Sometimes you need a cost effective place to store security data.

That is a strange sentence coming from Query. We have spent four years enabling customers to use security data without moving it. We still believe that. Most security data already sits in a system that can serve investigation, threat hunting and detection use cases, and the Query Security Data Mesh queries it right where it lives.

But some data has nowhere good to live. Vendor retention windows close, sometimes in as little as 14 days. The data has to go somewhere, and SIEM ingestion and storage rates have become cost prohibitive.

For many teams, it goes to Amazon S3. First-party AWS telemetry lands there. Third-party data gets exported there when retention windows close and budgets say no. Add it up across the industry and Amazon S3 may already be the largest storage destination for security data on the planet.

That is often the right call. S3 is durable, cost effective, and already inside your compliance boundary. If your team has standardized on it, you’ve done something smart.

Here is the problem: data stored is not the same thing as operational.

Security telemetry lands in S3 as machine exhaust. Millions of small files. Hundreds of accounts. No scan-based query engine handles that shape well, and no security team should have to care why. Making it truly operational is a data engineering project: compaction, partitioning, catalogs, and permanent upkeep. Most security teams can’t staff that work. The teams that can borrow the skills usually borrow them from a central cloud team, where the request enters a queue measured in weeks or months.

So the data sits there, technically retained and practically not operational.


The easy button

Today we’re introducing Query Accelerated Connectors (see https://www.query.ai/accelerated-connectors/), available now to Query customers.

Here is how it works: point Query at an S3 bucket with a cross-account IAM role, the same low-touch access pattern our connectors already use. Query validates access, provisions an isolated columnar store for your data, and backfills whatever history you choose. From there it keeps itself current: new objects are picked up continuously and become searchable within minutes. Data lands typed and sorted, with the full raw event preserved beside the extracted columns, so nothing is lost to somebody else’s schema decision. Retention is set per connector and enforced automatically, and you pay only for the storage you chose to keep. No pipelines to maintain. Normalized schema applied. No tickets to another team.

An Accelerated Connector becomes another source on the Query Security Data Mesh, which means everything that works on the mesh works on it. Search it with the same query language as your EDR, your identity provider, and your threat intel platform. Run federated detections against it without rate-limiting anything. Ask questions nobody modeled in advance, because every column is there. Queries that used to time out come back in seconds.


Your AI Agents reach it too

Every agent investigation eventually needs history. Has this indicator ever appeared here? What did this identity touch last quarter? When did this actually start? That history is exactly the data sitting in S3, and an agent that can’t reach it simply returns less answer. An agent that reaches it unreliably does something worse: a source that times out mid-query looks like “no activity,” and the agent reports a clean conclusion built on a fraction of the evidence. Our CEO Matt Eberhart calls that failure mode confidently incomplete, and he measured it against real security data. Agents working through the mesh found more of the answer with fewer queries and fewer tokens than agents wired to sources one at a time.

Accelerated data is mesh data: normalized, typed, consistent, and fast. Because queries against it are free at the margin, an agent that investigates every alert can afford to sweep a year of history on every single one. Point your agents at it and let them work.


Federate when possible. Accelerate when necessary.

An Accelerated Connector is an index. It has to be built and it has to be stored, and we know those costs better than anyone. Not paying them is why we built a federated query engine in the first place.

Nothing about the mesh changed. Querying data in place is still the default, and for most data sources it is still the right answer. Acceleration is for the slice of data that deserves an index: the high-volume telemetry your detections sweep all day, the history your hunts keep returning to, the S3 data you were smart to keep and tired of not using. You choose the slice, the retention window and the bill is storage you already track.

Federate when possible. Accelerate when necessary.

Accelerated Connectors are available for Amazon S3 today. If you have security data in S3 that you’d like to actually use, schedule a demo and bring your messiest bucket.