Why we built it

Having data isn’t the advantage. Acting on it is.

AI can answer almost any question about your business in seconds. That's exactly the problem.

Shapor Naghibzadeh CEO & Co-Founder
Aug 26, 2026

The most important thing I learned in eighteen years at Google wasn’t a specific technology. It was a belief the company held so deeply that nobody bothered to write it down.

Having data isn't the advantage. Acting on it is.

Most organizations are currently separated by an invisible wall. On one side is the data team, the pipelines, the code, the queries, the accountability for what’s accurate. On the other side is everyone actually running business decisions. To get answers to their real questions, they file a ticket, wait a week, and get back a chart that half-answers what they meant.

Behind that data-request backlog sits the same kind of messy multi-vendor stack we collapsed in security (more on that below). And now an AI chatbot bolted on top, producing answers that are fast, confident, and impossible to verify. We’re accumulating decision risk that can’t be traced to a clear data source.

Speed without traceability isn't progress. It's just a faster way to be wrong.


How we close the gap

QueryStory is a new agentic data platform built around decisions.

It connects a company’s data with the context that gives it meaning. It then turns questions into decision-ready outputs, or stories, that people can actually act on.

QueryStory is not data storage or compute. Unlike traditional data analytics platforms, QueryStory covers the full path from data to decision, for every team. Answers show their work: the sources, definitions, and assumptions behind them. They arrive as a brief, deck, doc, or dashboard that updates as the data changes. These assets and stories capture what was decided and why, so the next team builds on it instead of starting from scratch.


Why I believe this so deeply

From the earliest days of search, Google could measure and analyze what everyone else could only collect. If you could measure it, you could improve it: quality, latency, relevance, revenue. Whole generations of tools were built around that loop—Sawmill for logs, then Dremel, which the world later met as BigQuery. I worked with those tools for years, and I watched that loop win, over and over.

I was in systems operations back then, helping Google’s infrastructure scale. We asked a question that seems obvious in hindsight: what if we pointed the same machinery at ourselves? The tools the search team used to analyze the logs of the entire web were sitting right there, and they had already solved problems far bigger than ours. I'd spent previous jobs babysitting pipelines that fell over at a fraction of the load. So we pulled search's tools off the shelf and used them on our own operations, answering questions like “why are machines freezing?” and “how can we scale DNS to billions of queries per hour?”

At the end of 2009, we were hit with Operation Aurora—a nation-state cyberattack on Google. Because we had the logs, all of them, queryable, we could trace the attack end to end—from root cause to blast radius.

The ability to ask any question of your data, quickly, is the difference between knowing what happened and guessing.

That investigation pulled me into security, and I went on to help create Google’s Threat Analysis Group. We dug into every nation-state-sponsored actor on earth, and each investigation surfaced new questions and new ways to answer them. That accumulated craft eventually became Chronicle.

The insight that made Chronicle work was about people, not data.


Security analysts are not data analysts. They know what an attack looks like but not the query languages, the pipelines, or the schemas. The security industry spent thirty years building tools so those people could work with data anyway. We collapsed a messy multi-vendor stack into one system.

Then AI joined the party. Sure, we’d used ML for hard problems like insider risk and anomaly detection, but when LLMs landed, the ‘aha’ hit fast: this changes who can use the tools. What if a security analyst could just ask questions and get the truth? So I started the work that became Gemini for Security Operations, now serving the enterprises that trust Google to protect their data.

When I stepped back, I noticed something strange. Cybersecurity had quietly built the most advanced data-analysis practice of any industry, because it had to. Trust in the data is existential when you’re defending a company. We had decades of tooling developed for deep, verifiable investigation, and almost none of it had escaped to the rest of the world.

There was a reason it hadn’t. Everything we built assumed a schema, a curated data model that a dedicated team spent years building and maintaining. That was the tax cybersecurity paid, and most domains can’t afford it.

Then LLMs fundamentally changed what was possible. When a model can generate the query, understand messy sources, and work across systems, the schema stops being the gate. What security spent decades refining can suddenly be applied to any domain, without an army of curators.

So I took the idea to the two people I most wanted to build with. Stan was one of Chronicle's first engineers, and the reason Backstory shipped. I could describe what it needed to be; he was the one who made it work, across whatever the launch demanded. Since then he'd taken an applied-AI startup from its earliest team all the way through acquisition. Dave I'd known for years, from the other side of the wall: inside one of the world's largest consulting firms, responsible for how more than a hundred thousand people turned data into answers. When I showed him what security had built, he didn't need the pitch: he'd been living the problem it solved. Three different roads, same conclusion:

the people closest to a decision should be able to reach the data behind it.


The moment we’re in

Software solved a version of this twenty years ago. Shipping an application used to mean buying a database, writing the code, running your own servers, and wiring it all together. SaaS collapsed all of that into something you simply use.

QueryStory is that moment for data.

Cybersecurity spent thirty years learning how to pull trustworthy answers out of messy data, because it had to. We’re bringing what that industry learned to everything else.

So that's why we built QueryStory. Every company runs on data. Almost none of them run on understanding.

We're closing that gap.