Artemis Security

Security OperationsDetection Response also known as Artemis, Artemis Global Technologies

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2025
Funding $70M
Last updated 2026-08-25

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Artemis Security sells an alternative to the SIEM, the central log platform security teams use to detect and investigate attacks. It generates detections for each customer’s environment and investigates the alerts those detections raise. It also sells a managed service: senior Artemis analysts who operate the platform inside a customer’s environment, check what it finds and own the response. Cursor moved off its previous log platform onto Artemis. Fortune named Mercury, Wix, Lemonade and Abnormal AI as clients when the company left stealth in April 2026. Artemis or one of its partners published almost every account of what the product did inside a customer, so a buyer checking those results has little else to read.

Sourced Details

Description Artemis Security builds a security operations platform that maps each customer’s environment and business context, generates environment-specific detections, investigates alerts automatically, and stages response actions for approval across identity, cloud, endpoint, network, and SaaS activity. [f1]
Founded 2025 [f2]
HQ New York, New York, US [f2]
Funding $70M total [f3]
Latest funding Series A, $55M (April 2026) [f2]

Products

Product What it does
Artemis Protection platform that detects threats, investigates autonomously across log sources, and delivers cases with response actions, streaming detection-critical logs and querying the rest on demand.

Matrix Coverage

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

Artemis correlates identity, cloud, endpoint and SaaS activity to surface multi-step attacks that single-source detections miss. Artemis is mapped to the Cyber Defense Matrix. [f4]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 25 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 The buyer is the enterprise security operations team and the problem is stated precisely: paying to ingest telemetry, generic detections, and attacks that finish faster than manual triage. An SC Media brief positions the product against traditional platforms that can incur significant data streaming costs, which carries the cost half of the argument. Every figure that sizes the pain, the 96 percent cut in resolution time and the 94 percent cut in detect and respond time, traces back to Artemis, so the scale of the problem is asserted rather than measured independently. [s18, s1, s20, s21]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 The vendor’s platform pages, a catalog of 152 named connectors and two customer accounts describe the mechanism concretely, down to detector authoring in plain language and correlation across more than twenty log sources at Cursor. What is missing is a check from outside the vendor that bears on that capability: the reviewed sources carry no evaluation by a party independent of Artemis and no inspectable code, and the one hands-on write-up names Artemis as its author’s partner. [s4, s6, s7, s8, s15, s22]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 The enabler is dated: AI-orchestrated attacks that compress an intrusion from days to minutes, which Artemis documents in its July 2026 customer account and its chief executive repeats in the April 2026 launch coverage. Buyers have moved, with Fortune naming four clients at that launch and Cursor replacing its previous log platform, so the need is not one only the vendor argues. The demand evidence stops there: an independent research report examines the category without carrying survey or adoption data, and a marketplace listing is a route to buy rather than a sign buyers are searching. [s7, s16, s21, s1, s9]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 Shachar Hirshberg led product for Amazon GuardDuty, which GovInfoSecurity states in its own voice, and Fortune places Dan Shiebler as head of AI at Abnormal Security after a machine learning leadership role at Twitter, where the About page says he built the organization behind its web ads product. That is one named build documented outside the company plus senior in-domain roles. The reviewed record shows no business either founder took to an exit and no sustained publication record. [s17, s16, s2]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 Fortune named Mercury, Wix, Lemonade and Abnormal AI as clients and reported a spokesperson saying the company had closed a few seven-figure deals. Artemis has since published full accounts of two customers, Cursor and Lemonade. A buyer can contract through direct sales or the AWS Marketplace listing, and CrowdStrike, AWS and NVIDIA name Artemis in the 2026 cohort of the accelerator they run together. Scale itself stays uncorroborated, because no source outside the company reports revenue or a customer count. [s16, s7, s8, s9, s14]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 2/5 Seventy million dollars raised inside roughly six months of founding still sits against no disclosed revenue, margin or growth-per-dollar figure, and the recurring revenue on the record is the company’s own projection for the end of 2026. The efficiency-adjacent evidence in the record is real and confirms nothing about output per dollar: a Datadog case study puts the company at about fifty people and credits 280,000 dollars of annualized AI cost savings. [s18, s17, s16, s12]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 4/5 Others place the company without vendor coaching. GovInfoSecurity calls it a SIEM replacement startup, an SC Media brief positions it as an alternative to traditional SIEM platforms, MSSP Alert files the launch under a new generation of AI-powered SIEMs, an independent research report profiles it inside a security operations operating model, and the AWS Marketplace lists it under AI Security. The strongest recognition Artemis displays, an analyst selection, sits in a report the reviewed sources do not carry, so it stands as vendor-displayed rather than independently confirmed. [s17, s18, s19, s21, s9, s1]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 Detections tuned per environment and a model of the customer’s organization build friction that grows with deployment time, and retrieving data on demand pressures the ingest-priced economics incumbents sell on. Nothing in the reviewed record turns that into a structural barrier: the agents reason on models from an outside provider, and every customer runs in a dedicated single-tenant environment, so the record shows no asset that accumulates as customers are added. [s7, s13, s11, s14]
Business Risks Platform vendors already inside these accounts could add comparable AI investigation to products enterprises license today…
  • Platform vendors already inside these accounts could add comparable AI investigation to products enterprises license today. If that closes enough of the speed gap, the Artemis difference narrows to price before its reference base broadens.
  • Retrieving data on demand depends on telemetry sitting in sources Artemis can query. Enterprises whose logging is appliance-bound or on premises, without supported query access, blunt the cost advantage that anchors the pitch.
  • The managed service commits Artemis to putting human eyes on every customer-visible case at a company the record counts at about fifty people, on a figure that carries no date. If hiring lags what that service promises, the accountability it sells is what a customer notices missing first.
  • The efficacy figures a buyer meets first, a 96 percent cut in resolution time and a 94 percent cut in detect and respond time, come from Artemis, and the reviewed sources hold no independent test of either.
  • Artemis runs its detection and investigation agents on a licensed model service that its Trust Center lists as a subprocessor. A price increase or a capability change there would reach the Artemis cost base and product behavior directly.
  • Fortune reports startups proliferating with similar claims about autonomous detection and response. If those buyers prefer adding a layer to the platform they already run, Artemis faces the harder replacement sale with a younger product.
Problem & Market Artemis Security sells to enterprise security operations teams that pay to collect telemetry and still lose ground to attacks that outrun manual triage…

Artemis Security sells to enterprise security operations teams that pay to collect telemetry and still lose ground to attacks that outrun manual triage. The company argues that traditional log platforms charge for ingesting and storing everything, hand analysts a rule match to start from and leave the investigation to them. It offers two ways in, replacing that platform or running beside it, and its own page says a customer sets the pace.

Independent coverage carries the cost half of that argument. An SC Media brief summarizing SiliconANGLE coverage positions the product as an alternative to traditional SIEM platforms that can incur significant data streaming costs, and GovInfoSecurity describes a company that emerged from stealth to identify threats by better correlating telemetry data. The problem is established industry background rather than one Artemis has to teach a buyer.

The numbers that size the pain trace back to Artemis. Its homepage claims a 96 percent reduction in mean time to resolution, and an AlleyWatch article prints a 94 percent reduction in detect and respond time for early customers. No independent test of either figure appears in the reviewed sources, so a buyer weighs them against their own alert volume. [s18, s17, s1, s20, s4]

Product Capabilities A model of the customer’s environment is the platform’s claimed foundation…

A model of the customer’s environment is the platform’s claimed foundation. Artemis says it builds a living model of every user, account, device, resource and AI agent from identity providers, HR systems, asset management and business context, and applies that model when a detection runs rather than after an alert fires. Artemis says its research team maintains comprehensive MITRE ATT&CK coverage and that detectors written for one environment tune themselves as that environment shifts.

The data design is hybrid rather than purely federated. Artemis ingests the hot-path data detection depends on and queries high-volume sources where they already sit, which is how it argues for full visibility without the ingest bill. Its catalog lists 152 connectors across cloud, identity, endpoint, network, SaaS, log platforms and threat intelligence.

Published capability detail grew this quarter. The Cursor account describes correlation across more than twenty log sources, thousands of detectors tuned to that one environment, detector authoring in plain language with version history and rollback, and more than 1,200 threat hunts in a quarter. A second account covers Lemonade. Artemis also sells a managed service that puts senior analysts inside the customer’s environment to check what the platform finds and to own the response.

A buyer who wants to check the platform without Artemis has little to work with. No documentation portal and no self-service trial appear on the surfaces the reviewed sources cover, and no evaluation by a party independent of Artemis appears in them. The one hands-on write-up in the record comes from a newsletter whose author names Artemis as its partner, so a buyer assessing the capability reads what Artemis and its partners publish. [s1, s4, s6, s7, s8, s5, s22, s15]

Competitive Positioning Artemis positions against the legacy log platform rather than a named rival…

Artemis positions against the legacy log platform rather than a named rival. Its own pages contrast the product with platforms that deliver an alert and leave the investigation to the analyst, and with detection content that decays from the day a person stops maintaining it. Press sharpens the target, with GovInfoSecurity calling it a SIEM replacement startup and an SC Media brief positioning it as an alternative to traditional SIEM platforms.

The structural argument is economic. Artemis argues that traditional architectures charge for ingesting and storing everything, on a cost model that scales with data volume, so retrieving data on demand pressures the revenue line those platforms sell on. The reviewed sources do not show an incumbent changing its packaging in response. The counterweight is the shape of the sale, because a replacement means displacing a platform the buyer already pays for. Artemis hedges that by offering to complement or replace the existing platform at the pace the customer chooses.

CrowdStrike sits on both sides of that line. It sells security operations tooling to the same enterprise buyer, it runs the 2026 startup accelerator with AWS and NVIDIA whose cohort names Artemis, and Artemis reproduces a post from CrowdStrike’s chief business officer welcoming the launch. Fortune describes a crowded and rapidly evolving space, with startups proliferating around similar claims about autonomous detection and response. Artemis competes with them on the same ground when it runs beside an existing platform. [s1, s17, s18, s14, s4, s16]

Go-to-Market & Traction Customer evidence is named, and Artemis publishes most of it…

Customer evidence is named, and Artemis publishes most of it. Fortune named Mercury, Wix, Lemonade and Abnormal AI as clients in April 2026 and reported a spokesperson saying the company had closed a few seven-figure deals. Artemis has since published two full customer accounts, Cursor in July and Lemonade in August 2026, and its homepage publishes endorsements from named security leaders, among them Sony’s senior director of cyber defense and Upwork’s senior director of active defense.

Distribution runs wider than direct sales. The AWS Marketplace listing lets a buyer contract and bill through AWS, the careers page carries a channels and partnerships lead and a technology alliances manager, and CrowdStrike, AWS and NVIDIA name Artemis in the 2026 cohort of the accelerator they run together.

The commercial organization is still forming. The chief executive fronts the launch coverage and authors company posts, and the careers page lists fourteen openings including an enterprise account executive, a founding customer success engineer, a technology alliances manager, a security operations manager and a security analyst. Artemis also sells a managed service in which its own analysts operate the platform for a customer. [s16, s7, s8, s1, s9, s3, s14, s5, s23]

Team & Credibility The founders’ backgrounds map onto the product…

The founders’ backgrounds map onto the product. Shachar Hirshberg led product for Amazon GuardDuty, which GovInfoSecurity reports in its own voice, and the About page adds an early role at Demisto and an engineering leadership role at Palo Alto Networks. Fortune places Dan Shiebler as head of AI at Abnormal Security and earlier a machine learning leader at Twitter, and the About page says he built the machine learning organization behind Twitter’s web ads product.

Headcount evidence is dated and partial. GovInfoSecurity reported 30 employees at the April 2026 launch, and a Datadog case study lists the company at about fifty with no date attached to that figure. The reviewed sources name no executive beyond the two founders, so a buyer weighing leadership depth reads the founding pair and the roles the company is hiring for. [s17, s16, s2, s12, s3]

Trust Readiness Artemis publishes its compliance posture on a Trust Center named in the site footer…

Artemis publishes its compliance posture on a Trust Center named in the site footer. The rendered page lists ISO 27001:2022, SOC 2, HIPAA and GDPR, with a SOC 2 Type 2 report, an ISO 27001 certificate, an engagement letter, a security policy and a penetration test behind an access request. It also names the subprocessors behind the service, including the cloud provider, the hosted database provider, the authentication provider and the model service the agents run on.

Deployment evidence and a published tenancy design sit behind those attestations. The launch release reports production use in banking and financial services, sectors whose vendor reviews are demanding, and the case study Anthropic published states that customer data is never shared across tenants and is never used to train models. Because the reports are gated, a buyer requests them before a procurement review can confirm their scope. The AWS Marketplace listing gives buyers who prefer it a way to contract and bill through AWS. [s10, s13, s11, s17, s9, s5]

Competitors Splunk, Microsoft, CrowdStrike…
Company Relationship Note Compare
Splunk competes with Competes for the log platform budget line Artemis argues against, and Fortune quotes a partner at Felicis, which led the Artemis Series A, describing Artemis as positioning itself as an alternative to Splunk. Artemis also lists Splunk among the platforms it connects to. N/AWe scored these companies at different scopes, so the totals measure different things.
Microsoft competes with Sells Microsoft Sentinel to the same buyer, and Artemis lists it among the platforms it connects to. N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product.
CrowdStrike competes with Competes for the same security operations budget, supplies telemetry Artemis connects to, and co-runs the accelerator whose 2026 cohort names Artemis. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.

Add analyzed competitors to compare them side by side with Artemis Security.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 14 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Artemis reports correlating identity, cloud, endpoint and SaaS activity, and processing billions of events an hour, which is demanding engineering. It builds detections and a model of each customer’s organization separately for that customer, and the case study Anthropic published states that customer data is never shared between customers. The cited sources name no data asset that accumulates across customers, so the record shows no data advantage that compounds as Artemis adds accounts. Senior analysts now operate the platform for customers who buy the managed service, so Artemis sells expertise beside the software. Artemis holds ISO 27001 and SOC 2, credentials that ease a buyer’s review and that a funded rival can earn too.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 2/3 Customers buy software their own team operates, and Artemis now also sells a managed service in which its senior analysts work inside the platform on the customer’s environment, validate what it finds, own the response and take incident command. So a customer buys software in one case, and software plus Artemis staff in the other. The analysts act only within limits the customer sets per connector.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Detections and a model of the organization built for one customer, connector wiring across the stack and response integrations create friction that grows with deployment time. The cited record does not size the exit: Cursor keeps its own database under the deployment, Artemis offers to hold data or to leave it where it already is, and no cited source states what a migration away would take in duration, parties or complexity.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Artemis publishes ISO 27001:2022 and SOC 2 on its Trust Center, alongside HIPAA and GDPR statements and reports behind an access request. A funded competitor can obtain the same credentials through ordinary enterprise-market preparation, so they ease a procurement review without blocking a replacement.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Correlating identity, cloud, endpoint and SaaS activity, processing the billions of events an hour the company reports, generating and tuning detectors per environment, and running federated queries across heterogeneous stores is specialized engineering under adversarial pressure, the class of system the founders previously built at AWS and Abnormal AI.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 The named buyers are large enterprises, among them an insurance company whose account describes more than 500,000 assets under one security team. The launch release reports production use in banking and financial services, and the two purchase paths the record shows, direct sales and a marketplace contract, both run through a negotiation rather than a sign-up.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 Artemis spans the customer’s telemetry sources, its investigations and its response actions, which is more than a single-use application. No other software in the reviewed record depends on Artemis to function, which places it above a point tool and below the infrastructure other products are built on.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 What the cited record evidences is per-customer: environment models and detectors built for one tenant, with the case study Anthropic published stating that customer data is never shared across tenants or used to train models. The MITRE ATT&CK coverage the research team maintains is coverage of a public framework, and an outside provider supplies the reasoning models, so the record names no dataset, corpus or licence that accrues to Artemis itself.
Strategic Market Segmentation Artemis sells to enterprise security operations teams, and the named customers skew toward technology companies…

Artemis sells to enterprise security operations teams, and the named customers skew toward technology companies. The launch release adds banking and financial services as sectors already running the product, and the clients Fortune named are Mercury, Wix, Lemonade and Abnormal AI. Lemonade is an insurance company, so that account describes a regulated-sector buyer.

The two published customer accounts describe different entry points into the same category. Cursor moved off its previous log platform, an engineering-heavy company whose infrastructure changes by the hour and whose security team wanted to keep its own data store and write its own detection logic. Lemonade already ran an established platform when it bought Artemis for a current picture of more than 500,000 assets, and Artemis tags that account as a SIEM replacement. The account says the team weighed hiring a managed service and wanted the coverage without the tradeoffs it saw there.

Artemis names its buyer directly on the managed service page: security leaders who need accountability behind the automation, and teams without the headcount to staff an overnight rotation. Geographic and vertical packaging beyond those sector mentions is not disclosed, so a buyer outside the named sectors cannot tell from the record whether the product is packaged for them.

Product Capabilities & AI Advantages The claimed advantage is knowledge of the customer’s environment rather than a corpus Artemis owns…

The claimed advantage is knowledge of the customer’s environment rather than a corpus Artemis owns. The company describes a living model of users, accounts, devices, resources and AI agents, built from identity providers, HR systems and asset management, and applied when a detection runs. Its research team maintains MITRE ATT&CK coverage as the baseline, with per-environment detectors and behavioral baselines layered on top.

The reasoning models come from outside. The case study Anthropic published states that Artemis evaluated several model providers before building on Claude and runs three model tiers inside the platform, and the Trust Center lists Amazon Bedrock Anthropic among its subprocessors. So an outside provider supplies the models, and Artemis builds the environment model above them.

Demonstrated capability comes from the company and its partners. The Cursor account describes correlation across more than twenty log sources, thousands of detectors tuned to one environment, more than 1,200 threat hunts in a quarter, and investigations that ship the queries and evidence behind each verdict. No evaluation by a party independent of Artemis, no public sandbox and no self-service trial appears in the reviewed sources.

Sales Engagement & Go-to-Market Artemis runs an enterprise sales-assisted motion with no self-service path…

Artemis runs an enterprise sales-assisted motion with no self-service path. The site offers demo booking, the reviewed sources show no self-service sign-up, a proof of value runs four weeks against criteria the customer sets, and a spokesperson told Fortune the company had closed a few seven-figure deals, which fits large negotiated contracts rather than bottom-up adoption.

Distribution runs wider than direct sales. The AWS Marketplace listing lets a buyer contract and bill the platform through AWS, and the careers page carries a technology alliances manager alongside a channels and partnerships lead. CrowdStrike, AWS and NVIDIA name Artemis in the 2026 cohort of the accelerator they run together, which is a selection by three platform vendors rather than a reseller relationship. Resellers and managed-service partners do not appear in the reviewed sources, so the routes to a buyer that the record documents are the company's own sellers and the marketplace listing.

The motion reads as founder-led with an organization forming underneath. Shachar Hirshberg fronts the launch press and authors company posts, and the careers page carried fourteen open roles when it was captured on August 25, 2026, across engineering, security operations, product, customer success, sales and partnerships. Fortune reports that founders of Demisto and Abnormal AI, former Splunk leadership and senior executives from CrowdStrike, Palo Alto Networks, Microsoft and Okta joined the round, a network that may open doors, and no cited page shows it producing a deal.

Pricing Model Artemis publishes one number and leaves its unit undefined…

Artemis publishes one number and leaves its unit undefined. The AWS Marketplace listing prices one unit of Artemis cloud platform access at five million dollars for twelve months, with twenty-four and thirty-six month terms also offered. The same listing states that the platform bills in units and that a buyer commits to a quantity of them, and it does not define what a single unit maps to in a customer’s environment.

That gap is what a buyer closes in the sales conversation. Because the quantity is undisclosed, the published figure describes the price of a single unit rather than what a given environment costs, and the record does not show whether a growing telemetry estate raises the Artemis bill the way it raises an ingest-priced one.

Cost behavior during an investigation is undisclosed as well. Artemis offers to hold data for up to seven years or to leave it in storage the customer owns, so some storage cost can stay on the customer’s side. Whether query spikes during an incident land on the customer’s bill or the vendor’s is the kind of question buyers with log platform experience raise in procurement.

Product Delivery & Operations Artemis delivers a platform the customer connects to telemetry where it already lives, streaming the detection-critical part and querying the rest in place…

Artemis delivers a platform the customer connects to telemetry where it already lives, streaming the detection-critical part and querying the rest in place. The company says connectors go live in under an hour and that at one customer real cases appeared within an hour of the proof-of-value kickoff, with connectors running across Splunk, Microsoft Sentinel and SentinelOne. The marketplace listing describes software as a service deployed on AWS, and the launch release says the product works alongside existing security tools.

A managed service now sits beside the software. Artemis says its platform detects, investigates and prioritizes around the clock. Senior analysts operate it on the customer’s environment, review every customer-visible case, decide whether to close, respond or escalate, and act only within limits the customer sets per connector. The same team takes incident command when a case becomes an incident, and the page excludes posture and CVE management, management of the wider tool estate, offensive engagements and full-service forensics.

The operational bar is high and the public evidence for it comes from the company. Processing billions of events an hour is its own figure, and no service level agreement, status page or uptime commitment appears in the reviewed sources, so a buyer cannot test an operational commitment the record does not carry.

Earning Customers' Trust Artemis publishes its compliance posture on a Trust Center named in the site footer…

Artemis publishes its compliance posture on a Trust Center named in the site footer. The rendered page lists ISO 27001:2022, SOC 2, HIPAA and GDPR, and it offers a SOC 2 Type 2 report, an ISO 27001 certificate, an engagement letter, an information security policy and a penetration test behind an access request. It also names the subprocessors behind the service, which is the disclosure a buyer needs to route its own vendor review.

Deployment evidence and a published tenancy design back the attestations. The launch release reports production use in banking and financial services, and the case study Anthropic published states that every customer runs in a dedicated single-tenant environment and that customer data is never shared across tenants or used to train models. Because the reports are gated, a buyer requests access before a formal review can confirm their scope.

Platform Strategy & Ecosystem Positioning Artemis positions as a platform over the customer’s existing data estate, and its own architecture supports that claim more than its ecosystem does…

Artemis positions as a platform over the customer’s existing data estate, and its own architecture supports that claim more than its ecosystem does. Detection, investigation, hunting and response run on one living model of the environment, the catalog lists 152 connectors, and the product opens outward through an MCP interface with the customer’s own repository as the source of truth for detection logic.

Third-party programs are few and recent. The publicized ones are the June 2026 integration with Anthropic’s compliance API and telemetry from Claude Code and Claude Cowork, the AWS Marketplace listing, and the accelerator CrowdStrike runs with AWS and NVIDIA. The company also has a technology alliances manager opening, and Cursor’s engineers author detectors through the product’s MCP interface, which is an integration point other teams could build against.

Ecosystem mechanics beyond those are undocumented in the reviewed sources. No API documentation, partner directory or independently distributed product built on Artemis appears in them, so a reader weighing the platform claim has the architecture Artemis describes and little from outside it.

Team & Execution Capability The founding pair covers the two halves of the product…

The founding pair covers the two halves of the product. Shachar Hirshberg ran product for Amazon GuardDuty, which GovInfoSecurity reports in its own voice, and the About page adds an early role at Demisto and an engineering leadership role at Palo Alto Networks. Fortune places Dan Shiebler as head of AI at Abnormal Security and earlier a machine learning leader at Twitter, while the About page says he built the machine learning organization behind Twitter’s web ads product and holds a doctorate from Oxford.

Headcount evidence is dated and partial. GovInfoSecurity reported 30 employees at the April 2026 launch, and a Datadog case study lists about fifty with no date attached to that figure. The careers page carried fourteen open roles on August 25, 2026, across engineering, security operations, product design, customer success, sales and partnerships. Two of them are a security operations manager and a security analyst, and the managed service page says senior analysts operate the platform for customers who want accountability behind the automation.

Operator validation around the company is dense for its age. Fortune reports that founders of Demisto and Abnormal AI, the former chief executive and chief technology officer of Splunk, and senior executives from CrowdStrike, Palo Alto Networks, Microsoft and Okta joined the round. The reviewed sources name no executive beyond the two founders, so a buyer weighing leadership depth has the founders and the open roles to read.

Sources

Company Detail Sources (4)
Id Source Tier Accessed
f1 AWS Marketplace: Artemis listing, vendor-supplied product overview official 2026-08-25
f2 GovInfoSecurity on the Artemis launch (April 15, 2026) press 2026-08-25
f3 SC Media: brief summarizing SiliconANGLE coverage of the Artemis funding, April 16, 2026 press 2026-08-25
f4 Artemis Security homepage official 2026-08-25
Profile Analysis Sources (23)
Id Source Tier Accessed
s1 Artemis Security: platform homepage
“Artemis correlates signals across Identity, Cloud, Endpoint, and SaaS sources to surface multi-step attacks that single-source detections would never see.”
official 2026-08-25
s2 Artemis Security: About page with founder biographies
“He led product for Amazon GuardDuty, the largest cloud threat detection product in the world, and was an early employee at Demisto and engineering leader at Palo Alto Networks.”
official 2026-08-25
s3 Artemis Security: careers page listing open roles
“14 openings Detection Engineer Remote Apply Now Senior Product Designer New York City Apply Now Lead Security Engineer, Internal and IT New York City”
official 2026-08-25
s4 Artemis Security: Why Artemis product-architecture page
“Comprehensive MITRE ATT&CK coverage, maintained by the Artemis research team, and validated against real environments.”
official 2026-08-25
s5 Artemis Security: managed detection and response page
“Senior analysts operating Artemis on your environment.”
official 2026-08-25
s6 Artemis Security: connector catalog
“150+ connectors across the stack you already run.”
official 2026-08-25
s7 Artemis Security: Cursor customer case study, July 28, 2026
“Today, thousands of detectors are continuously tuned to Cursor's environment and recalibrate as behavior shifts.”
official 2026-08-25
s8 Artemis Security: Lemonade customer case study, August 11, 2026
“How Lemonade Modernized Security with Artemis”
official 2026-08-25
s9 AWS Marketplace: Artemis listing with vendor-supplied content and contract pricing
“Dimension Description Cost/12 months Artemis Cloud Platform Access to the Artemis cloud platform. $5,000,000.00”
official 2026-08-25
s10 Artemis Security: Trust Center, rendered in a browser
“Compliance ISO 27001:2022 SOC 2 HIPAA GDPR”
official 2026-08-25
s11 Anthropic: customer story on Artemis
“Artemis evaluated multiple model providers before building its platform on Claude, using Opus 4.7, Sonnet 4.6, and Haiku 4.5 within the platform.”
official 2026-08-25
s12 Datadog: case study on Artemis Security
“Cybersecurity & AI ~50 Employees New York”
official 2026-08-25
s13 Newswire: Artemis launch release, April 15, 2026
“In less than six months since company formation, Artemis is deployed in production and processing billions of events per hour for enterprise customers and other leaders in technology, banking, and financial services.”
official 2026-08-25
s14 CrowdStrike: 2026 Cybersecurity Startup Accelerator cohort announced with AWS and NVIDIA
“The 2026 cohort (stealth companies not included): Above Security Aira Security Artemis Astelia”
official 2026-08-25
s15 Resilient Cyber: newsletter analysis that names Artemis as its partner, May 12, 2026
“This is the context in which I sat down with Resilient Cyber's partner, Artemis Security 's Co-Founder Shachar Hirshberg to see what they've built and understand why they believe the detection and response category needs to be rebuilt from the ground up.”
official 2026-08-25
s16 Fortune: exclusive on the Artemis raise, April 15, 2026
“Clients already include Mercury, Wix, Lemonade, and Abnormal AI.”
press 2026-08-25
s17 GovInfoSecurity: report on the Artemis launch, April 15, 2026
“Artemis, founded in 2025, employs 30 people and has completed a $15 million seed round led by First Round Capital and Brightmind as well as a $55 million Series A round.”
press 2026-08-25
s18 SC Media: brief summarizing SiliconANGLE coverage of the Artemis funding, April 16, 2026
“Coverage from Silicon Angle indicates that Artemis Global Technologies Inc., a six-month-old cybersecurity startup, has successfully raised $70 million in funding.”
press 2026-08-25
s19 MSSP Alert: brief on the Artemis launch, April 15, 2026
“Instead of ingesting and storing all security data upfront, the platform queries data on demand from existing sources.”
press 2026-08-25
s20 AlleyWatch: interview with the Artemis chief executive
“Early customers have reduced mean time to detect and respond to critical security events by 94%, with one technology company discovering multimillion-dollar cloud spend savings and shadow activity invisible to existing tools during the first scan.”
press 2026-08-25
s21 Software Analyst Cyber Research: report on modern security operations, May 19, 2026
“Artemis Security is an AI-native security operations platform designed to compress the interval between detection, investigation, and response.”
research 2026-08-25
s22 Artemis Security: page sitemap, direct fetch on 2026-08-25 official 2026-08-25
s23 Artemis Security: company post on the Anthropic Compliance API and telemetry integration, June 4, 2026
“Artemis also ingests telemetry from Claude Code and Claude Cowork via OpenTelemetry, extending the same detection and investigation coverage to developer-assistant activity”
official 2026-08-25
Deep-Dive Sources (23)
Id Source Tier Accessed
s1 Artemis Security: platform homepage
“Artemis correlates signals across Identity, Cloud, Endpoint, and SaaS sources to surface multi-step attacks that single-source detections would never see.”
official 2026-08-25
s2 Artemis Security: About page with founder biographies
“He led product for Amazon GuardDuty, the largest cloud threat detection product in the world, and was an early employee at Demisto and engineering leader at Palo Alto Networks.”
official 2026-08-25
s3 Artemis Security: careers page listing open roles
“14 openings Detection Engineer Remote Apply Now Senior Product Designer New York City Apply Now Lead Security Engineer, Internal and IT New York City”
official 2026-08-25
s4 Artemis Security: Why Artemis product-architecture page
“Comprehensive MITRE ATT&CK coverage, maintained by the Artemis research team, and validated against real environments.”
official 2026-08-25
s5 Artemis Security: managed detection and response page
“Senior analysts operating Artemis on your environment.”
official 2026-08-25
s6 Artemis Security: connector catalog
“150+ connectors across the stack you already run.”
official 2026-08-25
s7 Artemis Security: Cursor customer case study, July 28, 2026
“Today, thousands of detectors are continuously tuned to Cursor's environment and recalibrate as behavior shifts.”
official 2026-08-25
s8 Artemis Security: Lemonade customer case study, August 11, 2026
“How Lemonade Modernized Security with Artemis”
official 2026-08-25
s9 AWS Marketplace: Artemis listing with vendor-supplied content and contract pricing
“Dimension Description Cost/12 months Artemis Cloud Platform Access to the Artemis cloud platform. $5,000,000.00”
official 2026-08-25
s10 Artemis Security: Trust Center, rendered in a browser
“Compliance ISO 27001:2022 SOC 2 HIPAA GDPR”
official 2026-08-25
s11 Anthropic: customer story on Artemis
“Artemis evaluated multiple model providers before building its platform on Claude, using Opus 4.7, Sonnet 4.6, and Haiku 4.5 within the platform.”
official 2026-08-25
s12 Datadog: case study on Artemis Security
“Cybersecurity & AI ~50 Employees New York”
official 2026-08-25
s13 Newswire: Artemis launch release, April 15, 2026
“In less than six months since company formation, Artemis is deployed in production and processing billions of events per hour for enterprise customers and other leaders in technology, banking, and financial services.”
official 2026-08-25
s14 CrowdStrike: 2026 Cybersecurity Startup Accelerator cohort announced with AWS and NVIDIA
“The 2026 cohort (stealth companies not included): Above Security Aira Security Artemis Astelia”
official 2026-08-25
s15 Resilient Cyber: newsletter analysis that names Artemis as its partner, May 12, 2026
“This is the context in which I sat down with Resilient Cyber's partner, Artemis Security 's Co-Founder Shachar Hirshberg to see what they've built and understand why they believe the detection and response category needs to be rebuilt from the ground up.”
official 2026-08-25
s16 Fortune: exclusive on the Artemis raise, April 15, 2026
“Clients already include Mercury, Wix, Lemonade, and Abnormal AI.”
press 2026-08-25
s17 GovInfoSecurity: report on the Artemis launch, April 15, 2026
“Artemis, founded in 2025, employs 30 people and has completed a $15 million seed round led by First Round Capital and Brightmind as well as a $55 million Series A round.”
press 2026-08-25
s18 SC Media: brief summarizing SiliconANGLE coverage of the Artemis funding, April 16, 2026
“Coverage from Silicon Angle indicates that Artemis Global Technologies Inc., a six-month-old cybersecurity startup, has successfully raised $70 million in funding.”
press 2026-08-25
s19 MSSP Alert: brief on the Artemis launch, April 15, 2026
“Instead of ingesting and storing all security data upfront, the platform queries data on demand from existing sources.”
press 2026-08-25
s20 AlleyWatch: interview with the Artemis chief executive
“Early customers have reduced mean time to detect and respond to critical security events by 94%, with one technology company discovering multimillion-dollar cloud spend savings and shadow activity invisible to existing tools during the first scan.”
press 2026-08-25
s21 Software Analyst Cyber Research: report on modern security operations, May 19, 2026
“Artemis Security is an AI-native security operations platform designed to compress the interval between detection, investigation, and response.”
research 2026-08-25
s22 Artemis Security: page sitemap, direct fetch on 2026-08-25 official 2026-08-25
s23 Artemis Security: company post on the Anthropic Compliance API and telemetry integration, June 4, 2026
“Artemis also ingests telemetry from Claude Code and Claude Cowork via OpenTelemetry, extending the same detection and investigation coverage to developer-assistant activity”
official 2026-08-25

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.