Community
Free
1 core. 2 pipelines. Forever free
- Full Motion stream capability
- Community support
We help organizations turn security data in motion into governed context they own.
Padas Motion streams, routes, detects on, enriches, and controls telemetry across the SOC. Padas Chronos (preview) is designed to turn processed telemetry into governed context and memory for analysts, playbooks, and AI agents.
Governed context means customer-owned context with provenance, control, and decision boundaries.
Shapes security data in motion
Padas Motion is the security data operations product line for streaming, routing, detecting on, enriching, and controlling telemetry across the SOC.
Explore MotionBuilds governed context and memory
Padas Chronos is the preview security context and memory product line for entity context, governed assertions, investigation memory, and AI-ready Context Packets.
See ChronosPadas Motion filters, normalizes, detects on, enriches, and routes telemetry in real time, reducing downstream noise while preserving control over detection logic and data flow.
Ingest from syslog, HTTP, Kafka, files, and more, then fan out to SIEM, S3, Kafka, or any HTTP target. No single broker required; Motion keeps control of data flow across the SOC.
Run PDL-based detection and transformation directly on the stream: filter noise, normalize events to any target schema (OCSF, OpenTelemetry, or your own), and emit alerts before data reaches your SIEM or data lake.
Padas Motion is designed for the sustained event rates common in security telemetry. Throughput scales with pipeline complexity and hardware: from simple routing to windowed aggregation over high-cardinality fields.
Connectors, streams, and PDL tasks compose pipelines that shape security data before it reaches downstream tools.
Filter, transform, enrich, and aggregate every event inline, with no separate query engine.
Run PDL detection on the normalized stream and alert before data reaches storage.
Map vendor fields to OCSF, OpenTelemetry, or your own schema, with no rigid ingest contract.
Dedupe and route only what matters, cutting SIEM ingest, storage, and analyst noise.
Sources and sinks for Syslog, Kafka, HTTP, files, Splunk HEC, and S3-compatible storage.
One stream, many sinks: alert your SIEM and archive raw events in parallel.
Ship to Splunk, Elastic, Kafka, S3, or any HTTP target via open formats.
Filtering, regex/grok, lookups, windowed aggregation, and routing, versioned independently.
Manage streams, tasks, and connectors with Prometheus metrics for full operational visibility.
Lookup enrichment today; Padas Chronos (preview) is designed to turn processed telemetry into governed context and memory.
Production support for Motion Engine and Padas UI, covering tuning, PDL debugging, and upgrade advisories.
Architecture, deployment, and operations consulting for production-ready clusters.
Padas Chronos is being built to connect security events to entities, evidence, behavior, history, and prior decisions, creating governed context that analysts, playbooks, and AI agents can use. Available to design partners ahead of general release.
Resolve who or what an event is really about.
Provenance-backed, time-aware security facts.
Reusable context and decision traces from prior SOC work.
Analyst-ready and AI-ready bundles of context, evidence, history, confidence, and gaps.
Context that compounds across cases, playbooks, and future investigations.
Governed access for analysts, SOAR workflows, and AI agents.
Padas Chronos is a preview product line. Capabilities described here are in development and available to design partners; general availability has not been announced.
Putting it together
Pricing
Licensed per node. Your bill follows deployment size, not data volume. Volume spikes do not change what you pay.
Chronos is a Preview module. Packaging and commercial terms publish with GA.
Security teams that own their security context will operate faster, make better decisions, and control how AI participates in security operations. We envision a path from security data in motion to governed context, so SOCs detect, decide, and act from context they own.