
Claude helps security teams investigate threats, validate findings, and resolve issues faster.


Artemis is a cybersecurity startup building an AI-native protection platform that delivers real-time detection and automated response for enterprise security teams. Artemis deeply integrated Claude into its platform, from the core reasoning that powers its security agents to the engineering workflows that build and maintain them.

Claude helps security teams investigate threats, validate findings, and resolve issues faster.
Claude helps security teams investigate threats, validate findings, and resolve issues faster.
Claude helps security teams investigate threats, validate findings, and resolve issues faster.
AI-powered threats can now run from initial access to data exfiltration with minimal human intervention, outpacing an entire generation of defensive technology. Traditional security stacks, built on static rule sets and manual investigation workflows, weren't built for this.
The problem runs deep. A skilled detection engineer in any security organization might write a few rules per week, each requiring intimate knowledge of the log source, the attack technique, and careful tuning to minimize false positives. When new SaaS tools get adopted or configurations change, those rules fall behind. And when a detection does fire, what follows is hours of manual work: copying IP addresses into threat intelligence tools, pulling cloud logs, cross-referencing across disconnected systems. Most alerts turn out to be benign.
"You can't bolt intelligence onto a fundamentally static architecture," says Dan Shiebler, co-founder and CTO, at Artemis. "You have to start over, with AI as the reasoning engine, not an add-on."

Build innovative AI applications with safer systems from Anthropic, supported by secure infrastructure from AWS.
Build innovative AI applications with safer systems from Anthropic, supported by secure infrastructure from AWS.
Build innovative AI applications with safer systems from Anthropic, supported by secure infrastructure from AWS.
Artemis evaluated multiple model providers before building its platform on Claude, using Opus 4.7, Sonnet 4.6, and Haiku 4.5 within the platform. Security workflows demand something specific: following complex multi-step instructions with precision, reasoning across large volumes of evidence, and producing structured output where every conclusion cites specific supporting data.
"The depth of Claude's reasoning capability, combined with Anthropic's commitment to safety and the enterprise trust of Amazon Bedrock, has been a fundamental piece in how we designed Artemis' platform," says Shachar Hirshberg, co-founder and CEO at Artemis. Every customer runs in a SOC2-compliant dedicated single-tenant environment. Customer data is never shared across tenants and is never used to train models.
Rather than applying generic rules, Claude-powered agents build a living model of each customer's environment: every entity, asset, behavioral baseline, and cross-source relationship. That context is what makes detections effective. When a new event arrives, Artemis evaluates it against the full context of the user, system, and organization, not just a static set of rules. Integration takes less than an hour, and customers begin receiving environment-specific intelligence within minutes of connecting their first data source.
When a detection fires, Claude-powered investigation agents take over: formulating hypotheses, querying across log sources, correlating signals, and producing reports with severity assessments and clear chains of reasoning. Deep domain expertise for each log type (Okta, AWS CloudTrail, Entra ID, Crowdstrike) is encoded into each investigation, regardless of which analyst is on shift. Before Artemis, one enterprise customer's security team averaged two hours per investigation. The same cases now produce structured, evidence-cited reports and response actions in less than five minutes. A global financial services customer went from initial integration to over a hundred environment-specific detections within the first week, covering credential access, lateral movement, and persistence techniques their previous tool missed entirely.
"The investigation backlog for our customers didn't shrink. It disappeared," says Hirshberg. "We help them go from triaging a fraction of alerts, hoping the ones we skipped were benign, to having every single alert investigated with the same analytical rigor. We also use Artemis internally to protect the company."
Analysts can also query their security data in English, asking to see suspicious commercial VPN usage across their organization, then follow up to review a detailed report, maintaining context across the interaction. They can build new detections through conversation and investigate specific alerts without having to know SPL, SQL, KQL, or any other domain specific language.
What's less visible but equally important: Artemis uses Claude not just in the product, but to build the product. 100% of the engineers work with Claude Code as a core part of their development workflow. Over 300 custom Claude skills encode the team's operational playbook, from creating new detectors to managing infrastructure and reviewing code. Internal tools become product features. The engineering team ships faster the more it builds.