The security engineers at Notion weren't exactly expecting this.
When they deployed an AI agent nicknamed "Scruff" to help triage alerts in January, it was more experiment than transformation. But by the time Scanner—the San Francisco startup whose security data lake powers that agent—announced a $22 million Series A on March 10, 2026, something had fundamentally shifted. Scruff and agents like it now generate roughly 80% of the queries hitting Scanner's platform.
Not next year. Not in some imagined future where AI finally lives up to the hype. Right now, in production.
"Agents are the most prolific users of Scanner," Bogomil Balkansky, the Sequoia Capital partner who led the round, said in a statement accompanying the funding announcement. Sequoia was joined by CRV and Mantis VC, alongside a cluster of angels that reads like a who's who of infrastructure founders: Vanta's Christina Cacioppo, MongoDB board chair Tom Killalea, and Venkat Venkataramani, who recently moved from MongoDB to lead infrastructure at OpenAI.
The timing is worth noting. Over the past three months leading up to the March 2026 announcement, what Scanner's founders built as a better mousetrap for storing and searching security logs has become something else entirely: the database layer for autonomous security operations.
When the Product Finds Its Real Use Case
Cliff Crosland and Steven Wu, both Stanford computer science graduates who spent years building large-scale data infrastructure at Accompany before Cisco acquired it, started Scanner in 2022 to solve a problem they'd lived through. After the acquisition, they watched log volumes explode and SIEM bills—those hefty invoices for security information and event management tools—climb in lockstep. Traditional systems like Splunk force painful tradeoffs: retain only 10 to 30 days of logs, ingest just a fraction of available data, and park everything else in AWS S3 buckets where it sits essentially unsearchable.
Scanner's technical approach—building an inverted index directly on object storage—wasn't revolutionary on its own. Fast full-text search across years of data, compute that scales to zero when idle. Useful, certainly, for security teams drowning in alerts with insufficient analyst headcount. Lemonade's CISO Jonathan Jaffe mentioned his team now searches 10 terabytes per second of uncompressed log data, extending retention from weeks to over a year. FloQast, after evaluating Datadog SIEM and Cribl Search, picked Scanner and stretched EDR log retention from 30 days to more than 12 months.
But the real inflection arrived around December 2025, when Scanner released a Model Context Protocol server. MCP, for those not steeped in AI infrastructure arcana, is essentially a standard way for AI agents to connect to external data sources. What Scanner perhaps didn't fully anticipate was how quickly customers would start deploying agents that query continuously—not as a supplement to human analysts, but as the primary interface.
Notion's Scruff, announced publicly on January 12, 2026, delivered an 84% reduction in median time to investigate false positives. Job satisfaction among security team members rose 30%, according to Notion's own metrics. The agent handles triage, hunting, and investigations—tedious, repetitive work that previously consumed hours of engineer time.
Ramp's engineering team now runs detections-as-code through GitHub CI/CD, querying Scanner daily across security and operations workflows. These aren't pilot projects. They're production systems that companies depend on.
The Agent Economy Arrives for Security

If you're skeptical about AI agents—and plenty of enterprise software veterans are—the 80% figure is worth sitting with for a moment. That's not a hockey stick projection in a pitch deck. It's actual usage data from customers like Notion and Ramp, companies not known for adopting unproven technology on a whim.
Perhaps it's less surprising than it initially seems. Security operations centers have been understaffed for years. The talent shortage is real, the alert fatigue is debilitating, and the consequences of missing something critical are catastrophic. An agent that can sift through terabytes of log data, chase down false positives, and surface genuine threats without needing sleep or equity compensation? Security teams were always going to embrace that, assuming it actually worked.
The broader question is whether Scanner can defend the position it's stumbled into. Microsoft announced Sentinel Data Lake last July, explicitly targeting what it called "unsustainable costs" in traditional SIEM architectures. AWS has Security Lake. Snowflake is pushing cybersecurity workloads. Startups like Abstract Security and Panther are circling the same opportunity from different angles.
Scanner's current edge appears to be that MCP integration and the agent ecosystem blooming around it. The company now counts Notion, Ramp, BeyondTrust, Lemonade, Benchling, Postman, and EliseAI among its named customers. Recent job postings—spotted on Greenhouse, where the company lists 13 full-time employees—signal expansion beyond pure security into DevOps, SRE, and observability workloads. Adjacent markets with identical log retention nightmares.
The $22 million, which follows an earlier undisclosed seed round from CRV, will presumably fuel that expansion. Scanner's advisor roster includes executives from Cribl, Temporal, HashiCorp, and NetApp, with board members drawn from Salesforce, Disney, HubSpot, and Asana—the kind of Rolodex that helps open doors at enterprises evaluating new infrastructure.
Wilson Sonsini handled the legal work, a detail that matters mainly as confirmation this was a reasonably complex transaction. The company maintains SOC 2 Type II compliance and keeps customer data within their own cloud environments. Pricing requires direct contact—never a good sign if you're hoping for transparent SaaS economics, but standard practice for infrastructure sold into security teams.
What Comes Next

Balkansky's announcement post described Scanner as "a fundamentally new approach" that "manages security data at AI scale." The phrasing is telling. Sequoia's thesis appears to center less on Scanner as a better SIEM alternative and more on Scanner as the data layer enabling agent-driven security operations.
That bet assumes agents continue to proliferate, which seems likely, and that Scanner can maintain its lead as larger players pile into the space, which is less certain. The company recently became an official Torq AMP partner, though details on that integration remain sparse—perhaps deliberately so, given how quickly partnerships can shift in enterprise security.
For now, the numbers speak clearly enough. When 80% of your queries come from autonomous systems rather than human analysts, you're no longer selling a tool. You're selling infrastructure. And infrastructure, unlike tools, tends to be sticky—right up until someone builds something better, faster, or cheaper.
The security engineers at Notion probably weren't expecting Scruff to become their most active user. Scanner's founders likely weren't expecting agents to drive the majority of platform traffic within months of releasing MCP support.
Turns out, the future arrives unevenly. Sometimes it shows up ahead of schedule.
