AI Email Security Agent by Mailbox Subscription: Automated Phishing Triage, Doubled ARR, and Over $240M in Total Funding
Workflow: Every day, raw emails flagged by employees, user reports, or system triggers are ingested. The ASA autonomously invokes
Key Fields
FIELD STAMPS🔧 Workflow
Every day, raw emails flagged by employees, user reports, or system triggers are ingested. The ASA autonomously invokes file opening, link tracking, threat intelligence, and sub-agents to complete the triage process, outputting classification, automated remediation (email retraction, cross-tenant purging of malicious emails), and replying to the reporter. When a coverage gap is discovered during triage, the ADE automatically analyzes attack behaviors, writes MQL detection rules, runs historical backtests, and provides one-click deployment recommendations, forming an hourly adaptive closed-loop system.
🛠 Setup Requirements
Individuals or small teams can start for free with self-hosted Core editions for the first 100 mailboxes, integrating with Microsoft 365 and Google Workspace. Requires foundational knowledge of email infrastructure and security baselines, proficiency in writing detection rules using SQL-like MQL, and leverage of the community-shared rule library to lower the barrier to entry. The Enterprise edition is billed based on mailbox scale, with a deployment cycle ranging from several days to a few weeks.
🧰 Toolchain
- 🔧 Sublime Security Platform (ASA Autonomous Security Analyst and ADE Autonomous Detection Engineer)
- 🔧 Microsoft 365 and Google Workspace Email APIs
- 🔧 MQL (Message Query Language) Detection Rule Engine
- 🔧 Threat Intelligence Sources and Community-Shared MQL Rule Library
💰 Revenue
The Enterprise edition is subscribed to based on the number of protected mailboxes, with specific unit prices undisclosed. In H1 2025, the company achieved 100% ARR growth and 100% enterprise customer retention, with total funding exceeding $240 million ($150 million Series C led by Georgian in November 2025) and a valuation of approximately $926 million. Individuals or MSSPs can start at zero cost using the free self-hosted edition for the first 100 mailboxes, then charge clients a monthly service fee per mailbox (specific unit prices undisclosed).
💸 Cost
The Core edition for the first 100 mailboxes is free and fully self-hostable, resulting in near-zero subscription costs for individual starters; the Enterprise edition is billed by scale (unit prices undisclosed). Requires self-provided cloud servers, email gateways, and daily operations manpower.
⏱ Time Investment
Deployment takes several days to a few weeks; routine maintenance takes about 1 hour per day to review alerts and rule backtest results. Once ADE automates rule supplementation, manual effort can be compressed to a few hours per week (one customer reported a 62% reduction in investigation workload).
🚀 Getting Started
Begin by connecting a real mailbox environment using the free self-hosted Core edition, running through the closed-loop chain of user reporting, ASA autonomous triage, and automated remediation starting from community-shared MQL rules. Then, acting as an MSSP or security consultant, charge local small and medium-sized businesses a monthly service fee per mailbox, and subsequently upsell enterprise-tier agentic features as high-margin value-adds.
🔑 Keys to Success
- ✅ Fully auditable, non-black-box English reasoning process where human analysts retain final decision-making authority—the trust foundation for compounding, practical adoption.
- ✅ The dual-agent closed-loop of ASA and ADE allows detection rules to organically grow alongside new attacks, driving down marginal human labor costs.
- ✅ Open MQL rules and a community-shared ecosystem lower the barrier to entry, while product-led growth drives rapid scaling through mailbox subscriptions.
- ✅ The free self-hosted edition for the first 100 mailboxes serves as an acquisition funnel, while the Enterprise edition bills by mailbox scale, amplifying revenue progressively from MSSP bundling to direct enterprise contracts.
⚠️ 风险
- ⚠️ False positives may disrupt normal business emails, while false negatives cause real financial losses such as BEC; human review and rollback channels must serve as a fail-safe.
- ⚠️ The self-hosted edition requires teams to possess email infrastructure construction and security operations capabilities, presenting a notable adoption barrier for individuals.
- ⚠️ Sublime heavily relies on Microsoft 365 and Google Workspace APIs for ingestion and retraction capabilities; platform policy changes or API rate limits will directly impact the availability of the automated remediation loop.
📌 Real Cases
- 📌 Elastic: Discovered over 2,000 additional attack emails missed by email providers within the first month of integrating Sublime, reducing the security team's investigation workload by 62%.
- 📌 Georgian: Led Sublime's $150 million Series C round in November 2025, bringing total funding to over $240 million and valuation to approximately $926 million, validating the institutional growth potential of the mailbox-subscription agentic email security model.
- 📌 Notable Capital: Listed Sublime in the 'Rising in Cyber 2026' top cybersecurity startup list, making it one of the most closely watched email security investment targets of 2026 alongside OpenAI and Anthropic ecosystem entry points.