Abstract Security

Abstract Security is a security data platform and AI-powered composable SIEM founded in 2023 by Colby DeRodeff and Aaron Shelmire. Its streaming-first architecture ingests security telemetry from cloud, SaaS, endpoint and on-prem sources, then filters, normalizes, enriches and routes it in real time to SIEMs, data lakes and low-cost archives. The platform separates high-value detection data from long-term compliance retention so teams can cut SIEM ingest cost without losing visibility. Named components include Collection (the security data control plane), Detection Fabric, AI-Enabled SecOps, Retention, and the Abstract Intel Gallery (AIG) for operationalizing threat intelligence. The company publishes a catalog of roughly 230 source, destination and action integrations covering AWS, Microsoft Sentinel, CrowdStrike, Splunk, Google SecOps, Palo Alto Cortex XSIAM, SentinelOne, Elastic and Netskope, and its threat research group (ASTRO) publishes open YARA rulesets on GitHub. Abstract Security has raised roughly $28.5M from Munich Re Ventures, Crosslink Capital, Rally Ventures and Liquid 2 Ventures. As of this profiling pass the company operates no public developer portal, publishes no API reference or machine-readable contract, and routes platform access through a sales/demo motion.

Abstract Security is profiled on the APIs.io network. Tagged areas include Security, Cybersecurity, SIEM, Security Data Pipeline, and Threat Detection.

Abstract Security’s developer surface includes engineering blog, support, signup flow, and 10 more developer resources.

14.3/100 emerging Agent 3/100 human only Full breakdown ↓
scored 2026-09-06 · rubric v0.19.0
0 APIs
SecurityCybersecuritySIEMSecurity Data PipelineThreat DetectionSecurity OperationsLog ManagementData StreamingObservabilityThreat IntelligenceCloud SecurityAI SecurityDetection EngineeringData RoutingCompliance Retention

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-06 · rubric v0.19.0
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/abstract-security: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Abstract Security Rate Limits

0 limits

RATE LIMITS

Security Posture 1

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Abstract Security Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Resources

Get Started 1

Portal, sign-up, and the first successful call

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 1

Pagination, idempotency, versioning, errors, and events

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 1

Authentication, authorization, and security posture

Operate 2

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: abstract-security
name: Abstract Security
description: Abstract Security is a security data platform and AI-powered composable SIEM founded in 2023 by Colby DeRodeff
  and Aaron Shelmire. Its streaming-first architecture ingests security telemetry from cloud, SaaS, endpoint and on-prem sources,
  then filters, normalizes, enriches and routes it in real time to SIEMs, data lakes and low-cost archives. The platform separates
  high-value detection data from long-term compliance retention so teams can cut SIEM ingest cost without losing visibility.
  Named components include Collection (the security data control plane), Detection Fabric, AI-Enabled SecOps, Retention, and
  the Abstract Intel Gallery (AIG) for operationalizing threat intelligence. The company publishes a catalog of roughly 230
  source, destination and action integrations covering AWS, Microsoft Sentinel, CrowdStrike, Splunk, Google SecOps, Palo Alto
  Cortex XSIAM, SentinelOne, Elastic and Netskope, and its threat research group (ASTRO) publishes open YARA rulesets on GitHub.
  Abstract Security has raised roughly $28.5M from Munich Re Ventures, Crosslink Capital, Rally Ventures and Liquid 2 Ventures.
  As of this profiling pass the company operates no public developer portal, publishes no API reference or machine-readable
  contract, and routes platform access through a sales/demo motion.
image: https://cdn.prod.website-files.com/69847dcdf15f603ba59220d8/6a28780d0e4dcdad57e2b620_abstract-logo.png
url: https://raw.githubusercontent.com/api-evangelist/abstract-security/refs/heads/main/apis.yml
x-type: company
x-source: harvest:secondary-market
x-tier: profiled
x-tier-reason: 'enrichment pass 2026-09-06: full STEP 0b contract discovery run across every known host; no public developer
  portal, API reference or machine-readable contract found — a real /llms.txt was harvested and the stub Website (nasdaqprivatemarket.com)
  was corrected'
specificationVersion: '0.23'
created: '2026-09-06'
modified: '2026-09-06'
tags:
- Security
- Cybersecurity
- SIEM
- Security Data Pipeline
- Threat Detection
- Security Operations
- Log Management
- Data Streaming
- Observability
- Threat Intelligence
- Cloud Security
- AI Security
- Detection Engineering
- Data Routing
- Compliance Retention
apis: []
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
  position: Producing
- FN: APIs.json
  email: info@apis.io
common:
- type: Website
  url: https://www.abstract.security/
- type: Blog
  url: https://www.abstract.security/abstract-canvas
- type: Support
  url: https://www.abstract.security/contact-us
- type: SignUp
  url: https://www.abstract.security/get-a-demo
- type: TermsOfService
  url: https://www.abstract.security/policies/terms-and-conditions
- type: PrivacyPolicy
  url: https://www.abstract.security/policies/privacy-policy
- type: GitHubOrganization
  url: https://github.com/AbstractSecurity
- type: Integrations
  url: https://www.abstract.security/integrations
- type: LinkedIn
  url: https://www.linkedin.com/company/abstractsecurity
- type: LLMsTxt
  url: llms/abstract-security-llms.txt
- type: DomainSecurity
  url: security/abstract-security-domain-security.yml
- type: Plans
  url: plans/abstract-security-plans-pricing.yml
- type: RateLimits
  url: rate-limits/abstract-security-rate-limits.yml
- type: Lifecycle
  url: lifecycle/abstract-security-lifecycle.yml
x-enrichment:
  date: '2026-09-06'
  status: minimal
  artifacts_added: 7
  pass: local-v3
x-coverage:
  state: gated
  reason: sales-gate
  detail: Abstract Security serves no developer portal or API reference at all — /docs, /developers, /api, /api-docs and /openapi.json
    every one 404 on www.abstract.security, the 348-URL sitemap contains no developer page, and the site navigation has no
    Developers section — while the API host named in the company's own TLS certificate (api.abstract.security, seen in Certificate
    Transparency) publishes no public DNS record, so the only route to the platform is the demo request form at /get-a-demo
    that routes to sales.
  evidence:
  - url: https://www.abstract.security/developers
    status: 404
  - url: https://www.abstract.security/openapi.json
    status: 404
  - url: https://www.abstract.security/get-a-demo
    status: 200
  - url: https://www.abstract.security/llms.txt
    status: 200
  checked: '2026-09-06'

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/abstract-security"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/abstract-security/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/abstract-security/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.