SOCRadar Featured on the Google Cloud Blog
Jul 02, 2026
SOCRadar’s Database Modernization Journey, from a 20x Performance Boost to AI-Driven Alert Filtering, Highlighted in a Dedicated Google Cloud Blog Post
SOCRadar has been featured on the Google Cloud Blog in a dedicated post detailing how the company modernized its threat intelligence infrastructure by migrating from self-managed PostgreSQL to Google Cloud’s AlloyDB for PostgreSQL.
The post, co-authored by SOCRadar Co-Founder and CTO Ahmet Kuruköse and Google Databases VP Sailesh Krishnamurthy, walks through how the migration delivered up to a 20x improvement in analytical query performance and freed the majority of the company’s database administration resources for platform innovation.

Threat intelligence at scale, on AlloyDB
As SOCRadar’s customer base and the volume of global cyber threats grew, the company’s on-premises, self-managed PostgreSQL database reached its performance limits. The system could no longer keep pace with the combined demands of high-velocity data ingestion from thousands of sources and the heavy, real-time analytical queries required to turn that data into actionable intelligence. The resulting bottleneck slowed the delivery of insights to customers and diverted engineering time toward constant manual database tuning.
To resolve this, SOCRadar evaluated several alternatives and selected AlloyDB for PostgreSQL. Its full PostgreSQL compatibility offered a low-risk migration path, while its architecture was purpose-built to handle both high-volume transactional workloads and real-time analytics at the same time. SOCRadar partnered with NGC, a Google Cloud Premier Business Partner, to validate the architecture and execute the cutover with minimal downtime.
The migration transformed how SOCRadar processes what its engineering team calls a “triple-threat” workload spanning live data ingestion, operational point-reads, and deep historical analytics:
- High-velocity ingestion: AlloyDB delivered a 3.2x boost in live ingestion speed for continuous data streams from Dark Web forums, botnet logs, and social media sources, ensuring new threat indicators are recorded and available for detection immediately.
- Real-time investigations: Indexed lookups that previously took 3 to 3.5 seconds under baseline conditions now complete in about 1 second, speeding up analyst investigations during live incidents.
- Deep analytical reporting: Using AlloyDB’s in-memory columnar engine, complex sectoral reports that scan a full year of historical data now run up to 20x faster than on standard PostgreSQL.
Beyond performance, the migration reshaped SOCRadar’s operational efficiency. AlloyDB’s automated memory management and storage optimization eliminated the need for constant manual tuning, cutting the database administration workload down to a health check roughly once every two to three days and freeing up 75% of the team’s DBA resources for core platform development. The company also reclaimed more than 45 terabytes of storage by clearing legacy data, with AlloyDB’s dynamic storage automatically scaling down to match actual data footprints instead of billing for fixed, provisioned capacity.
SOCRadar has also integrated Gemini Enterprise Agent Platform directly with its Alarm Management framework running on AlloyDB, addressing the alert fatigue that affects security operations centers worldwide. By running AI-native filtering on live data workloads, the platform automatically distinguishes true positives from benign false alarms, categorizing, filtering, and routing alerts before they reach analysts, so security teams see only validated, actionable intelligence.
“Our engineering team needed a database that could keep up with both the speed and the scale of modern threat intelligence, without pulling us away from building the platform itself,” said Ahmet Kuruköse, Co-Founder and CTO of SOCRadar. “AlloyDB gave us that headroom, and pairing it with Gemini Enterprise lets us cut through alert noise so our analysts spend their time on real threats, not false positives.”
Looking ahead, SOCRadar’s AI team is moving from passive analytics to active automation, currently testing agentic AI workloads for production rollout. By combining real-time data agents with Gemini Enterprise and AlloyDB, upcoming capabilities include:
- Natural language querying, allowing analysts to run threat hunts using conversational language.
- Intelligent semantic similarity search, using native vector embeddings to surface hidden patterns across historical logs that keyword search would miss.
- Automated incident summarization, turning complex technical logs into concise, plain-language executive summaries during active incidents.
By unifying transactional speed, historical depth, and built-in AI intelligence on a single platform, SOCRadar has removed its data bottlenecks and built a more automated, future-ready foundation for global threat detection. Read the full story on the Google Cloud Blog.
