Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
Query is an AI-powered Security Data Operations platform that creates a security data mesh by connecting distributed security data across SIEMs, EDRs, cloud storage, data lakes, identity, and network tools and more. With Query Federated Search & Analytics, security teams can search data where it lives, eliminating costly data duplication, and make better decisions, faster during investigations, threat hunting, and incident response.
Query AI Agents deliver automation and real-time context, helping analysts cut triage & investigation time from hours to minutes. Teams gain expanded visibility, reduce security data costs, and make faster, higher-confidence decisions during incidents.
Show the rest of the publisher’s description (2 more lines)
Query Security Data Pipelines make moving security data to cloud storage simple and efficient. Pipelines deploy in under five minutes with no YAML, no packs, and no custom ETL jobs required. Data is written in ZSTD-compressed Parquet and partitioned for performance. Its everything you need to write to the gold layer of your security lake, without the overhead. The result is an 80%+ reduction in storage footprint, cloud-ready data for compliance, analytics, and security operations, and a scalable foundation for long-term security data retention.
Query provides custom pricing for customers via Private Offer. Please contact info@query.ai for more information.
Highlights
Highlighted by the publisher on AWS Marketplace.
Get up and running fast - pre-built integrations make it simple to connect the products and services you already use - like Amazon Athena, Amazon S3, Amazon Security Lake, Crowdstrike, Splunk, Datadog, SentinelOne, Okta, Jamf, Virus Total and more.
Choice and control - Query is your answer to managing security data costs. Choosing what to centralize and what to leave in place means never having to compromise on security value for cost reasons.
Faster, more accurate investigations - Query is the gateway into all of your security-relevant data, wherever it is stored. Analysts can stop wasting time pivoting from console to console, and start using data to decide and act with confidence.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment
Plans and pricing as listed
1 listed- Units
Refund terms
As stated by the publisher on AWS Marketplace.
Contact us at info@query.ai
Sources
Publisher resources
4 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

