Abstract Security
Abstract Security is a venture-backed, AI-native composable SIEM platform that ingests, normalizes, and detects threats in streaming security telemetry before storage, serving enterprise security teams seeking to reduce SIEM costs, accelerate detection, and migrate off legacy monolithic SIEMs without vendor lock-in.
- Company typePrivate
- Founded2023
- HeadquartersSan Francisco, United States
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What Abstract Security does
Abstract Security is a venture-backed cybersecurity company founded in 2023 and headquartered in the San Francisco Bay Area that sells an AI-native, streaming-first security data platform branded as the AI-Gen Composable SIEM. The platform is architected as four independent, interoperable building blocks — Collection (a security data fabric that ingests, normalizes, enriches, masks, and routes telemetry), a Detection Fabric that supports in-stream, historical, and federated detection decoupled from storage, tiered Retention (Real-Time/Hot/Warm with a LakeVilla cold storage layer), and AI-Enabled SecOps (the embedded Astro assistant for triage, investigations, natural-language search, MITRE ATT&CK mapping, and SOAR automation). The product sits between cloud, SaaS, identity, endpoint, and network telemetry sources and downstream SIEMs or data lakes (Splunk, Microsoft Sentinel, CrowdStrike Falcon NGSIEM, Google SecOps, Palo Alto Cortex XSIAM, SentinelOne, Elastic, AWS Security Lake), with 100+ pre-built integrations enabling vendor-agnostic SIEM migration.
The company generates revenue through quote-based annual and multi-year enterprise subscriptions, with usage- or volume-sensitive components tied to data volume; fees are paid in advance under negotiated Order Documents and pricing is not publicly disclosed. Go-to-market is primarily sales-led and direct, supplemented by an Abstract Partner Program with deal registration for MSSPs, VARs, and resellers, and co-sell motions with AWS, Microsoft, Google Cloud, SentinelOne, CrowdStrike, Elastic, Palo Alto, Splunk, Netskope, and Torq. The customer base spans enterprise and startup buyers across verticals including consumer products (Juul Labs), financial services (OneMain Financial), supply chain intelligence (Altana), legal (a Global Law Firm), and security services (OmegaBlack); the company cites 380% YoY ARR growth, 264% net revenue retention, and 280% growth in new customers during a period when it made 40 strategic hires and expanded into EMEA, APJ, the Middle East (via a hosted GCP solution in Saudi Arabia), and India engineering.
Abstract is led by a founder team drawn from the builders of ArcSight, Anomali, and Verodin — CEO Colby DeRodeff (also co-founder of Anomali), COO Chris Camacho (formerly CSO/CRO at Flashpoint), and Chief Threat Research Officer Aaron Shelmire (CERT.org, Secureworks, Anomali, Palo Alto Networks). The company emerged from stealth in March 2024 with an $8.5M seed round led by Crosslink Capital, Rally Ventures, and Liquid 2 Ventures, then closed a $15M Series A in October 2024 led by Munich Re Ventures, bringing cumulative disclosed funding to approximately $28.5 million; an additional capital raise has been indicated by leadership.
Abstract Security firmographics
Firmographics- Name
- Abstract Security
- Legal name
- Abstract Security Inc.
- Website
- https://abstract.security
- Company type
- Private
- Founded year
- 2023
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- Abstract Security is a venture-backed, AI-native composable SIEM platform that ingests, normalizes, and detects threats in streaming security telemetry before storage, serving enterprise security teams seeking to reduce SIEM costs, accelerate detection, and migrate off legacy monolithic SIEMs without vendor lock-in.
- Ownership category
- akta.pro rank
Abstract Security industry classification
Industry- Product category
- Security Information and Event Management (SIEM)
- NAICS
- Computer Systems Design and Related Services (5415), Computer Systems Design Services (541512)
- SIC
- Services-Computer Integrated Systems Design (7373), Services-Computer Programming Services (7371)
- akta.pro primary industry
- SIEM Platforms & Log Management (HDADAGAA)
- akta.pro secondary industries
- Cloud Security Logging, SIEM/SOAR & Threat Detection (HDABAHAL), Attack Detection & Response for Cloud/SaaS (SOC for Cloud) (HDADAGAJ)
Keywords
Where Abstract Security is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Offices5 records
Markets served
Abstract Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- Subscription SaaS for AI-Gen Composable SIEM Platform: Recurring subscription access to the Abstract platform under Order Documents, with fees paid in advance and abstracted volumetric pricing tied to data, users, or capacity; customer agrees to non-sublicensable internal use for cyber threat identification, assessment, and response.
- Enterprise Expansion and Land-and-Expand: Reported 380% YoY ARR growth, 264% net revenue retention, and 280% increase in new customers indicate a land-and-expand subscription model with upsell across collection, detection, retention, and AI SecOps modules.
- Channel and Partner Sourced Revenue: Deal registration through the Abstract Partner Program with resellers, MSSPs, and VARs generating partner-sourced subscription revenue and supporting co-sell motions.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Quote-based enterprise subscription under Order Document |
| Usage-based | Multi-year contract | Usage- and volume-sensitive component tied to data volume reduction |
Go-to-market motion1 record
Distribution channels5 records
Marketing channels9 records
Abstract Security product offering
Product offeringCore offering
Abstract Security builds and sells an AI-native, streaming-first Composable SIEM platform that deconstructs traditional SIEM into four independent, interoperable layers — Collection (Security Data Fabric), Detection Fabric, Retention (including LakeVilla cold storage), and AI-Enabled SecOps (Astro) — so enterprise security teams can ingest, normalize, enrich, detect, retain, and analyze security telemetry without vendor lock-in. The platform reduces data volumes by 70-80% and reported SIEM costs by 65-75%, and supports incremental migration from legacy SIEMs such as Splunk, QRadar, Microsoft Sentinel, and CrowdStrike Falcon.
Product overview
Abstract Security's offering is a platform-plus-modules architecture branded as the "AI-Gen Composable SIEM." The unified core product is the Abstract Platform, which deconstructs security operations into four independent, interoperable building blocks — Collection (the Security Data Fabric), the Detection Fabric, Retention (including the LakeVilla cold storage layer), and AI-Enabled SecOps. Sitting on top of this core, Abstract sells a set of named add-ons: the Abstract Intel Gallery (AIG) for operationalized threat intelligence, the ASTRO threat research program that continuously publishes new detections, Abstract Compliance as an event-destination module, the Abstract Insights API for programmatic access, and the free Abstract Splunk Data Reduction Calculator App. Customers can adopt any single module standalone and add the others over time, with Abstract's vendor-agnostic pipelines letting teams route enriched data to existing SIEMs (Splunk, Microsoft Sentinel, CrowdStrike Falcon NGSIEM, Elastic Security, Google SecOps, Palo Alto Cortex XSIAM, SentinelOne Singularity, AWS Security Lake) or use Abstract as the SIEM of record.
Differentiator
Problem solved
Functional benefit
Brands
- AI-Gen Composable SIEM: Abstract Security's AI-native, streaming-first, modular SIEM platform architecture designed for modern security operations.
- ASTRO (Abstract Security Threat Research Organization)
- Astro
Products and services
- AI-Gen Composable SIEM Platform The unified core product marketed as the AI-Gen Composable SIEM — a streaming-first, AI-native platform that deconstructs SIEM into four independent building blocks (Collection, Detection, Retention, AI-Enabled SecOps) so enterprise security operations teams can assemble data, detection, and operations workflows without vendor lock-in. Targets CISOs, security architects, and SOC leaders replacing or augmenting legacy SIEMs.
- Collection (Security Data Fabric) A standalone security data fabric and control plane that ingests telemetry from cloud, SaaS, network, endpoint, and identity sources; normalizes to OCSF, ECS, or Splunk CIM schemas; enriches with asset, identity, Geo-IP, and threat-intel context; masks PII/GDPR/HIPAA/PCI; and routes data to multiple downstream SIEMs, data lakes, or compliance destinations. Sold standalone or as part of the AI-Gen Composable SIEM.
- Detection Fabric A standalone detection module that runs portable detection logic in-stream, historically (1D-3Y replay against cold storage), and federated across AWS, GCP, Azure, and on-prem environments. Decoupled from storage and ingestion assumptions, with sub-second streaming correlation and a no-code visual builder. Sold standalone or as part of the AI-Gen Composable SIEM.
- AI-Enabled SecOps (Astro) Standalone AI module that embeds generative AI (Astro / Colby) across triage, investigation, threat hunting, case management, and response — including natural-language search, AI-generated incident narratives, MITRE ATT&CK mapping, hypothesis-driven hunting, and AI-documentation of every investigation. Sold standalone or as part of the AI-Gen Composable SIEM.
- Retention (Multi-Tier Storage with LakeVilla) Standalone multi-tier retention module offering Real-Time, Hot, and Warm storage tiers plus the LakeVilla cold storage layer built on AWS S3, Azure Blob, and GCS. Enables instant query on archived data without rehydration or retrieval fees, and supports GDPR, SOC2, FedRAMP, and PDPA data residency requirements. Sold standalone or as part of the AI-Gen Composable SIEM.
- Abstract Intel Gallery (AIG) An add-on module that operationalizes threat intelligence detection by applying curated OSINT and third-party intelligence (VirusTotal, Shodan, Flashpoint, Recorded Future, Silent Push, Cyware, BforeAI) to Abstract detections, accelerating analyst investigations and reducing time-to-detect.
- LakeVilla Cold Storage A cloud-native cold storage layer built on AWS S3, Azure Blob, or Google Cloud Storage that allows instant querying of archived security logs without rehydration steps or retrieval charges, supporting retroactive threat hunting and rule validation.
- Abstract Insights API A standalone API in the Tooling category that provides programmatic access to Abstract platform insights and security data for partners, MSSPs, and downstream automation use cases.
- Abstract Splunk Data Reduction Calculator App A free app that installs directly into Splunk environments to analyze indexes and sourcetypes, surfacing dominant data sources, projected data reduction opportunities by integration type, and before/after visualizations of expected volume reduction.
- ASTRO (Abstract Security Threat Research Organization) Abstract's in-house threat research team and productized program that continuously builds and updates detection rules mapped to real-world adversary behavior, publishes campaign analyses, and focuses on SaaS- and cloud-native adversary behaviors (account takeover, OAuth abuse, privilege escalation, data exfiltration, CloudTrail abuse, LLMJacking).
- Abstract Compliance A compliance event-destination module in the Abstract integrations catalog that routes and stores compliance-grade security telemetry for regulated retention requirements.
Quantifiable outcome
- 70-80% average reduction in data volume before data reaches the SIEM or data lake
- +6 more outcomes
Companies that use Abstract Security
Customer profileNamed customers6 records
Segments2 records
Ideal customer profiles2 records
Abstract Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration34 records
AI capability12 records
Feature9 records
Abstract Security partnerships and signals
Strategic signalScale indicators12 records
Recent moves7 records
Abstract Security competitors and assessment
Company assessmentDirect peers
- Cribl: Cribl Stream is the closest direct competitor: a vendor-agnostic observability and security data pipeline that filters, routes, and enriches telemetry before reaching SIEMs and data lakes. Both Abstract and Cribl target the same SIEM cost-reduction and vendor lock-in narrative with comparable architectural approaches.
- Panther Labs: Panther is a cloud-native SIEM built for security teams that need detection-as-code, scalable log storage, and AWS-native deployment. It competes directly with Abstract's composable, cloud-first SIEM thesis and targets the same modern enterprise SOC customer.
- Hunters: Hunters provides a cloud-native SIEM with built-in detection engineering, automated correlation, and AI-assisted investigation. It directly competes with Abstract's AI-Enabled SecOps module for enterprise SOC modernization budgets.
- Exabeam: Exabeam is a cloud-native SIEM combining log management, behavior analytics, and automated investigation. It competes with Abstract on the same SIEM-replacement use case for mid-to-large enterprises, with a similar AI-driven SOC value proposition.
- Devo Technology: Devo offers a cloud-native SIEM and analytics platform with high-throughput log ingestion and integrated security operations workflows, overlapping with Abstract's Collection and Detection modules for security data fabric customers.
- Sumo Logic: Sumo Logic is a cloud-native log management and security analytics platform with continuous intelligence and integrated SIEM-style workflows. It competes with Abstract for customers seeking cloud-first log analytics and security operations.
Emerging players
- Tenzir: Tenzir is an emerging security data pipeline platform that ingests, normalizes, and routes security telemetry across SIEMs and data lakes. It targets overlapping use cases with Abstract's Collection module, particularly for SOC teams seeking vendor-agnostic data flows.
Broad incumbents
- Splunk (now Cisco): Splunk is the dominant enterprise SIEM and analytics platform, now owned by Cisco. Abstract explicitly positions against Splunk's cost structure and lock-in, and its data-reduction ROI claims are benchmarked against Splunk deployments.
- Microsoft Sentinel: Microsoft Sentinel is a hyperscaler-scale cloud-native SIEM embedded within the Azure ecosystem. Abstract runs upstream of Sentinel (and explicitly supports migration away from QRadar to Sentinel), making Sentinel both a competitor and a key integration partner.
- Google SecOps (Chronicle): Google SecOps (formerly Chronicle) is Google's cloud-native SIEM offering with petabyte-scale log management and built-in detections. Abstract integrates with and complements Google SecOps while competing for the same enterprise SIEM-modernization dollars.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights6 records
Customer concentration
Abstract Security social profiles
Digital presenceAbstract Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Abstract Security leadership team
Management profileNumber of profiles
Profiles15 records
Abstract Security funding detail
Funding detailFunding overview
Funding rounds4 records
Investors7 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Abstract Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Abstract Security
What does Abstract Security do?
Abstract Security builds and sells an AI-native, streaming-first Composable SIEM platform that deconstructs traditional SIEM into four independent, interoperable layers — Collection (Security Data Fabric), Detection Fabric, Retention (including LakeVilla cold storage), and AI-Enabled SecOps (Astro) — so enterprise security teams can ingest, normalize, enrich, detect, retain, and analyze security telemetry without vendor lock-in. The platform reduces data volumes by 70-80% and reported SIEM costs by 65-75%, and supports incremental migration from legacy SIEMs such as Splunk, QRadar, Microsoft Sentinel, and CrowdStrike Falcon.
Is Abstract Security a public or private company?
Abstract Security is a private company. It is classified as venture growth investor backed and is currently operating.
When was Abstract Security founded?
Abstract Security was founded in 2023. It employs 51 to 100 people.
Where is Abstract Security based?
Abstract Security is headquartered in San Francisco, United States, in the North America region.
How does Abstract Security make money?
Three revenue lines are on record. Subscription SaaS for AI-Gen Composable SIEM Platform is the primary driver. The others are enterprise Expansion and Land-and-Expand and channel and Partner Sourced Revenue.
Who are Abstract Security's main competitors?
Direct peers on record are Cribl, Panther Labs, Hunters, Exabeam, Devo Technology and Sumo Logic. Tenzir is listed as an emerging player. Broad incumbents are Splunk (now Cisco), Microsoft Sentinel and Google SecOps (Chronicle).
Does Abstract Security have an API?
Yes. Abstract Insights API is listed in the integrations catalog under the Tooling category, allowing programmatic access to insights and platform data. No detailed public documentation URL, SDK language, auth method, rate limits, or sandbox information is disclosed in the source material.
What industry is Abstract Security in?
Abstract Security's product category is Security Information and Event Management (SIEM). Its primary akta.pro industry code is HDADAGAA, SIEM Platforms & Log Management, with a secondary code of HDABAHAL, Cloud Security Logging, SIEM/SOAR & Threat Detection. Its NAICS code is 5415 and its SIC code is 7373.