Profile / 09.30.26
● BATUTA / ENDPOINT INTELLIGENCE / 50+ ENTERPRISES REPORTED IN 2024 / THE QUESTION: IS YOUR SECURITY REALLY THERE?

Company profile / Cybersecurity

The Security Tool That Asked a Rude Question

Your company bought the protection. Is it actually running on every machine? Batuta built a business around answering that awkward question, then making the answer better.

The most embarrassing thing about a security tool is discovering that it is missing. A company can have a contract, a dashboard, a renewal date and a reassuringly large invoice. None of those will tell it whether the tool is running on the laptop that just walked out of an airport lounge. That small gap between purchase and protection is where Batuta has chosen to live.

The short version

  • What it does: Batuta measures endpoint security posture, checks technology coverage and helps teams fix vulnerabilities and configuration gaps.
  • Who uses it: Enterprise IT and security teams, plus managed security partners. The company reported more than 50 enterprise customers in 2024.
  • Why it exists: Its founders kept encountering organizations with capable tools and no single reliable answer about what was protected.
  • What it costs: Batuta sells through demos and custom quotes; it publishes no standard price.

An endpoint is any device at the edge of a business network: a workstation, laptop or server, the places where people work and where many attacks eventually land. Batuta collects information from those machines and from the security products meant to defend them. It can show whether protection is deployed and active, which software is vulnerable, which settings are weak and which devices deserve attention first. Then it lets the team act: deploy software, harden settings, run response playbooks and produce a record of what changed.

The first failure was the handoff

Mauricio Benavides and Louise Ireland launched the business as Metabase Q. Company listings date its founding to 2019; Benavides describes starting the operating team in 2020. Their early work put specialists beside customers during security incidents. The pattern they saw was dispiritingly ordinary. One tool held the device list. Another held vulnerability findings. A third detected threats. The people responsible for safety had to decide what mattered while those systems argued, silently, about the facts.

The founders did not claim that every security product had failed. The first thing to fail was the handoff between products and the people operating them. Existing tools could be excellent at their assigned jobs and still leave a security chief unable to answer a basic question: which devices are missing protection right now? After the same problem appeared across customers, the team built Batuta to put endpoint facts, tool status and action in one place. That repeated encounter, more than an abstract product thesis, changed their minds about what to build.

“We orchestrated the replacement of a critical tool across 1,200 endpoints in a single day.”Customer account published by Batuta; independently unverified

The name is a little theatrical. Batuta means conductor’s baton in Spanish. A baton makes no sound itself; it helps players keep time. The metaphor works when the orchestra contains endpoint detection, patching, vulnerability scanning and human analysts who all need to perform at once. In May 2025, Metabase Q adopted the product’s name for the company. That is a rare corporate rename with an operational clue inside it.

Five verbs, one machine at a time

Batuta describes its platform as endpoint security posture management, or ESPM. Its loop is plain enough to fit on a wall: configure a standard image, detect vulnerable software, harden settings, contain incidents and report the resulting posture. The point of the final step is not decorative compliance. If a team cannot show that a patch landed or a protection agent is still talking to its console, a green tick is only a hopeful drawing.

The loop matters because the fifth step becomes the starting measurement for the next pass.

In practice, a security team might first find laptops whose endpoint detection agent is absent or disconnected. It can sort the list by exposure, install or repair the agent, and check again. The same view can surface old software, weak configurations or an unexpectedly popular browser extension. Batuta’s June 2026 update expanded inventory to extensions across Chrome, Edge, Brave, Opera, Vivaldi and Firefox. That is the kind of unglamorous detail a breach investigation tends to make interesting in hindsight.

Batuta endpoint security dashboard showing device inventory and technology coverage
Every dot on the map wants a receipt. A Batuta dashboard image released with the company’s 2024 funding announcement; its figures are illustrative of the interface, not current deployment totals.

The platform is one half of the business. Batuta also sells specialists and operations: managed security platform administration, managed detection and response, and a security operations center service. Its SOC To-Go feature routes selected alerts and approval steps through Telegram. A team that wants its own analysts in charge can use the platform directly; one short on staff can buy a managed operation around it. Managed security service providers can also use the platform to scale their own delivery. The company’s sales path is a conversation, demo and quote, so its per-device or service pricing cannot be compared from a public price sheet.

The expensive part was already paid for

Batuta’s pitch depends on a subtle distinction. Many competitors sell the first protective layer: endpoint detection products, vulnerability scanners, patch managers, device management consoles. Batuta sells a view across those layers and a way to operate them together. It lists integrations and services around tools including CrowdStrike, Qualys, Tenable, Automox and Microsoft Defender. Those are examples of products it can work with, not evidence that their makers jointly developed Batuta.

That positioning gives the company a useful economic question. If a business pays for 10,000 licenses but only 9,000 devices are covered, the missing thousand are a risk and the count is a budget problem. If the opposite is true and unused licenses pile up, the finance chief has a different reason to listen. Batuta can inventory coverage and help identify redundancy. The savings, like the risk reduction, depend on the customer’s existing contracts and the accuracy of its device estate; there is no universal dollar figure.

50+enterprise customers reported in 2024
45+countries with Batuta deployments reported in 2024
$11mSeries A extension announced in 2024

Company-reported figures, dated September 2024. Funding is capital raised, not the price customers pay.

The $11 million extension was led by SYN Ventures. Metabase Q said at the time that it had raised $16 million in total. Published funding databases disagree on later totals, and the company has not offered a public valuation. The more revealing number may be the spread of users: over 50 enterprises in more than 45 countries by September 2024, according to its announcement. That scale tests whether one endpoint model can survive the quirks of many networks, vendors and local teams.

A score is a beginning, not a verdict

Batuta posts customer outcomes, including a reported 18-point posture score increase across 4,476 ECOM endpoints in three months and a 48 percent score increase at ForzaCard over the same period. These are company case studies, not controlled comparisons. They show the kind of progress the product is built to measure: changes in coverage, hardening and update status over time. They do not prove that a higher score stops every attack. The more modest claim is also the more useful one: a team can see whether its last fix reached the machines it intended to fix.

In 2026, Batuta widened that loop. It announced Mac support, AI-assisted natural-language filters and draft PowerShell or Bash scripts, and a completed SOC 2 Type II audit. The scripts are presented for human review before execution. That detail matters. A tool that can fix thousands of endpoints can also make thousands of mistakes quickly; approval, rollback and measurement deserve as much attention as speed.

The habit worth stealing

A reader need not buy Batuta to copy its first move. Pick one security control already purchased. Count the devices that should have it. Count the devices where it is installed, healthy and reporting. Investigate the difference. Then repeat the count after remediation. This is not a grand theory of cyber defense. It is an audit of whether money turned into working protection.

The method has conditions. It needs a trustworthy asset inventory, permission to collect endpoint data and people empowered to repair what they find. A small operation with few devices and one well-run security tool may have little reason to add another platform. An enterprise unwilling to install an agent or connect its existing products will get a thinner picture. And a score, however neat, should never be mistaken for proof that attackers have run out of ideas.

Still, the rude question survives every product cycle. Is the protection there? Is it working? Did the last action make the answer better? Batuta has turned those three sentences into software, services and, eventually, its own name. The baton is a charming image. The work is less charming, and more valuable: making every player show up.