https://www.reco.ai/blog/we-rewrote-jsonata-with-ai Raises $85M Total after Series B Funding Read the News [6797b48d42] Raises $85M Total after Series B Funding Read the News Platform Platform Use Cases [679866af8c] Posture Management & Compliance Improve SaaS security posture [67986ed53a] Data Exposure Management Reduce SaaS attack surface [67986ef452] Identity & Access Governance Ensure appropriate access [67986f3936] Application Discovery Discover & manage all apps [67986f50b8] Threat Detection & Response Prioritize alerts of threats [68921c9448] SaaS App Factory(tm) 200+ app integrations, 10x faster [69b835de1e] AI Agent Security Discover connected AI agents Posture ManagementData Exposure ManagementIdentity & Access GovernanceGenerative AI DiscoveryApp Discovery & GovernanceShadow App DiscoveryThreat Detection & ResponseReco AI AgentsEmbedded AI DiscoveryAI Governance & SecuritySaaS App Factory(tm) Solutions Security Posture ManagementIdentity Lifecycle ManagementAgentic Security Posture ManagementAutomated SaaS Compliance Monitoring Applications SecurityGenerative AI DiscoveryData Access Governance Real Time Threat DetectionInventory Management Solutions by Use Case [68921e25ed] SSPM Keep SaaS posture airtight automatically [68921faae8] SaaS Application Security Discover & secure every app, every update [689220cf2e] Inventory Management Discover every connected app in seconds [68921e7e66] Identity Lifecycle Management Govern identities across the SaaS lifecycle [68922047d7] Data Access Governance Control who accesses what data [68921f22c9] Automated SaaS Compliance Monitoring Stay compliant without manual work [68922086d7] Real-Time Threat Detection Detect threats as they happen Use Cases [68a7589a33] Shadow SaaS Detection Discover hidden apps instantly everywhere [68a759366a] Unsanctioned Apps Control Block risky apps before damage [68a75a3e94] Custom Policy Studio Build security rules your way [68a75ab5be] Identity Governance Compliance Automate identity compliance across SaaS [68a75b2591] SaaS Ticketing Workflow Route security issues automatically fast [68a75c215c] SaaS Offboarding Remove access when employees leave Integrations by App [679870bea8] All Supported Applications Connect Reco to your SaaS apps [6798717bb5] Salesforce Protect your business-critical data [67987245ae] Okta Monitor access & unusual activity [679870e724] Microsoft 365 Securely create & collaborate [67987114b9] ServiceNow Prevent unauthorized access [679871d224] Workday Secure employee data [679872155b] Google Workspace Identify content at risk of exposure AI Security Explore AI Governance & SecurityReco AI AgentsGenerative AI DiscoveryShadow AI DiscoveryAI-Powered SaaS Security InsightsAgentic Security Posture Management AI Security Platform Use Cases [6871311a62] AI Governance AI Governance & Security Discover & control AI agents & agentic AI [67f93ca82a] AI Governance Reco AI Agents Automate your SaaS workflow AI Security Value Total AI SaaS visibility. Complete usage control. Reco discovers every AI agent, AI application, embedded AI usage, and AI third-party integration so your organization can leverage AI SaaS to accelerate with confidence. AI Security Solution Use Cases [68921ffe9c] AI Governance Generative AI Discovery Visibility into connected AI apps [68a75cc48c] AI Governance Shadow AI Discovery Catch unauthorized AI tools everywhere [68a75d1866] AI Governance AI-Powered SaaS Security Insights Get smart alerts with context [68921ec742] AI Governance Agentic Security Posture Management AI agents that manage posture continuously Top AI Integrations [694ab1afdf][694ab21865][694ab23e14][694ab25caa][694ab27dcd] [694ab2ab5c][694ab2dc2b][694ab2fdaa][694ab318c5] Explore More Integrations [694ab42d50] Featured AI Security Resources [694ab7efa3] CISOs Guide to ChatGPT Risk The hidden AI risks in your SaaS ecosystem [694ab42d50] [694abbd943] CISO Guide to AI Security Empower responsible AI usage and reduce cyber risks [694ab42d50] Resources [6798738ab1] Blog Thoughts from our experts [679873bdea] CISO Guide to SaaS Security Guidelines for SaaS security program [679873fd2a] Learn Self-service security education [6798742fb1] CISO Guide to Financial Services SaaS security guidelines for finserv [67987473a9] IT Hub The go-to hub for IT security [6798749e04] CISO Guide to Healthcare SaaS security guidelines for healthcare [679874cedd] Customer Stories How Reco helped customers [679874fbb9] CISO Guide to Salesforce SaaS security guidelines for Salesforce [6798752d19] Webinars On demand video content [6798756852] CISO Guide to Microsoft SaaS security guidelines for Microsoft [6798759b73] SSPM Market Insight Report Analysis of SaaS security market [679875cbb1] CISO Guide to AI Security SaaS security guidelines for AI [679876082a] The State of SaaS Security Report Essential insights for your SaaS program [67987639ae] CISO Guide to Shadow AI SaaS security guidelines for Shadow AI [68921af65b] The State of Shadow AI Report Essential insights for managing shadow AI [68f78b807c] Resource Center SaaS security guides and reports Featured Articles [68d63d88ce] Learning Center The Salesloft-Drift Breach: Analyzing the Biggest SaaS Breach of 2025 [679877c696] [68ee61e443] Blog Reco Named a 2025 SINET16 Innovator [679877c696] BlogLearnIT HubCustomer StoriesWebinars & VideosSSPM Market Insight ReportThe State of SaaS Security ReportCISO Guide to SaaS Security CISO Guide to Financial ServicesCISO Guide to HealthcareCISO Guide to SalesforceCISO Guide to MicrosoftCISO Guide to AI SecurityCISO Guide to Shadow AI Company Company [67987cc273] About Reco Dynamic SaaS Security [67987cef6e] Newsroom Latest Reco updates & news [67987d1f2a] Careers Hiring View our open positions [67987d4e3a] Contact Us Connect with a SaaS security expert [68921c04b8] Partners Become a Reco partner Contact [67987dd3e7] Schedule a Meeting Get in touch [67987eabb9][67987ee8b1][67a2fe9a06] [67987e0404] Email Us info@reco.ai About RecoCareersNewsroomContact UsRequest a Demo Partners Request a Demo[68655190a8] Chat with us [67ab6cd54a] Email Us info@reco.ai [68655190a8] Chat with us [67ab549eea] Demo Request Take a personalized product tour with a member of our team to see how we can help make your existing security teams and tools more effective within minutes. First Name[ ]Last Name[ ]Email Address[ ]Company[ ] [ ][ ][Submit] Thank you! Your submission has been received! Oops! Something went wrong while submitting the form. Home Blog We Rewrote JSONata with AI in a Day, Saved $500K/Year We Rewrote JSONata with AI in a Day, Saved $500K/Year [66e202] Nir Barak Updated March 25, 2026 March 27, 2026 5 min read [69c41472d9] Ready to Close the SaaS Security Gap? [68655190a8] Chat with us A few weeks ago, Cloudflare published "How we rebuilt Next.js with AI in one week." One engineer and an AI model reimplemented the Next.js API surface on Vite. Cost about $1,100 in tokens. The implementation details didn't interest me that much (I don't work on frontend frameworks), but the methodology did. They took the existing Next.js spec and test suite, then pointed AI at it and had it implement code until every test passed. Midway through reading, I realized we had the exact same problem - only in our case, it was with our JSON transformation pipeline. Long story short, we took the same approach and ran with it. The result is gnata -- a pure-Go implementation of JSONata 2.x. Seven hours, $400 in tokens, a 1,000x speedup on common expressions, and the start of a chain of optimizations that ended up saving us $500K/ year. An expensive language boundary At Reco, we have a policy engine that evaluates JSONata expressions against every message in our data pipeline - billions of events, on thousands of distinct expressions. JSONata is a query and transformation language for JSON (think jq with lambda functions), which makes it ideal for enabling our researchers to write detection rules without having to directly interact with the codebase. The reference implementation is JavaScript, whereas our pipeline is in Go. So for years we've been running a fleet of jsonata-js pods on Kubernetes - Node.js processes that our Go services call over RPC. That meant that for every event (and expression) we had to serialize, send over the network, evaluate, serialize the result, and finally send it back. This was costing us ~$300K/year in compute, and the number kept growing as more customers and detection rules were added. For example, one of our larger clusters had scaled out to well over 200 replicas just for JSONata expressions, which resulted in some unexpected Kubernetes troubles (like reaching IP allocation limits). In some respects, the RPC latency overhead was actually worse than the pure dollar cost. An RPC round-trip is ~150 microseconds before any evaluation even starts. For a simple field lookup like user.email = "admin@co.com" something that should take nanoseconds - we're paying microseconds just for crossing a language boundary. At our scale, those microseconds stack up quickly. We'd tried a few things over the years - optimizing expressions, output caching, and even embedding V8 directly into Go (to avoid the network hop). They did their part, but it was mostly just incremental improvements. The closest we got was a local evaluator we built using GJSON that handled simple expressions directly on raw bytes. It was fast for what it covered, but anything complex had to fall back to jsonata-js. We were patching around the problem, but the root cause remained unsolved. Building gnata During the weekend I built out a plan (using AI) separated into 'waves'. The approach was the same as Cloudflare's vinext rewrite: port the official jsonata-js test suite to Go, then implement the evaluator until every test passes. The following day, I pressed play. The plan was straightforward - build out the full JSONata 2.x spec in Go, with a focus on performant streaming and some extra features sprinkled on (localized caching, WASM support, metrics, and fallthrough capabilities back to the jsonata-js RPC). A few iterations and some 7 hours later - 13,000 lines of Go with 1,778 passing test cases. Total token cost: $400. Cursor AI dashboard for the gnata session I shared the numbers internally and someone asked about the ROI. Production cost for jsonata-js in the previous month was about $25K - now it was 0. That conversation ended up being pretty short. Two-tier evaluation gnata has a two-tier evaluation architecture. At compile time, each expression is analyzed and classified. The fast path handles simple expressions - field lookups, comparisons, and a set of 21 built-in functions applied to pure paths (things like $exists(a.b) or $lowercase(name)). These are evaluated directly against the raw JSON bytes without ever fully parsing the document. For something like account.status = "active" you get 0 heap allocations. Everything else goes through the full path - a complete parser and evaluator with full JSONata 2.x semantics. This does parse the JSON, but only the subtrees it actually needs, not the entire document. On top of this there's a streaming layer (the StreamEvaluator) designed for our specific workload: evaluate N compiled expressions against each event, where events are structurally similar. 1. All field paths from all expressions are merged into a single scan. The number of expressions doesn't matter - raw event bytes are only read once. 2. After warm-up, the hot path is lock-free. Evaluation plans are computed once per event schema and cached immutably, so reads are a single atomic load with no synchronization. 3. Memory is bounded. The cache has a configurable capacity and evicts the oldest entries when full. The fast-path design took a lot of inspiration from the existing local evaluator. For simple expressions it was excellent -- gnata won't be faster on an apples-to-apples comparison for those. But the schema-aware caching and batch evaluation is where the real gains come from. [69c38a1c16] Correctness: 1,778 test cases from the official jsonata-js test suite + 2,107 integration tests in the production wrapper. The speedup on simple lookups is mostly from eliminating the RPC overhead entirely -- gnata evaluates directly on raw bytes with no JSON parsing. Complex expressions involve full parsing and AST evaluation, so the gap narrows, but they're still 25-90x faster than the RPC path. In practice, gnata runs as a library inside our existing Go services. The serialization and RPC overhead goes away. Architecture: Before and After Shadow mode and the week after Building the library was day one. The rest of the week was about making sure it was actually correct. We already had mismatch detection infrastructure in the codebase - feature flags, shadow evaluation, comparison logging - built months earlier for the local evaluator. Wiring gnata into the same system was straightforward. The rollout: * Day 1: gnata built. PR opened. * Days 2-6: Code review, QA against real production expressions, deployed to preprod in shadow mode. gnata evaluates everything, but jsonata-js results are still used. Mismatches logged and alerted. Fixed edge cases as they came up. * Day 7: Three consecutive days of zero mismatches. gnata promoted to primary. By the time we promoted gnata, it had already been processing billions of events and producing identical results to jsonata-js. We also caught bugs in jsonata-js itself. Cases where the reference implementation doesn't follow its own spec. gnata handles them correctly. A side effect we didn't expect: gnata was one of the first large PRs where we had AI agents reviewing AI-generated code. The agents were flagging everything - real concurrency issues alongside cosmetic nitpicks - and we had to teach them which is which. That work fed into how we handle AI code review more broadly now. Beyond gnata - the next $200K Eliminating the RPC fleet took care of $300K, but there was one more thing we wanted to tackle - batching events end-to-end in our rule engine. JSONata - being only able to do a single evaluation at a time - forces the infra around it to contort itself with workarounds in order to stay performant. For our rule engine, that meant we were spinning up tens of thousands of goroutines to maximize concurrency (with all the added resources that entailed) in what would otherwise be a straightforward pipeline of micro-batches. As you might expect, that resulted in excessive memory and high CPU contention. In other words, our rule engine was both expensive and slow. gnata has no such limitations, so we were able to replace the rule engine internals with a far simpler and more efficient implementation. The details of the refactor deserve their own blog post, but they involved just-in-time batching (based on the request coalescing pattern), short-lived caches and grouped enrichment queries (done right before evaluation). I was quite surprised myself with the throughput increase the refactor brought - and with it, a sharp drop in resource utilization. The result: another ~$18K/month off the bill - around $200K/year. Combined with gnata, that's $500K/year gone from the pipeline, all in under 2 weeks of work. No longer just vibe coding There's an active debate over whether fully hands-off AI code belongs in production. I have some strong opinions on this (which I've been vocal about internally). But gnata has been a good case study for when it works well. Andrej Karpathy recently wrote that programming is becoming unrecognizable, and that at the top tiers, deep technical expertise is "even more of a multiplier than before because of the added leverage." Until recently, I was rather skeptical of agentic code. February 2026, however, has been a sort of inflection point even stubborn developers like myself can't ignore. I believe gnata is just the beginning. I suspect 2026 will be the year of surgical refactors. Try it go get github.com/recolabs/gnata expr, _ := gnata.Compile(`user.role = "admin" and user.loginCount > 100`) json := []byte(`{ "user": { "email": "admin@example.com", "role": "admin", "loginCount": 247 } }`) result, _ := expr.EvalBytes(ctx, json) fmt.Println(result) // true Full docs, streaming API, and WASM playground: github.com/RecoLabs/ gnata No items found. Request a demo and explore Reco in action Request a demo [65abefc9dc] [66e202e1c0] Nir Barak [65c10e8e2a][65c10e8df0][67c44d86cd] ABOUT THE AUTHOR Nir Barak is the Principal Data Engineer & Architect at Reco. He has deep expertise with implementing scalable systems that handle billions of events a day. Technical Review by: Gal Nakash Technical Review by: Nir Barak [66e202e1c0] Nir Barak is the Principal Data Engineer & Architect at Reco. He has deep expertise with implementing scalable systems that handle billions of events a day. [65c10e8e2a][65c10e8df0][65c10e8c97] Request a Demo [69c41472d9] Ready to Close the SaaS Security Gap? [68655190a8] Chat with us Table of Contents Overview Get the Latest SaaS Security Insights Subscribe to receive updates on the latest cyber security attacks and trends in SaaS Security. [ ][Subscribe] Thank you! Your submission has been received! Oops! Something went wrong while submitting the form. Explore Related Posts [69bcc7acd7] 5 min read SaaS Security Closing the Context Gap: How Reco and Torq Automate the "Risky Employee" Investigation Yaniv Blum March 20, 2026 When an employee is flagged as a potential insider threat, traditional investigations can take analysts hours of manual cross-referencing across dozens of fragmented tools -- but Reco and Torq's new Agent-to-Agent workflow changes that entirely. By combining Reco's deep SaaS identity intelligence with Torq's HyperSOC orchestration, the workflow autonomously pulls context from across the security stack -- EDR, DLP, SASE, and cloud security -- to deliver a confident, natural-language verdict in seconds. The result is fewer false positives, dramatically reduced MTTR, and analysts who can focus on remediation instead of chasing data. [69ba1e3fea] 6 min read SaaS Security Introducing Full AI Agent Visibility for SaaS Andrea Bailiff-Gush March 17, 2026 Organizations have thousands of AI agents operating across their SaaS environments, yet security teams have no visibility into what's running or what permissions these agents hold. AI agents create toxic combinations by connecting systems in ways that produce permission breakdowns traditional tools can't detect. Reco's AI agent security discovers every agent, maps the connections between systems, and gives teams control to manage risk. [69b4199ba8] 6 min read Cyber Attack Inside the ShinyHunters Experience Cloud Campaign: IOCs, Detection Logic, and What's at Risk Nitay Bachrach March 12, 2026 Reco is actively investigating a ShinyHunters campaign targeting organizations running Salesforce Experience Cloud sites with misconfigured guest user profiles. By exploiting publicly accessible Aura API endpoints, the threat actor claims to have compromised between 300 and 400 organizations -- with cybersecurity companies deliberately targeted to enable downstream supply chain attacks. This post covers the campaign's IOCs, the detection logic needed to hunt for it in Salesforce Event Monitoring, and the underlying misconfiguration that makes it possible. See more featured resources [67b9f0c056] Ready for SaaS Security that can keep up? Request a demo Reco - SaaS security platfrom Reco is the leader in Dynamic SaaS Security -- the only approach that eliminates the growing gap between what you can protect and what's outpacing your security. Reco keeps pace with SaaS sprawl, no matter how fast it evolves, by covering the entire SaaS lifecycle -- cradle to grave. Request a demo[68655190a8] Chat with us [68656581d7] Chat with us Memberships Reco is a member of the Forbes technical counsil.Reco is a member of the cloud security alLiance (CSA).[685f80aefa] Accreditations AICPA for RecoAICPA for RecoReco - ISO 27001Reco - ISO 27001Reco - ISO 27001 [669d285854][67ab8945d3][67ab895ac8][67ab896bc5][67ab897b7d] [67ab898cb5][6880d1df5c][67ab89b443][68ee78cd48] Platform Posture ManagementApp Discovery & GovernanceIdentity & Access GovernanceThreat Detection & ResponseData Exposure ManagementShadow App DiscoveryGenerative AI DiscoveryAgentic AI SecurityReco AI Agents AI Governance and SecuritySaaS App Factory(tm) Use Cases Shadow SaaS DetectionSaaS Ticketing WorkflowUnsanctioned Apps Control SaaS OffboardingCustom Policy StudioShadow AI DiscoveryIdentity Governance ComplianceAI-Powered SaaS Security Insights Integrations By App All Supported ApplicationsSalesforceMicrosoft 365Google Workspace ServiceNowWorkday ServiceNow soon SlackOktaVeeva Resources BlogLearnIT HubCustomer StoriesWebinarsCompareSSPM ReportCISO Guide Financial GuideHealthcare GuideSalesforce GuideMicrosoft GuideAI Security GuideShadow AI GuideState of SaaS Security ReportThe State of Shadow AI ReportResource Center Company About Reco Careers Hiring NewsroomBrand GuidelinesPartnersTrust CenterContact Us Top Content SaaS SecurityWhat is SSPMCISO Hub Use Cases Detect Shadow SaaSSaaS Ticketing WorkflowUnsanctioned Apps Control SaaS OffboardingCustom Policy StudioShadow AI DiscoveryEnsure Identity Governance ComplianceAI Powered SaaS Security Insights Memberships Reco is a member of the Forbes technical counsil.Reco is a member of the cloud security alLiance (CSA).[685f80aefa] Accreditations [669d285854][67ab8945d3][67ab895ac8][67ab896bc5][67ab897b7d] [67ab898cb5][6880d1df5c][67ab89b443][68ee78cd48] AICPA for RecoAICPA for RecoReco - ISO 27001Reco - ISO 27001Reco - ISO 27001 TermsPrivacy (c) 2026 Reco. All Rights Reserved.