The Expanso platform

Process data where it lives.

Design a pipeline once and run it on every node in your fleet. Filter noise, mask sensitive fields, and route telemetry at the source, before anything leaves your infrastructure.

INPUT
App logs
PROCESSOR
Filter noise
PROCESSOR
Mask fields
PROCESSOR
Enrich metadata
BROKER
Output broker
OUTPUT
Snowflake
OUTPUT
Splunk
OUTPUT
S3 archive
Pipeline Builder

Your whole pipeline, on one canvas.

Sources, processors, and destinations, wired as a graph. Drag to build, click to configure, and test with live data before anything ships.

Visual builder and YAML, in sync
Test with live data before deploy
Deploy to the whole fleet at once
payment-risk-routerDeploy
DesignCode
88%
SecretsAsk AI⌘I
HTTP Serverhttp_server
address:0.0.0.0:4195
path:/v1/payments
+3 more fields
dedupe_txnsdedupe
key:${! json("txn") }
score_riskmapping
root.risk = this.amount.sc…
route_by_scoreswitch
this.risk > 80
default
NATSnats
urls:["nats://nats-0:4222"]
subject:fraud.review
+2 more fields
BigQuerygcp_bigquery
dataset:payments
table:events
Data Samplepayment-webhooks
Configure Data Samples
OUTPUT · 2 EVENTS
{"txn":"tx_84921","amount":912.50,"risk":91,"card_country":"RO"}
{"txn":"tx_84922","amount":24.00,"risk":12,"card_country":"DE"}
1 event matched this.risk > 80 and routed to fraud.review
Component Config: NATS
fraud_alerts
nats://nats-0.acme.internal:4222A list of URLs to connect to. Comma separated.
fraud.reviewThe subject to publish to. Interpolation functions supported.
64
TLS
Custom TLS settings for this connection
Components

Read from what you have. Ship to what you already run.

Expanso ships connectors for the systems your data already lives in: message buses, object stores, databases, HTTP endpoints. Plus the processors to filter, mask, enrich, and reshape it in flight, and outputs into the warehouses and observability tools you already pay for.

Expanso Assistant
Describe a pipeline to get started
Drop debug logs and mask emails before anything reaches Splunk
Done. I added two steps before anything reaches Splunk: one drops debug logs, the other masks email addresses.
Pipeline YAML
Pipeline validated
Apply to pipeline
Ask about this pipeline...
Pipeline Assistant

Build pipelines in plain English

An assistant lives inside the builder. Say what you want in your own words and it builds the pipeline for you. No specs, no syntax, no code to learn.

Describe it and the assistant builds it
Review changes and apply them with one click
Hand it a broken pipeline to debug
Pipeline catalog

Your next pipeline is already written.

Proven templates for the jobs every data team has. Start from one, not from zero.

Log noise reduction
Drop debug lines and duplicates before they ship.
Field masking
Mask emails and card numbers at the source.
SIEM cost control
Send signal to the SIEM, archive the rest.
Sensor rollup
Aggregate readings into one row a minute.
Cold archive
Compressed, queryable archives from raw files.
AI feature prep
Clean, embedded events ready for training.
Fleet telemetry
Downsample healthy signals, keep anomalies.
Node management

From laptop to fleet, one installer.

Run the installer on any machine and it shows up in your network seconds later, already labeled and ready for pipelines. Remove it just as fast.

Cloud
EC2, GCE, AKS, or anything with a shell. Autoscaling groups register themselves.
On-prem
Data centers and factory floors, behind your firewall. Outbound-only connections.
Edge
Gateways, kiosks, vehicles, sensors.
edge-fra-041 ~ ssh session
$ curl -sL "https://get.expanso.io/edge/install.sh" | bash -s
Installing Expanso Edge
Detecting platform: linux/arm64
Registering with network prod-telemetry
node edge-fra-041 connected in 4.2s
$ expanso-edge run
16:24:42 INF Edge daemon started ▊
edge-fra-041
Connected · joined 2s ago
edgeeu-central-1
Log tailing

10,000 nodes. Zero SSH sessions.

Stream logs from any node or pipeline in real time. No SSH, no hunting across machines.

Tailing pos-kiosk-15eu-centrallivepipeline: pos-events-kafka
29 Jul 26 16:24:41INFOreader=applog tailing /var/log/kiosk/transactions.log
29 Jul 26 16:24:41INFOprocessor=mask redacted pan, cvv from 12 events
29 Jul 26 16:24:41INFOsink=kafka produced 240 msgs · topic=pos.events · p=3
▊

See every pipeline. Ship every change.

Metrics come built in, and rollouts reach the whole fleet with zero downtime in under 30 seconds.

  • Monitoring

    See how your system is running in real time — patterns, anomalies, and performance.

    Drill into metrics across nodes, pipelines, and every component within them.

  • Deployments

    Roll out in one shot. Or in waves.

    Pick how a deployment reaches the fleet, then let Expanso watch it land.

    One shot, or waves of any size
    Custom health checks gate every wave
    A failed check rolls back automatically
    Deploying v42
    events.prod pipeline
    Waves · 10%
    Wave 4 of 10 rolling out3,600 / 12,000 nodes
  • CLI Support

    Unlock full operational control with a CLI built for speed, reliability, and enterprise workflows.

  • Node management

    View, add, and remove nodes from your workspace with ease. Use labels to group nodes for different deployments.

  • Collaboration

    Granular access control and role-based permissions let you manage who can do what, when, and where.

Prefer to read first? It's all documented.

The data journey

AI-ready at the source

No retroactive cleaning, no surprise storage bills, no audit risk. Three controls run inside every pipeline before data leaves the source.

01Align: structure and context at creation
02Qualify: schemas enforced, bad data stopped
03Govern: policy decides where each stream goes
sourcesAligncontext + lineageQualifyvalidate + verifyGovernpolicy + routingSnowflakeSplunk
$ expanso-edge bootstrap ▊

Take control at the source.

Create a network, connect a node, and deploy your first pipeline in minutes.