The company that thinks most of your security data is noise - and built AI agents to prove it.
Above: the DataBahn wordmark. The name nods to Germany's Autobahn - fast, unobstructed lanes, rebuilt here for enterprise telemetry moving from edge to cloud.
Every large enterprise now generates more telemetry than it can afford to keep. Logs from firewalls, endpoints, cloud workloads, applications and increasingly from sensors and operational technology pour into security and observability tools that charge by the gigabyte. DataBahn, a Plano, Texas company founded in 2024, was built on a blunt observation about that flood: much of the data being paid for is never used.
Its answer is an AI-powered, security-native data pipeline - what the company calls an intelligent data fabric. Rather than shovel raw logs straight into a SIEM or data lake, DataBahn collects across sources, enriches and filters in flight, suppresses noise, and routes only high-value data to where it is needed. Customers, the company says, cut telemetry processing costs by more than half while keeping the alerts that matter.
The founders are not newcomers to the problem. Chief executive Nanda Santhana was a founding member of security-analytics firm Securonix and a technology fellow at Oracle. President Nithya Nareshkumar built data systems at J.P. Morgan and DTCC. Around them, DataBahn assembled a team drawn from security vendors, Big Four consultancies and global financial institutions - people who had personally wrestled with the plumbing they now aim to automate.
The modern security operations center runs on data engineering it never asked to do. When a vendor changes a log format - "schema drift," in the trade - dashboards break and detections go blind until someone rewrites the parser. When a new source comes online, onboarding it can take weeks. And all the while, ingestion meters keep running.
DataBahn frames three problems it set out to solve: runaway cost, as low-value telemetry inflates SIEM bills; blind spots, as fragmented, fast-growing data streams outpace the teams meant to watch them; and toil, the manual normalization, transformation and monitoring that consumes data engineers.
The company's pitch is that these are not three problems but one - a pipeline that is static when it should be adaptive. Fix the pipeline, and cost, coverage and toil improve together. That is the wager behind every product it ships.
It is also why the company describes itself as "security-native" rather than a general-purpose data tool. The pipeline is designed from the first byte for the governance, sensitivity and routing that security and IT teams require.
We built DataBahn to make data work for security and IT teams - not the other way around.
DataBahn sells a single platform with 500-plus connectors, fronted by three products that each attack a different part of the pipeline. Deployment is flexible - agentless or agent-based - across security, observability, application and IoT/OT data.
An agentic AI "data-engineer-in-a-box." Cruz automates log discovery, onboarding, normalization, transformation, optimization and operational monitoring - and flags issues like schema drift before they break detections.
Built on a DataBahn MCP server, Reef filters, contextualizes and prioritizes high-volume telemetry in real time, enables federated search, and writes to enterprise-owned data lakes - delivering context to analysts and AI agents.
Phantom agents gather telemetry without deploying traditional agents, avoiding footprint bloat and preserving compute - collection that stays out of the way of the systems it watches.
Figures below are company- and investor-reported outcomes for Fortune 500 / Global 2000 deployments. Treat as approximate.
Today's enterprises don't just need data pipelines; they need intelligent fabrics that adapt, govern and optimize data at scale.
DataBahn sells to large enterprises - Fortune 50 and Global 2000 organizations across financial services, healthcare, semiconductors, technology and cybersecurity. Publicly referenced customers include McAfee, CSL Behring, Archaea Energy (a BP subsidiary) and ThinkOn. The business model is straightforward B2B SaaS, usually justified on the ROI of lower SIEM and telemetry bills plus reclaimed engineering time.
The category it competes in - telemetry and observability pipelines - is getting crowded, with names like Cribl, Observo AI, Monad, Tenzir and the data-tiering features of incumbents such as Splunk and Databricks. DataBahn's differentiation is its agentic bet: rather than a configurable router that humans tune, it positions Cruz and Reef as autonomous operators that learn from data flows and act on them, with security governance built in from the start.
That places DataBahn at a busy intersection - between the SIEM, the data lake and the emerging agentic-AI stack. By building Reef on the Model Context Protocol, the company is wiring clean, governed security data directly into the LLMs and agents enterprises are only beginning to deploy. Its argument is that whoever controls the pipeline controls whether that next wave of AI is fed signal or noise.
Cybersecurity and data veterans from Securonix, Oracle, J.P. Morgan and DTCC launch the company in Plano, Texas.
The company introduces Cruz, an agentic AI data engineer, and Phantom agentless telemetry collectors.
DataBahn launches Reef, an MCP-server-based AI insight layer for context-aware security intelligence.
Forgepoint Capital leads a $17M round with S3 Ventures and GTM Capital, bringing total funding to about $19M.
CEO Nanda Santhana was a founding member of Securonix and a technology fellow at Oracle.
President Nithya Nareshkumar led data work at J.P. Morgan and DTCC before co-founding the company.
The name nods to the Autobahn - fast, unobstructed lanes, reimagined for enterprise data.
Reef is built on the Model Context Protocol, tying security data into the agentic-AI stack.
DataBahn's core claim: most data piped into a SIEM is never used - so filter before you pay to store it.
Series A was led by Forgepoint Capital, with S3 Ventures and returning investor GTM Capital.
| Legal name | DataBahn.ai, Inc. |
| Founded | 2024 |
| Headquarters | Plano, Texas, United States |
| Founders | Nanda Santhana (CEO) · Nithya Nareshkumar (President) |
| Team size | ~100 employees |
| Category | AI-powered, security-native data pipeline & fabric platform |
| Total funding | ~$19M (incl. $17M Series A, June 2025) |
| Investors | Forgepoint Capital, S3 Ventures, GTM Capital |
| Products | DataBahn Platform, Cruz, Reef, Phantom Agents |
It provides an AI-powered, security-native data pipeline and fabric platform that collects, enriches, filters and routes telemetry across security, observability, application and IoT/OT systems - reducing cost and noise while preserving visibility.
It was founded in 2024 by Nanda Santhana (CEO), a founding member of Securonix, and Nithya Nareshkumar (President), formerly of J.P. Morgan and DTCC. It is headquartered in Plano, Texas.
DataBahn raised a $17M Series A in June 2025 led by Forgepoint Capital, with S3 Ventures and GTM Capital, bringing total funding to roughly $19M.
Cruz is an agentic AI that automates data engineering tasks; Reef is an MCP-based AI insight layer that turns telemetry into context-aware intelligence; Phantom agents collect telemetry without deploying traditional agents.
By filtering and suppressing noisy, low-value telemetry before it reaches a SIEM or data lake, DataBahn reports cutting telemetry processing costs by more than 50% and automating 80%+ of data engineering work.