DataBahn Adds Federated Search So Security Teams Stop Copying Data to Find It
Data Engineering

DataBahn Adds Federated Search So Security Teams Stop Copying Data to Find It

Weeks after closing a $40 million Series B, DataBahn launched federated search and orchestration that lets security teams query fragmented telemetry in place instead of centralizing it first.

PublishedAugust 6, 2026
Read time6 min read
Share

The problem enterprises built for themselves

DataBahn announced Federated Search and Orchestration on August 5, timed to Black Hat USA 2026, extending what it calls its agentic data control plane. The capability lets security teams search across distributed data sources, SIEMs, data lakes, cloud storage, and cold archives, without moving or duplicating the underlying data first. Chief Product Officer Aditya Sundararam described the goal directly: security teams and AI agents can now search data across every source, retrieve answers grounded in enterprise context, and turn those answers into completed investigations without switching consoles along the way.

The situation DataBahn is selling against is one enterprises largely built for themselves over the last several years. Cost pressure pushed security teams to tier their telemetry across cheaper storage layers, cold archives for old logs, data lakes for medium-term retention, SIEMs for hot data that needs to be queried instantly. That saved real money on storage, but it fragmented the data landscape into separate consoles and query languages that do not talk to each other, so an investigation that should take minutes now routinely stretches into days of manual correlation.

What actually shipped

Three components carry the announcement. Reef is a live knowledge graph that enriches search results with environment context as data changes, rather than requiring a static index rebuild every time something moves. Lumen is a threat-hunting agent that produces cited timelines, meaning its output points back to the specific source records it drew from rather than presenting an unverifiable narrative summary an analyst has to take on faith. An MCP Hub acts as a governed gateway controlling which AI agents can reach which systems, addressing the access control question the moment any agent gets search privileges across sensitive telemetry.

DataBahn also cites a 40 to 70 percent reduction in telemetry volume across more than 600 integrations, a figure that predates this specific launch but frames the company's broader pitch clearly: reduce what has to be stored and searched in the first place, then make what remains searchable without ever having to move it again. Federated search is the second half of that equation finally shipping to customers who have been waiting for it since the volume reduction claims first appeared.

Fast follow-through on fresh capital

DataBahn closed a $40 million Series B in July, led by Insight Partners, on the argument that telemetry routing is infrastructure rather than a feature bolted onto a SIEM as an afterthought. Shipping a substantial new capability within weeks of closing that round is a meaningful signal in a funding environment where investors increasingly want proof that capital translates into shipped product quickly, not just headcount growth and a longer roadmap slide for the next board meeting.

It also sharpens the company's positioning against SIEM vendors and observability platforms that treat search as native to their own walled garden by default. DataBahn's bet is that no single vendor will ever hold all of an enterprise's security telemetry, so the value sits in the layer that can search across all of them regardless of where each source lives today or gets moved to tomorrow. That is a credible bet in a market where multi-vendor telemetry sprawl is the norm rather than the exception most vendors still design around.

Governance is the feature, not an afterthought

The MCP Hub detail deserves more attention than a typical product bullet point usually gets in a launch announcement. As AI agents gain search access across an enterprise's full telemetry estate, the access control layer determining which agent can query which source becomes the actual security boundary, arguably more consequential to the buyer than the search feature itself. Building that gateway into the launch rather than treating it as a follow-on release suggests DataBahn is anticipating the exact objection security buyers will raise first in any evaluation.

That sequencing matters because agent access control is precisely where competing telemetry and observability vendors have been slower to ship anything concrete. A federated search capability without a governed access layer is a liability rather than a feature for any security team asked to approve AI agents touching production log data at scale. Vendors that ship the guardrail alongside the capability, instead of after a customer explicitly asks for it, hold a real advantage in enterprise security procurement cycles that increasingly start with the access control question first.

What this means for security and data leaders

For CISOs and data leaders managing tiered telemetry architectures, this launch is a good reason to revisit whether the cost savings from storage tiering are being quietly offset by investigation time lost to fragmentation across consoles. If mean time to investigate has crept up since the last time storage was re-tiered purely for cost reasons, a federated search layer may pay for itself faster than another round of storage consolidation ever would.

The broader signal for data architecture generally is that search-in-place is becoming the default answer to sprawl, replacing the older instinct to centralize everything into one lake or warehouse before anyone can query it. That approach only works if the search layer is genuinely federated and genuinely governed end to end, which is why the access control component of this launch deserves as much scrutiny in any bake-off as the raw search quality itself does.

A Black Hat launch aimed squarely at buyers, not researchers

Timing the announcement to Black Hat USA 2026 rather than a standalone launch event is itself a signal worth reading. Black Hat draws the exact security operations leaders who own the tiered telemetry architectures this product targets, and DataBahn is using the conference to put a concrete capability, not a roadmap slide, in front of buyers who are already frustrated with fragmented investigation tooling. That is a more direct sales motion than the usual vendor pattern of announcing broadly and demoing narrowly months later.

It also puts pressure on competing telemetry pipeline and SIEM vendors attending the same conference to respond quickly or risk ceding the federated search narrative entirely. Enterprises evaluating telemetry architecture changes this quarter now have a concrete reference point to hold every other vendor's roadmap promises against, and vendors without a comparable governed search capability already shipping will have a harder time making the case that their own plans are further along than DataBahn's working product.

Tagged#news#data#data-engineering#databases#analytics#lakehouse#streaming#databahn#federated-search#agentic-data-control-plane#black-hat-2026#security-operations#mcp#threat-hunting