Home / Companies / ClickHouse / Blog / Post Details
Content Deep Dive

How iFood built its agentic security platform on ClickHouse Cloud

Blog post from ClickHouse

Post Details
Company
Date Published
Author
-
Word Count
1,520
Company Posts That Month
31
Language
English
Hacker News Points
-
Post removed?
No
Summary

iFood, Latin America’s largest food delivery platform, rebuilt its in-house security platform around ClickHouse Cloud after its Databricks-based approach became too costly and slow for high-volume log ingestion, long-term retention, and incident investigations across more than 130 TB of data. While Databricks remains central to the company’s lakehouse for BI and data science, ClickHouse Cloud delivered 9–16 times faster queries at an expected 40–50% lower cost, improved data freshness from hourly batches to two-to-ten-minute ingestion through AWS S3 and ClickPipes, and enabled security alerts to run about every 10 minutes. The security team uses SQL, Querybook notebooks, ClickStack dashboards, and Langfuse to support investigations and monitor AI workflows, with more than 500 employees trained on Langfuse company-wide. ClickHouse has also enabled agentic threat hunting, allowing AI sub-agents to investigate multiple hypotheses across tens of terabytes of historical logs in parallel, reducing work that previously took an analyst a week to about two hours. iFood plans to expand the platform by migrating CDN and API logs from OpenSearch, extending retention from seven days to six months at roughly one-quarter of the cost.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Observability 2 3,175 737 186 -24%
Real-time 2 4,432 1,050 222 -31%
AI Agents 1 5,780 1,243 245 -15%
Kubernetes 1 3,490 385 112 +26%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.