Security Data Works

MOAR Stack · Performant

Table format & wire (Iceberg + Arrow).

The open table any engine can read off cheap object storage, and the columnar wire that moves data between tools without a parse tax at each hop. Lab tests at a billion rows found that the Parquet writer governs both read speed and file size, not the table format: byte-identical files read at parity across most queries, and at a matched codec PyArrow wrote 193 MB to DuckDB's 114 MB on the same data, so the usual claim that Iceberg is more storage-efficient than DuckLake turns out to be measuring the writer.

Performant component · 11 essays

Listed from the front door down to the measured evidence. Start here marks the entry essay. The reading-level tag says whether you are reading the frame (Orientation), the argument (Depth), or a first-party finding (Evidence). The durability tag flags durable architecture versus an Evidence-pinned result tied to a version or price.

Evidence

Capability Matrix

The Matrix scores format openness, engine reach, and the write-path mechanics.

See the Capability Matrix →

← The MOAR Stack