Who RunReveal is

RunReveal is a security data platform. It ingests logs from more than 100 sources, stores them in ClickHouse for fast SQL queries, and handles detections, alert routing, and AI-assisted investigation in one place.

Two design choices matter for our clients. Detections are code, written as Sigma rules or SQL and managed in version control. And pricing is based on stored data instead of ingest volume, which changes the economics of monitoring for smaller companies.

How we use it

Most growing companies own plenty of logs and watch none of them. We run detection and monitoring on RunReveal to close that gap.

  • Pipeline setup: logs from your identity provider, endpoints, cloud accounts, and SaaS tools flowing into one queryable store
  • Detections as code: Sigma and SQL detections written for your environment, reviewed and versioned like the rest of your infrastructure
  • Alert routing: findings sent where your team already works, in Slack, PagerDuty, or your ticketing system
  • Investigation: when an alert fires, we investigate it, and the query history shows exactly what we looked at
  • Tuning: noisy rules fixed instead of muted, so alerts stay worth reading

Traditional SIEM pricing punishes you for collecting logs. Storage-based pricing means we can watch everything that matters at a cost a fifty-person company can justify.

Our own logs live there

Amomitto's internal telemetry runs through RunReveal: identity events, endpoint activity, and the audit logs from the tools we manage. The detections we write for clients start from patterns we already run against our own environment.

Related Services

Where RunReveal fits in our work

Collecting logs nobody reads?

Talk to us about detection and monitoring run on RunReveal.

Book a Call