Closing the gap between attack speed and defense speed
Artemis Security was founded to address a widening gap between how quickly attacks unfold and how quickly security teams can respond. Increasing automation allows attackers to move through parts of the attack lifecycle in minutes, while many security teams still rely on workflows that require significant manual investigation.
Artemis Security closes that gap. The company has built an AI-native security operations platform that automates threat detection, investigation, and response, helping organizations defend themselves against increasingly sophisticated attacks. Its customers include enterprises responsible for critical systems and sensitive data, where security teams must quickly distinguish real threats from overwhelming volumes of alerts. “Our mission is to make machine-speed detection, investigation, and response the default,” says Moshe Saada, Founding Engineer at Artemis Security. “The volume and sophistication of attacks today simply exceed what human-paced workflows can absorb.”
To help customers keep pace, Artemis Security reasons across the entire enterprise environment. The platform ingests telemetry from cloud providers, identity systems, SaaS applications, endpoint tools, observability platforms, and more than 100 additional security and operational data sources. By automatically assembling attack narratives and delivering decision-ready cases, Artemis enables security teams to focus on response instead of manual analysis.
The approach is already delivering measurable impact. Artemis customers have reported reducing mean time to resolution by as much as 96% and cutting false positives by more than 95%. Artemis also consistently identified complex multi-stage attacks that often remain hidden in traditional security workflows.
When AI becomes your fastest-growing operational cost
As Artemis Security expanded its platform and onboarded more customers, AI became central to nearly every part of its operations. Every investigation could trigger multiple agent-driven workflows, from enrichment and classification to reasoning, report generation, and analyst interactions.
The same AI capabilities that allowed Artemis to deliver machine-speed investigations also introduced new operational challenges. Understanding the cost and performance of those workflows became increasingly important as usage grew across customers and environments.
Traditional cloud billing tools provided only a limited view. Engineers could see aggregate costs but lacked visibility into which customers, workflows, models, or agent behaviors were driving them. With costs refreshing daily and limited to only a handful of dimensions, teams struggled to identify the root causes of spending changes or evaluate the impact of new AI capabilities. Answering deeper questions often required manual analysis and custom queries. “We wanted to operate our AI systems with the same rigor as the rest of our infrastructure,” says Saada. “The data existed, but turning it into something every engineer could use was a challenge.”
For a company built around rapid iteration, delayed feedback created unnecessary friction. Teams needed to understand the impact of changes quickly, whether they were introducing new AI capabilities, optimizing existing workflows, or improving efficiency across the platform.
Governing AI costs to scale with confidence
To understand how those AI workloads affected cost and performance, Artemis needed deeper operational visibility. Artemis Security adopted Datadog early through the Datadog for Startups program, giving the team enterprise-grade observability from the beginning. Rather than waiting until the platform reached a certain scale, the company embedded observability into its engineering culture as it built its AI-native security operations platform. “As a startup, we wanted to focus our engineering efforts on solving security problems for customers,” says Saada. “The Datadog for Startups program gave us a strong foundation from day one and allowed us to scale our visibility alongside the platform.”
As AI workloads became a larger part of the business, Artemis expanded that foundation using Datadog Agent Observability, custom metrics, dashboards, and monitors to gain deeper insight into how its agents operated in production.
“The Datadog for Startups program gave us a strong foundation from day one and allowed us to scale our visibility alongside the platform.”
Engineers can now analyze AI activity across more than 20 dimensions, including customers, workflows, investigation types, models, and pipeline stages — giving the team the granularity to optimize spend and performance customer by customer as the platform scales. The team built dashboards that provide a detailed view of both performance and cost, helping engineers quickly understand the impact of changes across the platform. “Measuring the impact of an AI workflow change used to require custom analysis,” says Saada. “Now engineers can see the results within the hour and make decisions based on real production data.”
Artemis also created automated monitors that continuously evaluate AI workload behavior. These alerts help identify unusual spending patterns, routing issues, investigation outliers, and cache-performance regressions before they become larger operational challenges.
“Measuring the impact of an AI workflow change used to require custom analysis. Now engineers can see the results within the hour and make decisions based on real production data.”
Accelerating cyber defense with confidence
Today, Artemis Security processes roughly 15 petabytes of customer data every day while delivering automated threat detection, investigation, and response across enterprise environments.
The visibility provided by Datadog has helped the team expand from just a handful of cloud cost dimensions to more than 20 operational dimensions across the platform. The company has reduced the time required to detect cost regressions from 24 hours to less than one hour, giving engineers near real-time feedback as they build and optimize AI capabilities.
Those insights have also enabled Artemis to make smarter architectural decisions around model selection, workflow design, and resource utilization. By optimizing model routing strategies, the team estimates it has avoided approximately $280,000 in annualized costs while maintaining the performance customers expect. “We treat AI agent costs and performance like any other production signal,” says Saada. “They should be instrumented, alerted on, and reviewed continuously.”
“The better we understand and optimize our own AI systems, the better we can help our customers stay ahead of increasingly sophisticated attacks.”
Looking ahead, Artemis Security plans to continue expanding its AI-powered response capabilities while providing customers with broader automation, richer context, and faster paths to action. As threats continue to evolve, the company believes defenders will need platforms capable of reasoning, investigating, and responding at the same speed as modern attacks. “Ultimately, we’re helping defenders keep up with the pace of modern threats,” says Saada. “The better we understand and optimize our own AI systems, the better we can help our customers stay ahead of increasingly sophisticated attacks.”