Skip to main content

PADAS

We help organizations turn security data in motion into governed context they own.

Schedule Demo

Motion shapes the data. Chronos builds the context.

Padas Motion streams, routes, detects on, enriches, and controls telemetry across the SOC. Padas Chronos (preview) is designed to turn processed telemetry into governed context and memory for analysts, playbooks, and AI agents.

Governed context means customer-owned context with provenance, control, and decision boundaries.

Padas Motion

Shape security data before it reaches downstream tools.

Padas Motion

Shape security data before it reaches downstream tools.

Padas Motion filters, normalizes, detects on, enriches, and routes telemetry in real time, reducing downstream noise while preserving control over detection logic and data flow.

Stream, Route, and Control

Ingest from syslog, HTTP, Kafka, files, and more, then fan out to SIEM, S3, Kafka, or any HTTP target. No single broker required; Motion keeps control of data flow across the SOC.

SyslogKafkaHTTPS3Splunk
Learn More

Detect and Enrich on the Stream

Run PDL-based detection and transformation directly on the stream: filter noise, normalize events to any target schema (OCSF, OpenTelemetry, or your own), and emit alerts before data reaches your SIEM or data lake.

PDLSchema-on-ReadMITRE ATT&CK
Learn More

Built for Security Telemetry Rates

Padas Motion is designed for the sustained event rates common in security telemetry. Throughput scales with pipeline complexity and hardware: from simple routing to windowed aggregation over high-cardinality fields.

Stream ProcessingWALREST API
Learn More

How Motion Works

Connectors, streams, and PDL tasks compose pipelines that shape security data before it reaches downstream tools.


  1. Motion Capabilities

    1. Key Features & Benefits
      1. Stream-Native Processing

        Filter, transform, enrich, and aggregate every event inline, with no separate query engine.

      2. Inline Detection

        Run PDL detection on the normalized stream and alert before data reaches storage.

      3. Schema-on-Read Normalization

        Map vendor fields to OCSF, OpenTelemetry, or your own schema, with no rigid ingest contract.

      4. Reduced SIEM Load

        Dedupe and route only what matters, cutting SIEM ingest, storage, and analyst noise.

    2. Integration & Flexibility
      1. Broad Connector Coverage

        Sources and sinks for Syslog, Kafka, HTTP, files, Splunk HEC, and S3-compatible storage.

      2. Multi-Sink Fan-Out

        One stream, many sinks: alert your SIEM and archive raw events in parallel.

      3. Vendor-Agnostic Delivery

        Ship to Splunk, Elastic, Kafka, S3, or any HTTP target via open formats.

    3. Future-Proofing & Adaptability
      1. Purpose-Built PDL

        Filtering, regex/grok, lookups, windowed aggregation, and routing, versioned independently.

      2. REST API Control Plane

        Manage streams, tasks, and connectors with Prometheus metrics for full operational visibility.

      3. Extensible Context Path

        Lookup enrichment today; Padas Chronos (preview) is designed to turn processed telemetry into governed context and memory.

    4. Professional Support & Services
      1. Technical Support

        Production support for Motion Engine and Padas UI, covering tuning, PDL debugging, and upgrade advisories.

      2. Professional Services

        Architecture, deployment, and operations consulting for production-ready clusters.

Preview

Turn processed telemetry into security context and memory.

Padas Chronos is being built to connect security events to entities, evidence, behavior, history, and prior decisions, creating governed context that analysts, playbooks, and AI agents can use. Available to design partners ahead of general release.

  • Preview

    Entity context

    Resolve who or what an event is really about.

  • Preview

    Governed assertions

    Provenance-backed, time-aware security facts.

  • Preview

    Investigation memory

    Reusable context and decision traces from prior SOC work.

  • Preview

    Context Packets

    Analyst-ready and AI-ready bundles of context, evidence, history, confidence, and gaps.

  • Preview

    Security memory

    Context that compounds across cases, playbooks, and future investigations.

  • Preview

    Context APIs

    Governed access for analysts, SOAR workflows, and AI agents.

Padas Chronos is a preview product line. Capabilities described here are in development and available to design partners; general availability has not been announced.

Pricing

Motion prices the nodes. Not the gigabytes.

Licensed per node. Your bill follows deployment size, not data volume. Volume spikes do not change what you pay.

01 / 02

Three plans. Differ by cores and pipelines.

Get started

Community

Free

1 core. 2 pipelines. Forever free

  • Full Motion stream capability
  • Community support
Start free
For regulated teams

Enterprise

Contact sales

Larger deployments. Annual commitment

  • SSO. Role-based access control. Audit controls
  • Enterprise Support with SLA
  • Self-hosted and air-gapped options
  • Advanced detection: correlation, replay, detection-as-code
Talk to sales

Chronos is a Preview module. Packaging and commercial terms publish with GA.

Built for Security Practitioners, by Security Engineers

Our Vision

Security teams that own their security context will operate faster, make better decisions, and control how AI participates in security operations. We envision a path from security data in motion to governed context, so SOCs detect, decide, and act from context they own.

Data in Motion
Governed Context