What we learned at RUNWAY, and what we’re building next

What we learned at RUNWAY, and what we’re building next
RUNWAY by RunReveal is our inaugural conference for security engineering practitioners and leaders.

Last week, we hosted our first RUNWAY conference in San Francisco. We brought together security practitioners and leaders to share what they’re building, what’s working, and what still needs fixing.

We’re incredibly thankful to everyone who showed up and contributed. The conversations were specific, honest, and often funny. Practitioners shared working systems, mistakes they’d made, and problems they hadn’t solved yet, and we couldn’t have asked for a better first event.

What’s actually working?

AI investigations were a big topic, but the most useful parts were the details behind them.

Max Baumgarten showed how Flexport built an agent to investigate alerts and notify the team when something needs attention. Early on, automating investigations still left someone reading every report. Making it useful required better context, better tools, and clearer decisions about when to involve an engineer.

Max emphasized: “Tune your alerts. Your alerts cost money now.”

Max Baumgarten, Staff Security Engineer @ Flexport

Mike Parowski shared how Harvey is improving detections with agents. One sign-in rule had accumulated so many exceptions that it effectively became a travel diary. Fixing it meant revisiting the behavior it should detect, the identity data behind it, and how the team validated the results.

Mike Parowski, Security Engineer, Detection & Response @ Harvey

We heard the same practical thinking in the panels. Security leaders are building tools that make their expertise available across the business. Practitioners are figuring out how to constrain agent permissions, monitor tool calls, and evaluate the instructions agents load.

There’s a lot working already. There’s also a lot of engineering left to do.

The job is changing, too

The leadership panel explored how security teams are taking on more responsibility for AI adoption, internal tools, and engineering productivity. The role increasingly involves helping the company decide what to build and how to make it work securely. Preparing the next generation of leaders means giving practitioners more than technical assignments: ownership of decisions, exposure to customers, and opportunities to work across the business.

Joe Sullivan, Martin Choluj (CISO @ ClickHouse), Sneha Regmi (Director Security Operations & Resilience @ Affirm), Ben Draffin (prev. Director of Security @ Decagon), Derek Chamorro (Head of Security @ Together AI)

Our “Securing What’s Next” panel explored what teams are creating tools for their own workflows, making vulnerability findings easier to act on, and finding new ways to reduce repetitive work. The opportunity is exciting, but it also raises the bar for judgment: deciding which problems are worth solving and whether the result actually helps.

Evan Johnson (CEO & Co-founder @ RunReveal, Kapil Yadidi (Security Engineer @ Baseten), Pippin Wallace (Staff Security Engineer @ Favor/H-E-B), Alberto Martinez (Head of Security @ Runlayer)

Both conversations left us excited about how much more security teams can own and improve.

Good investigations need good data

Across those conversations, the same dependency kept coming up: agents need context.

Who owns this account? Is this device managed? Has this behavior happened before? What else occurred around the same time?

Answering those questions requires data from different systems, enough history to make comparisons, and queries that finish quickly. An agent can generate the SQL, but it still has to wait for the database. If the evidence wasn’t collected, it can’t query it at all.

That’s why the data engineering discussion with Tristan Ahmadi mattered. Ingestion, retention, schemas, and query performance directly affect what a security team can investigate. Agents increase the number of questions the system needs to answer.

These are the problems we built RunReveal to solve, and they’re becoming more important.

Tristan Ahmadi, Solutions Architect @ ClickHouse

What we’re building next

At RUNWAY, we previewed an onboarding flow that connects RunReveal to a customer’s own ClickHouse service. We also demonstrated agents gathering evidence, building investigation timelines, and helping responders write follow-up queries and detections.

The direction is straightforward: make it easier to bring security data together, query it efficiently, and give people and agents the context they need to investigate.

That includes the less glamorous work:

  • Knowing when a source stops sending logs
  • Handling different formats
  • Making common queries faster
  • Preserving useful investigation context
  • Understanding what an agent did and how much it cost

Those details determine whether a system is useful during an incident. They also determine whether a modern security team can cover more ground without spending its day managing pipelines or reading another queue of reports.

We’re excited to keep building this with ClickHouse and with the practitioners who push us to make it better.

If growing data volumes, slow queries, or missing context are holding back your detection and response program, book a demo with our team. We’ll show you how RunReveal brings security data and investigations together on ClickHouse, helping your team investigate efficiently and giving agents the evidence they need to do useful work.