Dossier · Private startup · 3 independent sources

Keewano

Cloud & Developer Infrastructure Dual-Use Technology Priority Signal Founded 2024

Last updated: Sep 20, 2026

Keewano (formal entity Sandstorm Ltd.) is an Israeli AI-infrastructure startup building KeewanoDB, an event-oriented database designed for machine reasoning and AI agents. Its architecture keeps complete event sequences together and queryable in context, aiming to let agents investigate live user, device, transaction, and operational histories without reconstructing them through conventional ETL pipelines.

Visit Website

Company Overview

**Product and the concrete problem it solves.** Keewano is addressing a data-layer mismatch created by agentic software. Conventional relational databases, warehouses, dashboards, and precomputed aggregates are generally optimized for people asking known questions or applications reading a current state. An AI agent investigating why a customer churned, why a device failed, or what sequence preceded a security incident needs the entire chronology, including events that were not anticipated when the schema or report was designed. Teams normally reconstruct that context by joining logs, warehouse tables, feature stores, and ad hoc exports, which creates delay, cost, and opportunities to lose evidence. KeewanoDB is positioned as a database for machine reasoning at scale: it stores the actions of users, devices, transactions, and AI agents live, completely, in order, and with context. The company also offers Keewano Analytics, an agent-driven layer for product and operational investigation. The commercial promise is to turn new questions into queries over a retained event record rather than new data-engineering projects.

**Core technology and how it works.** The architecture is differentiated by its storage layout and execution path. Keewano says each entity's events are kept together and in chronological order, so an agent can read the relevant sequence directly instead of asking a warehouse to rebuild it from normalized tables. The product preserves raw events at full resolution, adds a context layer connecting events to entities, timelines, and outcomes, and adds a semantic layer that maps raw fields to shared business concepts. Reports, sequence comparison, and custom logic run close to the data; results are exposed through MCP, SQL, REST, APIs, webhooks, and business-intelligence tools. The company describes a distributed, multi-sharded design running in Docker and Kubernetes, with vectorized CPU processing rather than a mandatory GPU dependency. SiliconANGLE reported Keewano's claim of roughly 250 million events queried in under half a second, while the company's own materials cite billions of events and high-throughput processing; these are vendor claims that require independent benchmarking. Keewano can ingest Kafka streams, Parquet, Apache Iceberg, Postgres, Snowflake, BigQuery, and application SDK events, and can run alongside an existing warehouse. Its in-database acceleration uses compact event representation, SIMD-style processing, and Lua logic invoked through MCP so an agent receives a smaller, relevant context window instead of an entire history.

**Market, customers, and go-to-market.** Keewano began with a practical beachhead in game analytics, where one player can generate a long, high-cardinality sequence of actions and product teams frequently need to understand behavior that was not modeled in advance. That origin gives the team a concrete workload and a route to early design partners, while the underlying event model can extend to SaaS product analytics, fraud, customer operations, observability, IoT, and enterprise AI. The go-to-market appears to combine a self-serve Keewano Cloud entry point with enterprise deployments that sit beside an existing warehouse or replace parts of it. The company says pricing is based on active entities rather than individual events, which encourages customers to retain more raw history and avoids the per-event tax common in telemetry and analytics products. It is also selling to developers and platform teams through standard interfaces rather than requiring every customer to adopt a proprietary agent. Public sources do not name paying customers, contract values, annual recurring revenue, retention, or production deployment counts. The near-term buyer case is strongest for organizations with very large event streams and a recurring need for open-ended investigation, where faster answers and lower model-context costs can be measured against warehouse and analyst spend.

**Traction, funding, and third-party validation.** Keewano was founded in 2024 and emerged from stealth on September 15, 2026 with general availability for KeewanoDB and a disclosed $12 million seed round. Hetz Ventures led the financing, with participation from a16z Speedrun, Remagine Ventures, DIG Ventures, and angel investors. Dealroom characterized the round as placing in the 95th percentile of Israeli AI seed deals, which is a market signal rather than proof of product-market fit. SiliconANGLE independently described the product architecture, the Tel Aviv base, the formal entity name Sandstorm Ltd., the claimed performance, Kafka and Iceberg integrations, and the company’s ability to run alongside Snowflake or BigQuery. Keewano's official launch materials claim that customers have seen token savings of about 84 percent when relevant context is filtered in the database before reaching a model; the claim is not independently audited and should be tested on representative workloads. The public launch itself, early availability of a cloud product, a named investor syndicate, and a technical explanation detailed enough for external coverage establish credible activity. They do not establish repeatable enterprise revenue, production reliability at trillions of events, or a proven moat.

**Founders and team background.** The founding team is unusually relevant to the stated problem. Mark Kardashov is CEO and co-founder; Dima Karger is COO; Pavel Bibergal is CTO; and Vitaly Bukhovsky is CPO. Dealroom and the company report two prior exits and a decade of experience operating analytics at gaming scale. Kardashov and Bukhovsky previously built TestProject, acquired by Tricentis in 2019, and Devalore, acquired by Abra in 2022. Bibergal was CTO at Plarium, while Karger led one of Plarium's large game studios. That background explains why Keewano started from high-volume behavioral telemetry rather than from a generic vector database pitch. LinkedIn lists the company as founded in 2024, headquartered in Ramat Gan in Israel's Tel Aviv District, and employing 11-50 people. The team profile is a positive early signal for shipping and customer discovery, but the public record does not yet establish the depth of its distributed-systems, security, enterprise-sales, or public-sector engineering bench. Diligence should verify who owns storage-engine correctness, isolation and authorization, workload benchmarking, and the operational support required for sensitive customers.

**Competitive dynamics and edge.** Keewano competes against both database platforms and the status quo of assembling a data stack. Snowflake and Google BigQuery provide mature warehouses with enormous ecosystem and procurement advantages; ClickHouse offers fast columnar analytics for high-volume event data; Elastic combines search, logs, and analytics; and Datadog captures operational events with a broad observability platform. MongoDB and specialized time-series systems can also serve applications that need flexible event records. Keewano's proposed edge is architectural focus: full event sequences remain available at query time, reasoning and filtering occur close to the data, and agents connect through MCP without forcing every question into a predefined dashboard schema. The entity-based pricing model and claimed token savings could create a tangible cost advantage if benchmarks hold. The risk is that incumbents can add sequence-aware retrieval, semantic layers, and agent interfaces to products already trusted by enterprise buyers. A durable moat therefore depends on execution evidence: lower latency on open-ended investigations, better answer grounding, lower total cost, and a developer ecosystem that makes Keewano the default event substrate for agents.

**Defense, security, and resilience relevance.** Keewano has genuine dual-use potential as an enabling data layer, although no public source establishes defense customers or classified deployments. Security operations, fraud detection, industrial control monitoring, fleet telemetry, and mission-support systems all generate ordered event histories where context and provenance matter more than a current snapshot. An agent investigating a cyber incident could trace the sequence of identity, endpoint, network, and application events; a critical-infrastructure operator could compare failure precursors across equipment; and a logistics or emergency-response organization could reason over the chronology of shipments, assets, alerts, and interventions. Keeping raw events intact and returning evidence-linked sequences is strategically useful for auditability and post-incident review. The platform's ability to run beside existing systems, expose standard interfaces, and avoid mandatory GPU infrastructure could also help hybrid or sovereign deployments. The qualification is material: Keewano has not disclosed government contracts, security certifications, air-gapped operation, export-control posture, or mission-specific integrations. Its national-security value is therefore a credible resilience and cyber-infrastructure adjacency that still requires accreditation, hardening, access-control testing, and operational proof.

**Growth stage, trajectory, and diligence risks.** Keewano is early stage: two years from founding, newly public, seed funded, and still building the reference base that will show whether a new database category can displace entrenched warehouses. The trajectory is attractive if AI agents become routine data consumers and if customers discover that preserving complete event history materially improves decisions while reducing model-context costs. The main diligence questions are: (1) whether the performance and 84 percent token-savings claims survive independent tests across workloads rather than curated demos; (2) whether a novel storage format, sharding model, and in-database execution remain reliable during schema evolution, backfills, outages, and multi-tenant failures; (3) whether customers can govern sensitive event data, agent permissions, Lua execution, and MCP connections without creating a new attack surface; (4) whether the active-entity pricing model remains economical at very large scale; (5) whether cloud, warehouse, observability, and database incumbents bundle comparable capabilities; and (6) whether the small team can support enterprise reliability, security reviews, and international expansion. The $12 million round provides runway for product hardening and hiring, but the next proof points should be named production references, independent benchmarks, renewal or expansion evidence, and deployments in regulated or resilience-critical environments.

Dual-Use Assessment

Military & Commercial Applications

Keewano's event-sequence database has credible dual-use value as infrastructure for commercial analytics, cyber defense, industrial monitoring, logistics, and resilience operations. Ordered, complete, evidence-linked histories can help agents investigate incidents and operational failures in both civilian and security-sensitive environments. No public source used here verifies defense customers, classified deployments, government contracts, or security accreditation, so the defense thesis is enabling infrastructure adjacency rather than fielded military capability.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Keewano merits a positive legacy priority signal because it is attacking an infrastructure bottleneck created by the shift from human-defined queries to machine-led investigation. 1) The product has a specific architectural thesis—ordered event storage, semantic context, and in-database reasoning—rather than a generic AI wrapper. 2) The $12 million seed led by Hetz Ventures with a16z Speedrun, Remagine Ventures, and DIG Ventures provides credible early financing and a network suited to AI infrastructure. 3) The founding team has two documented prior exits and experience operating analytics at gaming scale. 4) The market could expand across product analytics, cyber, observability, fraud, and industrial operations. The signal is not an investment recommendation; the principal unknowns are production reliability, independent performance, customer conversion, and incumbent response.

Strategic Value to U.S.-Israel Alliance

Keewano could become a strategic data substrate for AI systems that must reason over what happened, not merely retrieve a current record. Its emphasis on complete event history, evidence-linked answers, standard interfaces, and reduced model context can support cyber defense, infrastructure monitoring, logistics, and other resilience workloads where missing chronology creates operational risk. The Israeli base and experienced technical founders are useful ecosystem signals, while the platform's stated ability to run alongside existing warehouses reduces adoption friction. Strategic value remains conditional on security isolation, auditability, sovereign or hybrid deployment, and proof that the engine performs reliably under sensitive, high-volume workloads.

Key Technologies

  • Entity-centered chronological event storage that preserves complete raw histories
  • Semantic context layer linking events to entities, timelines, outcomes, and business concepts
  • Distributed multi-shard execution with vectorized CPU processing and compact event representation
  • In-database sequence comparison, reports, similarity analysis, and Lua execution through MCP
  • Agent and application interfaces through MCP, SQL, REST, APIs, webhooks, and BI tools
  • Streaming and file ingestion from Kafka, Postgres, Snowflake, BigQuery, Parquet, and Apache Iceberg
  • Managed cloud and self-managed deployment patterns that can run beside existing data warehouses

Use Cases & Applications

  • Open-ended product analytics that explains the event sequence behind churn, conversion, or adoption
  • AI-assisted cyber investigation across ordered identity, endpoint, network, and application telemetry
  • Fraud and financial-risk analysis that compares transaction histories and precursor behavior
  • Industrial and critical-infrastructure monitoring that identifies sequences preceding equipment failure
  • Fleet, logistics, and emergency-response analytics over asset, alert, shipment, and intervention timelines
  • Agent-ready observability and root-cause analysis for high-volume software and cloud operations
  • Grounded enterprise AI assistants that retrieve evidence-linked context without rebuilding ETL pipelines

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 7 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Investor Lens

What this entry is

Private startup

Why it may matter

Keewano may matter as a Cloud & Developer Infrastructure entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify traction
  • Verify cap table/funding
  • Verify regulatory/export-control issues
  • Verify customer concentration

Main investor questions

  • Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
  • What customer, revenue, product, and technical evidence supports the company story?
  • What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies Keewano's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • What regulatory, procurement, and buyer-adoption constraints could slow deployment in strategic or government-adjacent markets?
  • What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?

Related sector

See the Cloud & Developer Infrastructure sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.