dev+2
Helpful?
Vendor refund policy
In the event of a termination by Customer pursuant, Scanner will refund to Customer a pro rata share of any unused amounts prepaid by Customer under the applicable Quote for the Services on the basis of the remaining portion of the current subscription term (a Pro Rated Refund). Scanner will issue the Pro Rated Refund directly to Customer. In the event Scanner terminates this Agreement, Customer shall be required to pay through the remainder of the term indicated in the Quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Each Scanner customer receives support via a private Slack channel. Support is also available via email to the customer's account team or via support@scanner.dev.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Cycode is the only AppSec and Posture Management (ASPM) platform that provides visibility, prioritization, & remediation for Sec, Dev, & Ops teams to secure applications from code to cloud.
Rezilion automatically detects, prioritizes and remediates software vulnerabilities across cloud or on-prem infrastructure and applications. Rezilion leverages its Dynamic SBOM to eliminate 85% of patching work and cut backlogs from months to days, giving developers time back to build.
Checkmarx One helps you deliver secure software faster with an integrated Application Security Testing platform deployed as a service. A single event, like a code commit or build stage, can trigger scans of your source code, dependencies, and IaC templates, with results aggregated in one place.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.