Artemis Security
New York City, US · 53 employees on LinkedIn · 7 known investors
Artemis is an AI-native cybersecurity platform that detects and eliminates cyber threats for enterprises. The platform replaces traditional SIEMs with intelligent threat detection powered by AI/ML, delivering precise alerts with actionable context at lower cost.
Also known as Artemis · Artemis Global Technologies Inc.
Founders & leadership

Investors · 7
Also in the syndicate · 3
Funding
SEC filings, press & company announcements- Undisclosed amountSeries AApr 2026 · 2 sources
Brightmind Partners (lead), Felicis (lead), Brightmind, First Round Capital, Lockstep, Theory VC
Source ↗
Source: company announcements and press reports — follow each round's link for the claim.
Company profile
researched Aug 2026Artemis Security (corporate entity reported as Artemis Global Technologies Inc.) builds an AI-native security operations platform intended to replace or supplement traditional SIEM and detection tooling. The core of the product is what the company calls an "Environment Model": a continuously updated representation of every user, account, device, resource, cloud workload, application and AI agent in an organization, along with the relationships between them and their business context. The model is populated from authoritative systems of record — identity providers, HR systems and org structure, CMDB/ITSM and asset management, crown-jewel maps — rather than inferred from past alerts, and is applied at detection time rather than consulted after another system raises a flag.
On top of the model the platform provides three layers. Adaptive detection starts from MITRE ATT&CK coverage maintained by an in-house research team, adds behavioral analytics grounded in what is expected for each entity, and synthesizes new detectors against a specific customer environment within minutes when new threat intelligence arrives; detectors auto-tune as the environment changes. Autonomous investigation produces what the company calls a "decision-grade case": one case per actor consolidating identity, cloud, endpoint, AI and SaaS activity into a single narrative with a judgement, confidence level, auditable reasoning chain, the queries the agent ran, and the underlying evidence. Response actions are staged with the case and can be executed autonomously or held for human approval, with the level of autonomy configurable by the customer. Engineers can author custom detectors in natural language via an AI Mode or the Artemis MCP interface, with versioning, audit history and one-click rollback, and without writing SPL, KQL or SQL. According to SC Media's summary of Silicon Angle reporting, the platform uses federated querying to analyze telemetry where it is generated instead of centralizing data, positioning it as a lower-cost alternative to SIEM data streaming, and on detection produces a visual attack timeline, a natural-language incident description and remediation suggestions.
Founding story
Co-founders Shachar Hirshberg (CEO) and Dan Shiebler (CTO) started the company approximately seven months before the April 2026 public launch. Hirshberg describes a prior decade building and scaling enterprise security operations platforms as a product and engineering leader at Demisto, Palo Alto Networks and AWS GuardDuty, working with security operations centers ranging from Fortune 500 companies to 200-person startups. Shiebler's background is in architecting AI systems over large data volumes: behavioral modeling of hundreds of millions of users at Twitter, and leading AI/ML at Abnormal AI, where similar techniques modeled organizational communication patterns for email security. The founding thesis was that AI reasoning becomes substantially more reliable when it operates over a structured model of the environment being analyzed, and the founders applied that principle to enterprise infrastructure telemetry.
Business model
Enterprise software sold to security operations teams; the platform is deployed into customer environments, integrating with existing log sources, identity systems, cloud, endpoint, network, SaaS and AI telemetry. Specific pricing and contract structure are not disclosed in the sources, though the company references a "contract term," implying subscription-based enterprise agreements.
Traction
Customers are reported to have reduced mean time to detect and respond by 94%. The platform processes over 15,000TB of data daily and more than 2 billion events per hour, generating over 2,000 insights daily. At Cursor, Artemis is described as investigating every alert generated across more than 10 billion events per day, with 96% of cases closing without human involvement, and running thousands of continuously tuned detectors correlating more than 20 log sources. The company says it is in production with large and fast-growing companies in financial services, technology and insurance.
Latest developments
Following the April 2026 stealth exit and $70M announcement, Artemis published an integration with the Anthropic Compliance API and telemetry in June 2026, and research/thought-leadership posts in July 2026 on AI-speed attack tempo, machine-speed defense, and AI-driven breaches that went undetected at real companies. The company states it is hiring across R&D, go-to-market, product and marketing.
▸Full profile — market position, technology, go-to-market, history, risks & controversies
Market position
Positioned as an AI-native alternative to traditional SIEM and alert-pipeline tooling, in the security operations / detection and response category. Its differentiation claim rests on building the environment model before detection rather than retrieving context after an alert, which the company argues competing platforms cannot retrofit. Investor and industry endorsements come from figures including a former Splunk CEO and CrowdStrike's chief business officer.
The company argues that context retrieval used only during investigation limits a platform to what other tools already flagged, whereas Artemis applies its environment model at detection time and can therefore detect events such as a first-ever access to a sensitive resource without a pre-written rule. Additional stated differentiators: detectors generated and auto-tuned per environment rather than a static library, one consolidated case per actor instead of multiple alerts across consoles, fully auditable AI reasoning chains, customer-controlled autonomy levels for response, and no requirement to write query languages such as SPL, KQL or SQL.
Technology
A continuously updated "living model" of the customer environment built from identity providers, HR and org data, CMDB/ITSM, asset management and business-context sources, used at detection time. Layered on it: AI-generated adaptive detectors covering MITRE ATT&CK plus entity-level behavioral analytics with continuous auto-tuning; agentic threat hunting; autonomous investigation agents that produce auditable evidence chains and verdicts; and staged or autonomous response actions. SC Media reports a federated query capability that analyzes telemetry in place rather than ingesting it centrally. Natural-language detector authoring is available via AI Mode and an Artemis MCP interface with versioning and rollback.
Go-to-market
Direct enterprise sales with a "Book a Demo" motion on the website and personalized demos led by company experts. The company references early customers and design-partner-style references from named security leaders, and says proceeds from its funding will expand engineering and go-to-market teams. It participated in the CrowdStrike + AWS + NVIDIA Cybersecurity Startup Accelerator, and a CrowdStrike executive publicly referenced Artemis building on CrowdStrike Falcon and driving next-generation SIEM adoption.
Enterprise security operations centers and detection-and-response teams, spanning AI-native startups through global enterprises. The company states it is in production with companies across financial services, technology and insurance. Named references on its site include security leaders at Cursor, Sony, Lemonade, Abnormal, Mercury, Amazon Security, Upwork, Aviatrix, Wix and an unnamed global financial institution.
History
The company was founded roughly seven months prior to its April 2026 launch, i.e. around late 2025. The founders participated in the CrowdStrike + Amazon Web Services + NVIDIA Cybersecurity Startup Accelerator approximately six months before launch. Artemis emerged from stealth on 15 April 2026 with $70 million raised across a seed round and a Series A. Company blog posts published after launch cover AI-speed attack tempo (July 2026), an Anthropic Compliance API and telemetry integration (June 2026), and machine-speed defense (July 2026).
Risks & controversies
Sources are predominantly company-authored; the only third-party coverage in the material is an SC Media brief summarizing Silicon Angle reporting. Traction metrics such as the 94% reduction in mean time to detect and respond and the 96% autonomous case closure rate are self-reported. Headquarters, founding date precision, employee count and revenue are not disclosed in the available material. Two unrelated firms share the Artemis Security name (a physical security consulting LLC and a Southern California guard-services provider) and were excluded from this profile.
Compiled by commissioned research from 8 cited public sources — announcements, filings, and press listed under research sources below.
Key figures
latest reportedCompany-reported or press-reported figures, each dated to when it was claimed — not independently audited.
Competitors · 3
by search overlapCompanies competing with Artemis Security for the same Google search keywords, organic and paid, via search-intersection analysis.
Timeline · 3
launches, deals, and filingsArtemis announced support for securing enterprise AI usage through an integration with the Anthropic Compliance API and telemetry.
Artemis publicly launched with $70 million raised in two tranches: a Series A led by Felicis and a seed round co-led by First Round Capital and Brightmind, with participation from Theory VC, Lockstep, and angels including founders of Abnormal AI and Demisto, the former CEO and CTO of Splunk, and senior executives from CrowdStrike, Palo Alto Networks, Microsoft and Okta. Funds are earmarked for expanding engineering and go-to-market teams.
$70M source ↗
CrowdStrike Chief Business Officer Daniel Bernard states that the founders entered the CrowdStrike + Amazon Web Services + NVIDIA Cybersecurity Startup Accelerator approximately six months before the April 2026 launch.
Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.
In the news
▸Research sources · 8
primary sources listed
- Artemis Securityartemissecurity.com · web
8 public sources were cited for this profile; the first-party ones are listed here.
Frequently asked questions
- What does Artemis Security do?
- AI-native security operations platform that models a customer's environment to detect, investigate and respond to attacks.
- Who founded Artemis Security?
- Artemis Security was founded by Shachar Hirshberg, Dan Shiebler.
- Who are Artemis Security's investors?
- Artemis Security's investors include Brightmind, Dria Ventures, Felicis Ventures, First Round Capital.
- Where is Artemis Security headquartered?
- Artemis Security is headquartered in New York City, US.

