Abstract Security adds $25M Series A extension for SIEM alternative
The startup says ARR rose 380%, but it did not disclose revenue scale or its new valuation after the extension.
By Dominic Okoye · Staff Writer
· 3 min read
Abstract Security has raised a $25 million Series A extension to expand its security operations platform and sell deeper into large enterprises. The company said annual recurring revenue increased 380% over the past year, a strong growth rate that comes without disclosure of the underlying ARR base.
Cheyenne Ventures and Atlantic Vantage Point co-led the new financing. Existing backers Crosslink Capital and Rally Ventures also participated. Abstract said the extension was priced at three times its previous valuation, but did not provide the current or prior valuation. The company has now raised close to $50 million in total.
The round follows a $15 million Series A led by Munich Re Ventures in October 2024 and an earlier $8.5 million seed round. Abstract said net revenue retention reached 264%, its customer count tripled and it added 40 employees during the year. It did not disclose total headcount, customer numbers, revenue, burn rate or runway.
Founded in 2023, Abstract was started by security industry veterans from ArcSight, Bank of America, Mandiant and Palo Alto Networks. The company is positioning itself against traditional security information and event management systems, a category dominated for years by platforms that centralize logs before applying detection and analytics.
Abstract’s argument is that the SIEM model has become too expensive and too restrictive as security teams ingest more telemetry across cloud, on-premises and hybrid environments. Its platform processes security data in motion, separating data sources from downstream destinations and applying detections before information is written into storage, according to the company.
The startup says its system can route and tier data into multiple formats and destinations, including the Open Cybersecurity Schema Framework, Elastic Common Schema and Splunk’s Common Information Model. That is the practical part of its pitch: customers can avoid sending every log to one repository while still feeding existing tools that expect specific schemas.
Abstract also sells an AI layer called Astro AI for detection, triage, investigation and response. As with many security startups, the AI claim is broad. The company did not provide performance benchmarks, adoption metrics for Astro AI or evidence of analyst productivity gains. The platform is available through the Amazon Web Services, Microsoft Azure and Google Cloud marketplaces.
Chief Executive Colby DeRodeff said Abstract’s model gives security teams more control over sources, destinations and where AI is applied in the workflow. Cheyenne Ventures partner J.R. Becko said enterprises do not want to be tied to a single data platform to detect threats, describing Abstract’s approach as streaming-first and composable.
The financing reflects continued investor interest in security operations tools that promise lower data costs and less dependence on legacy SIEM architectures. Abstract’s reported retention and growth metrics suggest expansion among existing customers, but the absence of absolute revenue and valuation figures leaves the size of the business unclear. The new capital will go toward broader in-stream threat detection, more AI tooling and a larger go-to-market team.
This story draws on original reporting from SiliconANGLE.