At BETSoftware, the expensive part of security was beginning to look like the cheap part of data. Every new source of telemetry promised a clearer view of the business, then arrived with a larger SIEM bill. Old records sat in cold storage, theoretically retained and practically awkward to search. The South African gaming technology company wanted more coverage, but its existing pricing model made the next log source feel like an indulgence.
Abstract Security entered before the bill. BETSoftware placed its pipeline between data sources and the incumbent SIEM, filtered low-value events, added context to the remainder, and sent different records to different destinations. Its published case study reports 73% less data reaching the SIEM, restored searchability for long-term storage, and return on investment above 250%. Those are customer-reported figures, not a universal recipe. Yet the mechanism is easy to recognize: the costly decision was made upstream.
- Abstract collects, shapes, enriches, detects on, and routes security data while it is moving.
- Customers can keep an existing SIEM, change one, or send data to several destinations at once.
- Published cases center on lower ingestion volume, faster migrations, and leaner analyst work.
- The price is negotiated; Abstract does not publish a standard subscription rate.
The toll booth nobody designed
A SIEM, or security information and event management system, gathers evidence from an organization’s computers, cloud services, identities, and networks. It is supposed to help a security team see an attack while there is still time to intervene. For years, the natural response to missing an attack was to collect more. The result was a strange bargain: richer visibility and a larger mountain of material that analysts might never read.
Abstract’s founders knew that bargain from inside the industry. CEO Colby DeRodeff worked at ArcSight, an early SIEM company, and later co-founded threat intelligence firm Anomali. COO Chris Camacho previously led strategy and revenue at Flashpoint. CTO Aaron Shelmire built detection systems at Secureworks, Anomali, and Palo Alto Networks. Their company, founded in 2023, set out to separate the jobs that a traditional SIEM often bundles together: collection, detection, retention, and the analyst’s response workflow.

The phrase Abstract uses is “composable SIEM.” It sounds like furniture requiring an Allen key. The practical claim is simpler. A team can improve detection without changing its storage contract; change storage without rewriting every rule; or send the same live data to a new analytics tool while the old one continues to operate. The SIEM becomes a destination and a capability, rather than the only road out of town.
Abstract's four platform components can be adopted together or separately.
A pipeline with editorial judgment
Imagine an AWS event entering the system. Abstract can normalize it into a common schema, attach identity or threat intelligence context, compare it with other events in the stream, and choose where it goes next. A high-value signal may head toward fast analysis. An event kept mainly for compliance may go to cheaper retention. A redundant debug record might never enter the premium SIEM index. That is the company’s central product: a security data fabric that gives operators a decision point while the evidence is still in motion.
The platform also offers in-stream, historical, and federated detection, plus AI-assisted triage and investigation. Its more recent Credential Shield feature addresses a humbler problem: secrets accidentally written into logs. Abstract describes examples such as an error handler dumping authorization headers or a build step echoing environment variables. The timing matters. Once a credential is copied into several downstream stores, a small mistake becomes a scavenger hunt.

This positions Abstract against two habits as much as two kinds of vendors. One is the monolithic SIEM that wants collection, analysis, and storage in a single contract. The other is a pipeline treated as plumbing that simply forwards logs. Abstract wants the pipeline to do security work: enrich, correlate, suppress noise, and make an early detection. A team can still use Splunk, Microsoft Sentinel, or another SIEM downstream. In fact, that compatibility is part of the sale.
What the customer cases actually say
BETSoftware’s deployment is unusually instructive because it did not start with a ceremonial replacement of everything. Its existing SIEM kept running while Abstract was connected. The team used a no-code pipeline interface to find reduction opportunities, applied rules to routine noise, and made cold data searchable for later investigation. Channel partner IGNISNOVA stayed involved through the proof of concept. Only after the technical case had been tested did the partners settle commercial terms. That sequence is worth copying: prove reduction and retrieval on your own events before trusting anyone’s percentage.
An unnamed global law firm offers a second version of the same idea. It needed to leave IBM QRadar for Microsoft Sentinel. Its published case says that sending all telemetry directly to Sentinel would have cost hundreds of thousands of dollars each month in Log Analytics fees. The firm used Abstract to filter and compress data in-stream, send less urgent records to cheaper storage, and retain the option to replay archived data later. It reports a 70% drop in log volume and a completed migration in 90 days. One engineer now manages most of its pipelines.
Juul Labs had a different first failure: overlapping, outdated logging infrastructure. Its security leader, Pablo Quiros, says Abstract produced useful visibility within an hour of deployment. A task that had taken four days fell to one, according to the company’s case study. Juul’s projected infrastructure savings of up to 75% were a forecast at the time of publication, so they belong in a plan, not on a scoreboard. The observed time savings tell the cleaner story.
“It’s not something we have to babysit. We adjust when we want to try something new.”Security team at an unnamed global law firm
Managed security provider OmegaBlack offers a fourth use: matching threat intelligence against customer events without building and maintaining every integration itself. Abstract announced OmegaBlack as a customer in 2024 and said much of its new business was moving through channel partners. The pattern is consistent. These buyers are not buying a prettier dashboard. They are trying to recover control over work that had become hostage to data volume, integration labor, or a vendor’s storage meter.
The economics behind the architecture
Abstract sells enterprise software through direct sales and partners, with customized pricing and private offers listed through Microsoft AppSource. There is no public price card from which to calculate a standard payback period. A buyer has to compare the proposed contract with its own ingestion fees, retention obligations, engineering hours, and value of faster detection. If most logs already arrive clean, volumes are modest, or the current SIEM contract makes additional ingestion cheap, the savings case will be less dramatic. The customer examples show what is possible in data-heavy environments, not a guaranteed percentage.
The company has had capital to make its case. It announced an $8.5 million seed round in March 2024, a $15 million Series A that October, and a $25 million Series A extension in July 2026. The three disclosed rounds total $48.5 million. With the last round, Abstract reported annual recurring revenue growth of 380%, net revenue retention of 264%, and a tripled customer base over the prior year. It has not disclosed the underlying revenue or customer count, so the percentages signal momentum without revealing scale.
A January 2026 partnership with Netskope shows where Abstract intends to sit in the market. Netskope One telemetry can enter Abstract’s stream for filtering, enrichment, detection, and routing before it reaches a SIEM or lake. The broader ambition is to be a control point between proliferating sources and the expensive places they end up. It is an ambitious position precisely because it does not require the incumbent tools to vanish.
There is a pleasing irony in a company called Abstract making its best argument through plumbing. The lesson for a security leader is concrete. Draw a map of every event source, each destination, and what an event costs once indexed. Test whether filtering still preserves the evidence you need. Try a second destination in parallel before moving the first. If an old archive cannot be searched when an incident arrives, ask whether it is an archive or merely a storage bill. Abstract’s customers found that the design of the road changed what they could afford to watch.