Provides an open, API-driven email security platform that integrates with Microsoft 365 and Google Workspace to detect and block advanced threats like Business Email Compromise, phishing, and malware. By enabling custom detection rules, automating threat response, and operationalizing threat intelligence, it reduces email-originated incidents and improves SOC efficiency.
Funding
$89.8M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.




Founders
Product
Problem
Organizations face an increasing volume of sophisticated email-based attacks, including business email compromise, phishing, and malware, which bypass traditional security measures. Security operations centers (SOCs) struggle to efficiently manage user-reported suspicious emails and operationalize threat intelligence to prevent future incidents. Existing email security solutions often lack the flexibility to create custom detection rules and automate incident response workflows.
Solution
Sublime Security provides an open, API-driven email security platform that integrates with Microsoft 365 and Google Workspace to detect and block advanced email threats. The platform enables security teams to create custom detection rules using a detections-as-code approach, leveraging behavioral and AI-powered analysis. It automates the triage and investigation of user-reported phishing attempts, reducing the workload on security analysts. Sublime Security also facilitates attack surface reduction by allowing administrators to block entire attack categories with tailored policies and operationalize threat intelligence by blocking inbound messages containing indicators of compromise (IOCs).
Target Audience
The primary target audience includes security operations centers (SOCs), managed security service providers (MSSPs), and enterprises using Microsoft 365 or Google Workspace seeking to improve their email security posture and reduce the operational burden on security teams.
Features
- Integration with Microsoft 365 and Google Workspace via APIs, eliminating the need for MX record changes
- Custom detection engine allowing users to write and run their own behavioral, AI-powered detection rules
- Automated triage and investigation of user-reported phishing emails
- Herd immunity feature to remediate email campaigns organization-wide based on user reports
- Threat intelligence operationalization to block inbound messages containing IOCs and retroactively hunt for threats
- Attack surface reduction capabilities to block entire attack categories with custom policies
- YARA rule support for detecting malware and other malicious content in email messages
- EML Analyzer tool for rapid phishing investigation
- EmailRep integration for email address reputation scoring