Abstract Security
Revolutionizes security with AI-driven analytics and no-code data management.. [Contact for Pricing]
Last verified:
What is Abstract Security?
Abstract Security is the world's first AI-Gen Composable SIEM, a revolutionary security data platform that redefines security operations by decoupling data ingestion, detection, storage, and response into modular, composable building blocks. Founded in 2023, Abstract replaces monolithic SIEM architectures with a streaming-first model where analytics run in-stream before data is indexed or stored, enabling real-time threat detection and response.
Key features include: a security data fabric that collects from any source (cloud, SaaS, network, endpoint, identity), normalizes to common schemas like OCSF, enriches with asset/identity/threat context, and intelligently shapes/filters/routes data based on analytical intent. The platform supports three detection modes—in-stream detection for real-time threats, historical detection for retroactive analysis, and distributed detection across environments. Storage is tiered into Real Time Storage, Hot Storage, and Warm Storage to optimize costs. AI is deeply embedded across SOC workflows for assisted triage, prioritization, context-rich investigations, proactive threat hunting, and AI-enabled SOAR response.
Abstract is designed for modern SecOps teams, security leaders in highly regulated environments, and organizations struggling with vendor lock-in, explosive security data growth (25-30% annually), and broken SIEM economics. It serves multi-cloud and hybrid environments, helping teams simplify data operations, eliminate noise, reduce storage costs by 65-75%, and achieve faster mean time to detect (MTTD) and mean time to respond (MTTR).
The platform was built by industry veterans and category creators known for redefining cybersecurity. Abstract enables organizations to route data to any destination without vendor lock-in, easily migrate between SIEM destinations, and choose their architecture, deployment model, and analytics engines without sacrificing performance or control.
Abstract Security pricing
Pricing model: Freemium
Abstract Security does not publish public self-service pricing. Pricing is based on contract duration and terms with the vendor. On AWS Marketplace, the Abstract Forwarder component for up to 1 TB/day costs $150,000 for a 12-month contract, with additional components required. The company offers custom enterprise plans—organizations must contact Abstract to set up a demo and discuss pricing. Customers report 65-75% cost reduction compared to traditional SIEM. No free tier is mentioned on the website.
Abstract Security pros
- Eliminates vendor lock-in with composable architecture
- 65-75% reduction in SIEM-related costs
- Streaming-first detection runs before data is indexed or stored
- In-stream detection enables real-time threat response
- AI deeply embedded across all workflows, not bolted on
- Flexible data collection from any cloud, SaaS, network, endpoint, identity source
- Intelligent data routing to multiple destinations without doubling ingestion cost
- Three-tier storage (Real Time, Hot, Warm) optimizes costs significantly
- Normalizes data to OCSF schema in real time
- Enriches data with asset, identity, environment, and threat context
- Scales elastically across multi-cloud and hybrid environments
- Faster mean time to detect (MTTD) reported by customers
- Faster mean time to respond (MTTR) reported by customers
- Filters out noise and unwanted data before it hits billing meter
- Decouples detection from storage, allowing independent upgrades
- AI-assisted triage and prioritization reduces analyst overwhelm
- Supports historical detection for low-and-slow retroactive analysis
- Built by industry veterans with cybersecurity category creation experience
Abstract Security cons
- Relatively new company founded in 2023 with limited track record
- No public self-service pricing—requires sales contact for demo
- AWS Marketplace shows $150,000/year minimum for 1 TB/day
- Enterprise-focused may not suit small teams or startups
- Requires meeting with founding team—no instant onboarding
- New architecture may require team retraining and adaptation
- Limited third-party integrations compared to established SIEMs
- Still Series A stage with $23.5M raised—less mature than incumbents
- Custom deployment may require professional services engagement
Frequently asked questions about Abstract Security
What is AI-Gen Composable SIEM?
AI-Gen Composable SIEM is Abstract's architectural standard for modern security operations, built natively for artificial intelligence, streaming data, and modular control. It replaces monolithic SIEM architectures with a streaming-first model where ingestion, pipelines, storage, detection, AI triage, and response operate as composable building blocks that can be swapped, scaled, or integrated independently.
How does Abstract eliminate vendor lock-in?
Abstract decouples data sources and destinations, allowing organizations to route data to any SIEM or data lake destination. The composable architecture means detection is not tied to storage, storage is not tied to licensing, and teams can easily migrate or transition data routing between different SIEM destinations without rip-and-replace replatforming.
What is in-stream detection?
In-stream detection runs analytics in the data stream before data hits storage, is indexed, or is slowed down. This enables real-time and near-real-time threat detection and response, allowing security teams to detect and stop adversaries before damage is done, rather than waiting for data to be centralized and indexed like legacy SIEMs.
What storage tiers does Abstract offer?
Abstract offers three storage tiers: Real Time Storage for instantaneous retrieval where milliseconds matter, Hot Storage for high-value high-signal data that detection engines access quickly, and Warm Storage for cost-efficient retention that meets regulatory and compliance purposes. This tiering allows deliberate placement of right data into right storage for right use cases.
What data sources does Abstract support?
Abstract collects from any source including cloud (AWS CloudTrail, Azure Activity Logs, GCP Audit Logs), SaaS applications, network devices, endpoints, and identity systems. The platform normalizes data into common schemas like OCSF and can handle multiple schemas simultaneously.
How does Abstract reduce costs by 65-75%?
Abstract reduces costs by intelligently tiering and routing data, filtering noise before it hits the billing meter, and avoiding indexing/storing all data identically. Unlike legacy SIEM pricing that scales with data volume regardless of value, Abstract routes compliance-only data to warm storage while keeping high-signal detection data in hot/real-time storage, dramatically reducing expensive hot storage costs.
How is AI embedded in Abstract?
AI is deeply embedded across the entire data pipeline from ingestion to detection to investigation, not bolted on as a feature. AI-enabled SecOps includes AI-assisted triage and prioritization, context-rich investigations, proactive threat hunting, a unified analyst workbench, and AI-enabled response and SOAR workflows operating as an AI-enabled control plane across the architecture.
Can I use Abstract with my existing SIEM?
Yes. Abstract layers into your existing stack so you can improve what matters most without replacing everything. The platform simplifies the security data pipeline from ingestion to detection to storage and can route data to your existing SIEM or privacy-first data lake, allowing teams to start where their stack needs the most help.
What services does Abstract offer beyond the platform?
Abstract offers regulatory compliance consulting and security threat analysis services including Collection Effectiveness Assessment (reviewing technology portfolio to identify key data sources and prioritize based on threats, risks, and compliance needs) and Detection Effectiveness Assessment (reviewing existing detection content and coverage to identify improvement areas based on threat landscape knowledge).
Who founded Abstract Security and what is their background?
Abstract Security was founded in 2023 by Colby DeRodeff (CEO & Co-Founder), Chris Camacho (COO & Co-Founder), and Aaron Shelmire (Chief Threat Research Officer & Co-Founder). The team consists of category creators and industry veterans known for redefining the cybersecurity landscape, with advisors including Jon Oltsik and CISOs from major hospitality and healthcare companies.