Auguria develops an AI-driven SecOps data management platform centered on its Security Knowledge Layer, a connective layer between SIEMs, security data lakes, XDR tools, and AI assistants. The platform curates and understands security telemetry before downstream analysis, helping teams reduce noise, enrich context, and prioritize the events most relevant to detection and investigation.
Its approach is designed to address the operational and cost pressure created by high-volume log ingestion and fragmented security tooling. Auguria positions the platform as a way to modernize legacy SIEM environments, support open and federated detection architectures, and give analysts faster access to high-confidence signals without extensive rule writing or manual data engineering.
Offerings, Capabilities, and Integrations
Auguria focuses on security telemetry ingestion, normalization, enrichment, prioritization, and routing. It connects to SIEMs, data lakes, XDR platforms, cloud logs, identity signals, and APIs, then filters, aggregates, clusters, and labels data before it reaches higher-cost analytics tiers. The platform also builds environment-aware relationships between entities, behaviors, and timelines so human analysts and AI assistants can work from the same contextual foundation.
Integration flexibility is a central part of the offering. Auguria supports a broad range of vendor data formats, normalizes data to OCSF, and provides no-code workflow tooling for shaping pipelines and directing data to live search, investigation, or long-term retention destinations. It can run in customer-controlled environments or within Auguria-managed infrastructure and is designed to work alongside existing SIEM, XDR, SOAR, and security data lake investments.
Products and Services
- Auguria Security Knowledge Layer (SKL): Flagship platform layer that ingests, enriches, semantically ranks, and links security data across SIEMs, data lakes, XDR, and AI-driven workflows to surface the most relevant signals for SecOps teams.
- AI-Powered Detections: Detection capability that combines rules for known threats with AI-driven identification of novel or unusual activity to improve prioritization and investigative focus.
- Searchable Archive Storage: Low-cost, long-term security data retention with full searchability for compliance, forensics, and historical investigation use cases.
- No-Code ETL connectivity suite: Spreadsheet-inspired data pipeline and workflow tooling for connecting, formatting, transforming, and routing security telemetry without heavy custom engineering.
- Exploratory Visualization: Interactive visualization capability that plots prioritized enrichments and relationships on an ontology-oriented view to support threat hunting and incident analysis.
- Auguria SKL App: Splunk-facing application component that brings Auguria Security Knowledge Layer insights into Splunk environments for security operations workflows.
- Auguria SKL Add-On: Companion integration component for Splunk environments that supports ingestion and operational use of Auguria Security Knowledge Layer outputs, including Splunk Cloud compatibility.
Target Customers
Auguria targets security operations teams that manage large, diverse, and expensive telemetry estates. Typical users include SOC analysts, threat hunters, incident responders, detection engineers, and teams responsible for maintaining SIEM and security data lake pipelines.
Auguria is especially relevant for organizations trying to reduce Splunk or Microsoft Sentinel ingestion costs, retain compliance data in searchable low-cost storage, or build multi-vendor open XDR and data lake architectures without heavy security data engineering overhead. It also fits teams that want to operationalize AI-assisted investigations on top of better-labeled, context-rich security data.
Cloud Integrations and Marketplace
- AWS Marketplace: Auguria Security Data Management Platform is available through AWS Marketplace.
- Amazon S3: Auguria supports direct connection to S3 and can route compliance or lower-priority data to cost-efficient storage while preserving searchability.
- Databricks: Auguria can connect directly to customer Databricks environments as part of customer-managed data processing and analytics workflows.
- Snowflake: Auguria supports direct connection to Snowflake for customer-managed storage and security data operations.
- Splunk Cloud: Auguria SKL App and Auguria SKL Add-On are approved as Splunk Cloud compatible.
Key People
- Jessvin Thomas: CEO
- Chris Coulter: Co-Founder and CTO
- Craig Iannucci: CFO
- Josh Cowling: Head of Product
- Dan Burns: Board Member
- Ryan Permeh: Board Observer
Key Facts
- Headquarters: Ladera Ranch, California, United States
- Employees: 11-50 employees
- Annual Revenue: $1M-$10M (estimated)
- Parent Company: None
- Subsidiaries: None
- Publicly Listed: No