Listing Thumbnail

    Sublime Email Security Platform

     Info
    Deployed on AWS
    Sublime stops more email attacks with less work. Our agentic platform protects, adapts, and responds in real-time, eliminating vendor bottlenecks.
    4.8

    Overview

    Sublime's agentic platform stops more email attacks with less work. It's team of AI agents work like a digital SOC team in your environment, triaging and blocking advanced threats while adapting protections at adversary speed. It provides full transparency and automation by default, with control on demand for advanced teams, eliminating vendor bottlenecks or one-size-fits-all limits.

    Get an AWS Private Offer and speak with the team at sales@sublimesecurity.com 

    Highlights

    • By stopping more attacks and reducing false positives, Sublime delivers a superior autonomous AI experience that requires less work. For advanced teams, the platform is fully extensible, allowing you to author your own detections and hunt for threats with a level of precision that one-size-fits-all solutions can't.
    • Block sophisticated threats (BEC, novel phishing, QR-based phishing) and reduce the false positives that waste time and disrupt workflows. Sublime's tailored protections deliver a demonstrably higher catch rate, validated by the world's most demanding security teams.
    • Protect Microsoft 365 and Google Workspace accounts with no MX changes. Deploy in Sublime Cloud or self-host on AWS.

    Details

    Categories

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Sublime Email Security Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    Price per Mailbox
    Annual price per mailbox starting at
    $76.20

    Vendor refund policy

    We do not currently support refunds.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Sublime Security Support Policy can be found at

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.8
    35 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    94%
    6%
    0%
    0%
    0%
    1 AWS reviews
    |
    34 external reviews
    External reviews are from G2  and PeerSpot .
    Sachin Mohanty

    Advanced detection has transformed phishing defense and now speeds up investigations

    Reviewed on Jul 26, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I have been using Sublime Security  for four years. I have used Sublime Security  for phishing detection, malware detection where it detects malicious attachments, scripts, and links delivered through email, threat hunting which enables the security teams to proactively search historical emails for indicators of compromise, and automated response where it automatically quarantines malicious emails from user mailboxes.

    I use Sublime Security for better detection of sophisticated phishing and business email compromise attacks and for faster investigation and response workflows.

    How has it helped my organization?

    Sublime Security has had a significant positive impact on my email security operations, improving my ability to detect sophisticated phishing, business email compromise, and malicious email campaigns that would have bypassed traditional email security, helping me respond faster to email-based threats, reducing operational overhead and improving collaboration.

    I measure the impact of Sublime Security using a combination of SOC metrics and operational KPIs, and since deploying it, I have seen a reduction in mean time to investigate and respond because the platform automatically analyzes suspicious emails with context.

    Based on my observation, Sublime Security has blocked approximately 20 to 30% more malicious emails compared to my previous email security solution, with significant improvements in detecting sophisticated phishing, business email compromises, and credential harvesting attacks that previously required manual investigation.

    What is most valuable?

    Sublime Security is primarily used as an email security platform focused on detecting, investigating, and preventing advanced email threats using a combination of artificial intelligence, behavioral analysis, threat intelligence, and a community detection engine to identify attacks that traditional secure email gateways may miss.

    The best features Sublime Security offers include artificial intelligence-powered security agents and detection engineering, with its adaptive detection engine being one of the strongest capabilities as it adapts the detection coverage to my organization's email patterns instead of relying on a one-size-fits-all rule set.

    I mainly depend on the artificial intelligence-powered security agents which include a security analyst and a detection engineer, and I mostly rely on automated remediation where it automatically quarantines malicious emails and deletes or moves the messages and adds warning banners.

    The best features include the adaptive artificial intelligence-powered detection engine, autonomous email triage, advanced threat hunting, content grouping, and automated remediation which helps the security team reduce manual effort, investigate incidents faster, and improve overall email security posture.

    The artificial intelligence agents do a good job of analyzing email content, sender behavior, authentication results, and threat intelligence to provide clear context and prioritize the risks, which improves analyst productivity, reduces investigation time, and accelerates the response to phishing and business email compromise attacks.

    The Autonomous Detection Engineer has had a positive impact on my detection coverage by helping me identify new and evolving email threats much more quickly through continuously analyzing emerging attack patterns and generating new detection logic to improve coverage.

    What needs improvement?

    Sublime Security can be improved by expanding the integrations with additional SIEM , SOAR , and ITSM  platforms, making it easier to fit into diverse enterprise ecosystems, and overall there are enhancements rather than major shortcomings.

    I would like to see more dashboard customization so different teams can tailor views and reporting to their needs, and alert tuning could also be more granular to further reduce false positives.

    I did not give it a perfect rating because there are areas that can be improved such as dashboard customization and compliance reporting, as these are enhancements rather than major shortcomings. Overall, it is a highly reliable and effective email security solution that has strengthened my organization's security posture.

    Overall, I am very satisfied with Sublime Security, but there are a few enhancements that would make it even better including more customizable dashboards and executive-level reporting to help different teams tailor the platform to their specific needs.

    For how long have I used the solution?

    I have been working in my current field for five years.

    What do I think about the stability of the solution?

    Sublime Security is a very stable and reliable platform that consistently performs well in my production environment with continuous email monitoring and threat detection without any significant performance or availability issues.

    What do I think about the scalability of the solution?

    Sublime Security is quite scalable. As my organization grows, I have been able to extend protection across additional mailboxes and business units without performance issues or increased operational complexity.

    How are customer service and support?

    The customer support was quite good and they were very knowledgeable.

    Which solution did I use previously and why did I switch?

    Before implementing Sublime Security, I relied primarily on Microsoft Defender for Office 365  as my email security solution, but I wanted stronger detection capabilities for advanced phishing, business email compromises, and targeted email attacks along with better investigation and threat hunting capabilities.

    How was the initial setup?

    I was not involved in the pricing, setup, and cost and licensing, but the setup process was straightforward due to its API-based integration with Microsoft 365, requiring minimal changes to my existing email infrastructure and enabling quick monitoring and protection of my environment.

    What was our ROI?

    I have seen a positive return on the investment from Sublime Security through time savings, improved operational efficiency, and a stronger email security posture, having reduced email investigation and triage time by approximately 40 to 50% as the platform automatically analyzes suspicious emails.

    Which other solutions did I evaluate?

    Before selecting Sublime Security, I evaluated several email security solutions including Microsoft Defender for Office 365 , Proofpoint, Mimecast, Abnormal Security , and Ironscales, comparing them based on phishing and business email compromise detection capabilities, investigation workflows, threat hunting, deployment complexity, and overall ease of management.

    What other advice do I have?

    My advice for others looking into using Sublime Security is to clearly define your email security objectives and involve both your security and IT teams early in the evaluation process to gain the most value when integrating with existing systems.

    In order to use Sublime Security for Microsoft Office 365 , I have additional thoughts on how it can enhance email security. I am providing this review with an overall rating of 9.

    AmitRathod

    Automated policies have protected our email channels and reduced phishing risks every day

    Reviewed on Jul 13, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I currently use Sublime Security  to restrict phishing campaigns occurring in my organization, as it detects suspicious indicators such as domain impersonation, automatically flags, and remediates those messages before user interaction. To restrict user interaction, I use Sublime Security  here.

    My organization specializes in email-related security, so we exclusively use Sublime Security without using Microsoft Defender.

    What is most valuable?

    What I like the most about Sublime Security is that it automatically analyzes and remediates suspicious emails reported by the AI agents, allowing security teams to write custom organization-specific policies according to their needs. It converts threat handles into automatic decisions, uses MQL, and monitors and blocks outbound email containing sensitive information or user data, helping organizations prevent leaks related to email.

    What needs improvement?

    One issue I dislike about Sublime Security is that it requires expertise in MQL, which took my organization almost two months to learn. I initially took help from a vendor but later needed customization, meaning I had to learn the MQL language myself, which was challenging since none of my five to six engineers knew how it worked beforehand. Additionally, while Sublime Security mainly focuses on email defense systems, it does not protect other tools like Microsoft Teams , OneDrive, or Zoom. It would be beneficial if it could be used for other tools configured with emails. I also found limitations in its integration with specialized tools, requiring customized API solutions for end-to-end data capture.

    For how long have I used the solution?

    I have been using Sublime Security for the last eight months, and it is a one-time configuration, so I do not need to use it again and again. I simply enjoy its automation directly.

    What do I think about the stability of the solution?

    Regarding stability, I can say that I have not faced any lagging, crashing, or downtime issues, so I would score it full marks since there have been no problems until now.

    What do I think about the scalability of the solution?

    Concerning scalability, I am getting a large volume of emails daily, around one thousand to one thousand five hundred per mailbox, indicating that it has good scalability since I have not encountered any issues.

    How are customer service and support?

    I contacted technical support because there were some emails that could not be identified due to phishing. I contacted the team and learned that I missed some configurations on my end. The technical team helped me greatly, and since then, I have not faced any issues. I need to take care during configuration, refer to their documentation, and ensure everything is set up correctly to avoid future problems.

    Since I contacted support only once and it was helpful, I would give them a score of ten out of ten.

    Which solution did I use previously and why did I switch?

    I cannot provide specifics about other systems I have used before, but I can say that I have encountered approximately forty to sixty phishing emails so far. These include suspicious messages related to financial matters and promotions which Sublime Security has successfully detected to prevent interactions.

    How was the initial setup?

    The initial deployment of Sublime Security was moderate; it was neither particularly difficult nor easy. It was configured by my vendor team and required some MQL expertise alongside some custom API configuration.

    What's my experience with pricing, setup cost, and licensing?

    In terms of maintenance, it requires an annual subscription per mailbox if I want to purchase it at once. If there are no issues, I do not think annual maintenance costs should be necessary since there are no major issues (P1, P2) with Sublime Security.

    Which other solutions did I evaluate?

    I have not used any alternatives, but there is Microsoft Defender, which is an inbuilt tool for Microsoft.

    What other advice do I have?

    In terms of transparency, Sublime Security provides the correct information I require. It also offers usable data and additional solutions for configuration to avoid potential issues, which I appreciate. The transparency is particularly good in terms of knowledge.

    It is very important for my organization that Sublime Security offers reduced vendor dependency when deploying new protections, especially to mitigate phishing risks since I am a security organization. I do not want to face any vulnerabilities, security breaches, or risks related to email, given its central role in my daily interactions. I see Sublime Security as a very important tool that allows me to work without fear of breaches.

    I have installed only one AI agent, ASA , which stands for Autonomous Security Analyst. This agent analyzes and remediates dangerous or suspicious emails reported from other mails. So far, I have only used ASA , which has been incredibly helpful, but I am not sure about other AI agents since ASA has been my only implementation.

    Regarding the impact of the autonomous detection engineer on my environment's detection coverage, I have not faced any issues, so I cannot comment on its impact at this time.

    I would give Sublime Security an overall review rating of nine out of ten.

    Prajwal Chougale

    Advanced email defenses have reduced phishing false positives and improved SOC investigations

    Reviewed on Jul 07, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Sublime Security  is email security, as it provides an AI-powered email security platform designed to manage all the emails coming to the organization, which is comparable to other email security tools available, allowing us to detect phishing attacks using different rules.

    Regarding my main use case for Sublime Security , we mainly use it as an email security tool, which is customizable with detection logics and automation capabilities that help us understand why emails are flagged, enabling organization-specific detections.

    What is most valuable?

    The best features of Sublime Security include its seamless integration with Microsoft 365, which can be set up easily within three to four hours, the built-in detection rules that are effective against phishing, and its ability to reduce false positives compared to Microsoft Defender.

    The customization and threat hunting features of Sublime Security have helped my team by allowing us to create specific detection rules for quarantined emails and alerting SOC analysts automatically, and one notable instance involved identifying a compromised user through flagged suspicious alerts.

    Sublime Security positively impacts my organization with AI-driven detection that reduces false positives and improves alert severity, providing timely notifications to the SOC analyst if any interaction occurs after clicking a potentially malicious link.

    What needs improvement?

    To improve Sublime Security, I would appreciate better reporting capabilities, as the current reports are too high-level for regular SOC operations.

    Apart from reporting, everything else about Sublime Security is impressive.

    For how long have I used the solution?

    I have been using Sublime Security for more than around 1.5 years.

    What do I think about the stability of the solution?

    Sublime Security is stable, with minimal maintenance times and high reliability, experiencing very few downtimes.

    What do I think about the scalability of the solution?

    Sublime Security's scalability is impressive, accommodating organizations of various sizes and capable of handling growth effortlessly.

    How are customer service and support?

    I raised multiple support cases regarding report availability, and they have been very responsive, showing a commitment to resolving issues.

    I would rate the customer support a 9.5.

    Which solution did I use previously and why did I switch?

    I have exclusively used Sublime Security for this customer, but I have used Avanan  and Microsoft Defender for others, and I find Sublime Security to be one of the best tools for email security.

    How was the initial setup?

    The best features of Sublime Security include its seamless integration with Microsoft 365, which can be set up easily within three to four hours.

    What about the implementation team?

    We are customers of Sublime Security, without any other business relationship.

    What was our ROI?

    While quantifying return on investment is challenging, Sublime Security has helped my team by avoiding multiple false positives and facilitating better investigations.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing is limited, but I noticed that Sublime Security was slightly more expensive than Avanan  or Defender, as Defender comes included with other Microsoft products, but I believe Sublime Security is value for money.

    Which other solutions did I evaluate?

    Before choosing Sublime Security, we evaluated Avanan and Defender 365, but clients opted for Sublime Security due to its superior detection rules and customer support.

    What other advice do I have?

    If pricing is not an issue, I advise others to go for Sublime Security.

    Reduced vendor dependency in deploying new protections with Sublime Security matters to us as it enhances email classification and security alerts, aiding in the detection of subtle threats.

    The impact of Autonomous Detection Engineer (ADA) on our detection coverage has been significant, blocking over 1,500 to 1,800 emails classified mostly as spear-phishing targeting VIP users.

    As for the AI agents, we have not fully utilized their capabilities yet, relying more on improving detection rules and email classification.

    I rate this product a 9 overall.

    reviewer2809026

    Advanced email rules have improved spam detection and made daily reviews more efficient

    Reviewed on Jul 03, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Sublime Security is to test how this product works, so I am using this for that purpose.

    For a quick specific example of what I tested with Sublime Security, it detects the emails of the person on this side to check that feature, and there is a feature in Sublime Security that is detection as code, which is an excellent feature that I have noticed in this product. I am talking about eleven hundred, and that detection feature is something where I can explicitly customize mentions of power spam or non-structured email. With our custom permissions, we have it, and getting that notice by word blocking is something very important. It is a great feature that I have been using.

    Regarding my main use case for testing Sublime Security, it is very good, and I fully specify that detection; it is something very extensive with maximum features.

    What is most valuable?

    The best features Sublime Security offers include detection as code, which gives a very powerful feature for users to write rules, custom objects, and the language provides some syntax that is definitely a good feature. The second one is why it detects spam emails or justifies why this is considered spam, which is the second most valuable feature.

    I use the detection as code feature in my day-to-day life, which usually identifies junk emails and spam emails by default with the conditions and the vast dataset it has. Even if some emails may not get into that machine learning dataset, I can describe if it is from an external source and has rewards; I can remove it since it is considered spam. This feature changes the usual segregation and categorization, helping users not fall for known types of emails that the system may not detect. The explanation of justification, instead of just flagging something as spam, gives the user understanding such as, this is not a Google email; we really cannot click on it. It enhances user security, and even if another user sees this type of content based on gesture events for another email, they think not to use the image correctly.

    Sublime Security has positively impacted my organization.

    What needs improvement?

    I would say there are very minimal changes needed regarding Sublime Security; for first-time users, it can be difficult knowing how to write the tool. Having some templates available would improve the experience.

    My advice for others looking into using Sublime Security is that each edition would be helpful for initial users, and users should set templates in, which can be added; right now, I am not trying anything new, as this is cool.

    For how long have I used the solution?

    I have been using Sublime Security for three months.

    What do I think about the stability of the solution?

    Sublime Security is stable; I confirm this.

    Which solution did I use previously and why did I switch?

    I did switch to Sublime Security; it is part of my style of working.

    Which other solutions did I evaluate?

    Before choosing Sublime Security, I evaluated alternatives such as MyCast and Proofpoint, which I refused before finalizing on Sublime Security.

    What other advice do I have?

    Phishing versus phishing detection is also something I find good, and I have mentioned these things already.

    Since I have been using Sublime Security personally, I have noticed specific improvements like fewer spam emails and improved detection, which saves me time. It helps me segregate emails instead of reviewing all things manually, as it detects spam emails. I do not have to go through every email, which makes me very efficient for other tasks. It also shows if some emails are current, and if I am about to register or receive registration links, it tells me why those emails are separated. I understand better instead of reading all the emails, and it summarizes the words or thumbnails of the emails. If an email is considered good, I continue, making my time more efficient.

    Regarding the AI capabilities of Sublime Security, I think for detection, using ML to analyze content is already a feature present in Sublime Security, which also identifies phishing attempts.

    I think Sublime Security shows false positives. I give this review a rating of nine.

    Dhruv Vaghasiya

    Advanced email defenses have reduced phishing incidents and improve response to targeted attacks

    Reviewed on Jun 29, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Sublime Security  serves as our primary solution for advanced mail threat detection and response. We use it to identify phishing attempts, business email compromise, malicious attachments, credential harvesting campaigns, and other email-based threats before they reach our end users.

    One recent example involved a phishing campaign targeting our finance team members with fake invoices. Using Sublime Security , we detected suspicious indicators such as domain impersonations, link behavior, and email content patterns, which flagged and isolated the messages before users interacted with them, preventing a potential credential compromise.

    We use Sublime Security daily for monitoring inbound email threats and also for investigating suspicious emails, tuning detection rules, and improving our overall email security posture.

    What is most valuable?

    Sublime Security's best features include advanced phishing detection, custom detection rules, real-time threat analysis, and email behavior analysis.

    The detection engine has made the biggest difference because it catches sophisticated phishing attempts that traditional email security sometimes misses.

    In terms of Sublime Security's impact, it has strengthened our email security posture, reduced the phishing risk, improved response time, and increased confidence in our security controls. It has reduced phishing-related incidents by approximately 60% and makes the investigation and response process faster by around 30 to 40%.

    The Autonomous Detection Engineer has made a noticeable difference because it works far better than normal detection rules, thanks to its AI capabilities and the context it has regarding email threats.

    I find the controllable and transparent AI in Sublime Security regarding its decision-making process and auditability to be excellent, allowing us to control all the security workflows effectively.

    What needs improvement?

    Sublime Security is a great tool, but improvements are needed in areas such as better executive-level summaries, a more advanced reporting dashboard, and more automated remediation workflows. Additionally, integration with security platforms could be more useful.

    The product is already strong from a detection perspective, and most improvements should focus on reporting, automation, and broader integration.

    For how long have I used the solution?

    I have been using Sublime Security for about 11 months.

    What do I think about the stability of the solution?

    Sublime Security has proven to be stable and dependable in our daily operations.

    What do I think about the scalability of the solution?

    Sublime Security's scalability is very good, and it scales well with growing email volume and evolving threat patterns.

    How are customer service and support?

    Our customer support has been responsive and technically knowledgeable, leading to a great experience with their team.

    Which solution did I use previously and why did I switch?

    We previously relied on default email security controls and a combination of security monitoring tools because we needed stronger protection against increasingly sophisticated phishing attacks and better visibility into email threats.

    How was the initial setup?

    The setup is relatively straightforward, and the pricing feels reasonable considering the value it provides in preventing phishing and email-based threats.

    What about the implementation team?

    We directly purchased Sublime Security from the vendors.

    What was our ROI?

    The ROI comes from reduced phishing risk, faster incident response, and lower operational overhead, making it a very good investment.

    What's my experience with pricing, setup cost, and licensing?

    On average, Sublime Security has prevented about 200 to 300 malicious emails daily for all users, which equals around 6,000 to 7,000 per month, totaling approximately 60 to 70,000 over the 10 to 11 months we have used it.

    Which other solutions did I evaluate?

    We evaluated Abnormal Security  and Microsoft Defender before choosing Sublime Security.

    What other advice do I have?

    Sublime Security is performing well with its SaaS platform, but for enterprise levels, they might need to consider adjustments such as license pricing and setup for on-premises clients.

    My advice to others looking into using Sublime Security is to integrate it fully with your email environment and security workflows and to spend time tuning detection policies early to maximize value and reduce noise, as it is a great tool that provides enterprise-level security.

    I find that the threat detection is accurate and very reliable, with strong detection performance and relatively low false positives, which is vital for operational efficiency.

    I would rate this review a 9 out of 10.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    View all reviews