Skip to main content

OpenSearch Octane, only from Lucenia

Your OpenSearch cluster, measurably better

Four modules that drop into the cluster you already run. Your mappings do not change, your queries do not change, and nothing phones home.

curl -fsSL https://getoctane.lucenia.io | sh

The Advisor

Start by finding out what’s actually wrong.

A free, read-only tool that reads your cluster over its REST API and writes one self-contained page. No licence, no trial, no expiry. It works the same whether or not you ever buy anything.

Critical · checked first

Which published CVEs your cluster is exposed to.

Before anything about shards or heap, the report opens with the vulnerabilities the version on each of your nodes is actually subject to — matched against the affected-version ranges in the advisory itself, not guessed from a version number.

  • CVE-2025-9624Denial of service via complex query_string input. Every OpenSearch below 3.3.0.HIGH 8.3
  • CVE-2022-35980Information disclosure: document- and field-level security not applied when a query matches an aliased index.HIGH 7.5
  • CVE-2023-31141Fine-grained access control rules not applied on a particular request path.MEDIUM 4.8

A clean result is never silent. Every run states how many advisories it compared, where they came from and the day they were generated — because an empty security section and an unrun check look identical, and only one of them is good news. If the data is older than an OpenSearch release cycle, the report says so instead of calling it an all-clear.

One command

Needs a JDK and nothing else. Verifies its own download, runs, and writes a page you can mail to whoever owns the budget.

It only reads

Every request to your cluster is a GET, and no data about it ever leaves your machine. Nothing is ever sent to Lucenia — running it tells us nothing, not even that you ran it.

Numbers, not opinions

Every finding carries the figures it was computed from, so you can check it against _cat/shards in thirty seconds.

And what to do

Each one comes with the exact command, built from your own cluster’s values — real index names, ready to paste.

The modules

Four things. Buy one, or buy all of them.

Each is independent. The licence plugin is shared, and nothing phones home.

Accelerator

Faster shape and vector queries.

Benchmarked against stock OpenSearch on the same hardware and the same data. Your mappings do not change, your queries do not change, and your application does not know it is there.

  • 1.24× faster shape and range queries
  • 32× less memory per candidate on vector search
  • Semantic ontologies and meaning-based retrieval — read how it works

From $6,103/year

24%faster geo_shape and range queries against stock OpenSearch — reproducing on every clean run

Bytes read per candidate, 768 dimensions

Stock OpenSearch3,072
Octane96

The read that happens on every query, every candidate. OpenSearch’s own vector codec has no binary quantization at all.

Governance & Compliance

Redact it before it’s ever indexed.

The compliance engine finds sensitive values and redacts them before writing, so the cluster never holds what you are not allowed to keep. Eleven regulatory profiles, four redaction modes, and detectors you can define at runtime without a redeploy.

  • Policies mapped to the regimes auditors actually name
  • Per-organisation control over what may be ingested, and from where
  • Redaction at write time, not a filter on the way out

From $4,359/year

11regulatory profiles, with the entity mappings curated rather than hand-listed

A compliance control is bought against an auditor’s deadline, not a benchmark — so this one is priced above content and below the accelerator.

Content Extraction

Documents and imagery, made searchable.

Extraction, chunking and embedding in the ingest pipeline, plus the geospatial stack: imagery tiling, reprojection, and raster sources read by range request rather than downloaded whole.

  • Text extraction and chunking with embeddings in one pass
  • Cloud-optimised GeoTIFF read by byte range
  • Reprojection across the EPSG codes that matter

From $3,836/year

1pass from document to searchable, embeddings included

Fetches are governed: deny-by-default control over which sources a cluster may read, so ingest cannot be turned into an exfiltration path.

Autoscale

It installs nowhere.

A controller you run beside the cluster, not a plugin you install into it. No per-node install, no restart, and it works against a managed OpenSearch domain where you could not install a plugin at all.

  • Scale-out in one step; scale-in only after a safety check
  • Never removes the last started copy of a shard
  • Recommends by default — nobody should let a new autoscaler delete nodes on day one

From $3,139/year

0nodes to restart, because there is nothing to install

A licence gates starting work, never finishing or undoing it: a drain writes an allocation exclusion that something has to remove.

Air-gapped by default

Nothing phones home. Ever.

No licence server, no metering call, no telemetry. A licence is a signed file your cluster verifies against a public key it already has, offline, at install and at every gate. If it lapses, capability degrades — your data stays readable, because a billing problem must never become an outage.

Pricing

Priced per data node, billed annually.

Move the slider to your cluster’s data node count. Every figure below is the amount charged — there is no rounding between this page and your invoice.

25
$13,950 /year

All four modules for 25 data nodes, billed annually.