Defending at Machine Speed

Avatar photo
Artemis Security July 28, 2026

How Cursor built AI-native security operations with Artemis

Artemis SecurityArtemis Security  ·  July 28, 2026

“At Cursor we know what great AI products look like. Artemis is the first time we have seen that same standard applied to security, detecting and responding at the speed our environment actually moves.”

Tom Daniels  ·  CISO, Cursor

10B+

Security events analyzed daily

100%

Alerts investigated, 24/7

96%

Investigations resolved autonomously


About Cursor

Cursor is one of the most widely used AI coding agents and one of the fastest-growing software companies of all time. Inside Cursor, engineering runs at a blazing pace. Changes ship continuously, and the infrastructure underneath it changes by the hour. Securing an environment that moves this fast falls to a lean, deeply technical security team led by CISO Tom Daniels.

The opportunity

For Daniels, the same shift that lets Cursor ship fast also rewrites the security problem. When code, infrastructure, and identity all move at machine speed, so do the risks. An exposed credential, an over-privileged automation account, or a developer reaching into production can become an incident in seconds, faster than any human analyst can work through an alert queue.

The other half of the equation is the attacker. Frontier AI is increasingly available to adversaries, and AI-orchestrated attacks have already moved from research reports to reality, compressing intrusions from days to minutes. Daniels’s working assumption is simple: AI is available, someone will use it to attack.

“We are an AI company end to end. It did not make sense for security to still operate at human speed.”

Tom Daniels  ·  CISO, Cursor

That led Daniels to a clear conclusion. Detection and response could not simply be assisted by AI. They had to be AI-native: adaptive, self-tuning, and able to investigate on their own.

The challenge

Cursor already had a legacy SIEM in place, but it was built with AI bolted on top rather than at the core of the product. What Daniels wanted was a platform designed for the way an AI-native organization actually operates. Manual detection engineering, where people write and maintain every rule by hand, could not keep up with an environment that never holds still.

For the engineers doing the work, the deeper problem came down to one line: we don’t know what we don’t know. Signal was spread across Okta, AWS, and a growing list of other sources, and correlating them into a real picture of an attack demanded expertise that is hard to scale. Even with a clear target in mind, parsing each source correctly and producing a high-signal detection rule took long, sustained effort.

The team also had strong views on how the platform should work. They are engineers first, and they wanted control and transparency rather than a black box. That meant:

  • Keeping ownership of their data
  • Providing context on what matters for detection coverage
  • Bringing their own detection logic
  • Working via MCPs
  • Always being able to see exactly what the system was doing, and why

The solution

Artemis fits the way Cursor operates.

Learning the environment: Artemis starts by learning the environment: AI agents continuously map Cursor’s systems, identities, and behaviors, building baselines of what is expected — which automation accounts touch production, how developers reach infrastructure, what routine data movement looks like.

Adaptive detection: Instead of a static rule set, Artemis generates adaptive detectors and tunes them automatically as the environment changes, so coverage keeps pace with the org rather than falling behind it. Today, thousands of detectors are continuously tuned to Cursor’s environment and recalibrate as behavior shifts.

Control stays with Cursor: With a bring-your-own-ClickHouse model, Cursor kept ownership of its data. Security engineers author custom detectors in plain language through AI Mode or Artemis’ MCP, with versioning, audit history, one-click rollback, and GitHub as the source of truth.

Autonomous, auditable investigations: Investigations run at machine speed, correlating across sources and working cases autonomously, and every verdict is auditable: the reasoning chain, the queries the agent ran, and the evidence behind each conclusion ship with the case.

Human-in-the-loop response: Response actions such as suspending a compromised account are generated dynamically and stay behind human-in-the-loop confirmation. Day to day, the team lives in a Slack-native workflow with the ability to tag Artemis to run AI Mode sessions.

“We now use Artemis to generate working detections and find the correlations across log sources automatically. That’s where most of our effort used to go. Now if we want to detect something, we just ask the agent in plain English: help us write a detector to find this.”

Zehuan Li  ·  Security Software Engineer, Cursor

How Cursor uses Artemis

Artemis watches the places where a fast-moving AI company is most exposed:

  • Correlation across more than 20 log sources: cloud audit logs, identity activity, proxy logs, and data access logs — stitching siloed signals into cohesive investigations
  • Production access monitoring: the developers and automation accounts that touch production, break-glass cloud access, and anomalies in the identity provider
  • Machine-speed data exfiltration: catching attempts before they turn into incidents

That coverage expands without heavy lifting: when the team brings on a new log source, engineers point Artemis at the source to learn the log patterns, so nobody hand-writes parsers or wrestles with format details, and unstructured sources onboard as quickly as structured ones.

On top of that, Artemis hunts. It turns new external intelligence into threat hunts across the whole environment, more than 1,200 hunt executions in the last quarter, and when a hunt hits, it opens a case backed by the same evidence-cited investigation as any detection. When something feels off, the team can also launch its own hunt in plain language through AI Mode, straight from Slack.

For the people who use it every day, Artemis has become the default starting point.

“My browser basically opens to Artemis now. The minute anything looks off, it is the first place I go.”

Zehuan Li  ·  Security Software Engineer, Cursor

Results and impact

Cursor standardized on Artemis as its AI-native detection and response platform across the environment. Moving off its old SIEM onto a single platform put detection, investigation, and response in one place, built for the speed at which the company operates.

The difference shows up in the results: every alert generated or ingested from over 10 billion events a day across Cursor’s environment is investigated automatically, and 96% of them close without human involvement. The security team now focuses their precious time on investigating the handful of decision-grade cases that matter, each arriving pre-investigated with the reasoning and evidence already assembled.

Because the team can tune and iterate on detectors in minutes, coverage and precision keep improving in step with the environment, ahead of what manual processes could sustain.

Underpinning all of it is a close technical partnership, with fast response times and steady delivery on what Cursor asks for.

The strategic outcome is readiness: as attacks themselves become AI-orchestrated, Cursor’s detection, investigation, and response already run at machine speed, and adapt as fast as threats do.

“We threw everything we had at Artemis, every edge case and every hard question, and it kept clearing the bar we set. It has exceeded even what we hoped it could do.”

Tom Daniels  ·  CISO, Cursor


Get started with Artemis

Attacks now move at machine speed, and security has to match the speed and sophistication. Artemis learns your environment, generates and tunes detections continuously, investigates every alert autonomously, and keeps your team in control of response. Integration takes less than an hour, and the first environment-specific detections and investigations arrive the same day.

See what Artemis can do in your environment. Request a demo at artemissecurity.com.

Table of contents
    Get a personalized demo

    Ready to See Everything and Stop Anything?

    Book a personalized demo and see what Artemis is building differently and how it can anticipate anything in your environment.

    Book A Demo
    2
    B+
    events processed every hour
    15,000
    + TB
    data processed daily
    2,000
    +
    insights generated daily