Overview
Sublime's agentic platform stops more email attacks with less work. It's team of AI agents work like a digital SOC team in your environment, triaging and blocking advanced threats while adapting protections at adversary speed. It provides full transparency and automation by default, with control on demand for advanced teams, eliminating vendor bottlenecks or one-size-fits-all limits.
Get an AWS Private Offer and speak with the team at sales@sublimesecurity.com
Highlights
- By stopping more attacks and reducing false positives, Sublime delivers a superior autonomous AI experience that requires less work. For advanced teams, the platform is fully extensible, allowing you to author your own detections and hunt for threats with a level of precision that one-size-fits-all solutions can't.
- Block sophisticated threats (BEC, novel phishing, QR-based phishing) and reduce the false positives that waste time and disrupt workflows. Sublime's tailored protections deliver a demonstrably higher catch rate, validated by the world's most demanding security teams.
- Protect Microsoft 365 and Google Workspace accounts with no MX changes. Deploy in Sublime Cloud or self-host on AWS.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Trust Center
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
Price per Mailbox | Annual price per mailbox starting at | $76.20 |
Vendor refund policy
We do not currently support refunds.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
Sublime Security Support Policy can be found at
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products
Customer reviews
Streamlined email triage has reduced phishing response time and improves investigation clarity
What is our primary use case?
My main use case for Sublime Security is email security and phishing detection, where I use it to investigate suspicious emails, identify phishing and BEC attempts, analyze malicious links and attachments, and support the triage and remediation process.
One example of how I used Sublime Security to handle a real situation is when it flagged a phishing email that appeared to come from a legitimate vendor based on the sender and email content. I used it to investigate the links and other indicators, confirmed it was a phishing attempt, and removed the message from affected mailboxes, which helped prevent users from interacting with it.
I mainly use Sublime Security as part of my day-to-day email alert triage, which helps me quickly identify suspicious emails, investigate phishing and BEC attempts, and gather useful context before deciding whether to close or escalate an alert. I also find the automation and remediation capabilities helpful for reducing manual work.
What is most valuable?
For me, the best features Sublime Security offers are phishing and BEC detection, detailed email analysis, threat hunting, and automated triage remediation. I appreciate that the detections are transparent, allowing me to understand why an email was flagged instead of just receiving a black box verdict. Sublime Security's AI Analyst is particularly useful for automatically investigating user-reported emails and reducing manual triage work.
Sublime Security's AI Analyst has helped me reduce the amount of manual email triage I need to do because when users report suspicious emails, it analyzes the message, links, attachments, and sender context and provides a verdict with reasoning. This gives me a quick starting point for investigation instead of reviewing everything manually, which saves time especially when there are a large number of user-reported emails. This allows me to focus my attention on cases that actually need deeper investigation.
I particularly appreciate the combination of detections, threat hunting, and remediation in one platform. The campaign grouping is useful because I can investigate related emails together instead of treating every message as a separate alert. The transparency of the detections is another strong point as it helps me understand why a message was flagged.
Sublime Security has positively impacted my organization by helping our team reduce manual email triage and respond to phishing and BEC threats faster. The automated analysis and remediation allow analysts to spend less time reviewing routine user-reported emails and more time on higher-risk investigations. It also gives us better visibility into why an email was flagged, making investigations and escalations easier.
The biggest measurable impact has been reducing the time spent on email triage, handling user-reported phishing emails faster, and reducing the amount of manual investigation required. Although I don't have a specific organization-wide percentage to share, the improvement is noticeable in analyst workload and response time.
What needs improvement?
I believe the main areas for improvement for Sublime Security are ease of onboarding and learning, as the platform has many powerful capabilities, making it take some time for new analysts to become comfortable with all the features and detection logic. I would also appreciate continued improvements in customization and integration, especially for fitting it smoothly into different SOC workflows.
Regarding needed improvements, I think the documentation is generally useful, but I would appreciate more beginner-friendly guidance and practical SOC examples, particularly around setting up detections, tuning rules, and integrating Sublime Security with SIEM and SOAR platforms. The API and integration options are already strong, but clearer step-by-step examples would make it easier for analysts to get started and build more advanced workflows.
For how long have I used the solution?
I have been using Sublime Security for 1.5 years.
What other advice do I have?
I would recommend Sublime Security to teams that want to strengthen their existing email security and reduce manual phishing triage. I suggest they start with a focused evaluation using real user-reported emails and measure detection quality, false positives, and analyst time saved. I have covered all the relevant points regarding Sublime Security. I give this product a rating of 9.
Focused email threat workflows have improved phishing investigations and automate remediation
What is our primary use case?
I usually start by reviewing the sender, then proceed with header analysis, URL and attachment review, and analyzing the message content. After that, I check the threat indicators and detection results to understand the risk, and if it is confirmed, I use Sublime Security's remediation capabilities to remove or quarantine the email and document the incident.
I also use Sublime Security to investigate similar email campaigns and identify patterns across users. Its detection and remediation capabilities help me respond consistently, reducing manual work and improving the overall security posture.
What is most valuable?
Campaign grouping helps us identify similar phishing patterns across multiple users and investigate them as one campaign instead of handling each email separately, which makes it easier to spot common IOCs, understand the attack pattern, and quickly remediate all related messages. This saves our time and improves consistency.
Sublime Security has improved our email threat detection and response by helping us identify phishing and Business Email Compromise campaigns faster, investigate related emails, and automate remediation, which has reduced our manual effort and improved our response time. This enables us to better protect against email-based threats.
What needs improvement?
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
What was our ROI?
What other advice do I have?
Advanced email rules have improved spam detection and made daily reviews more efficient
What is our primary use case?
My main use case for Sublime Security is to test how this product works, so I am using this for that purpose.
For a quick specific example of what I tested with Sublime Security, it detects the emails of the person on this side to check that feature, and there is a feature in Sublime Security that is detection as code, which is an excellent feature that I have noticed in this product. I am talking about eleven hundred, and that detection feature is something where I can explicitly customize mentions of power spam or non-structured email. With our custom permissions, we have it, and getting that notice by word blocking is something very important. It is a great feature that I have been using.
Regarding my main use case for testing Sublime Security, it is very good, and I fully specify that detection; it is something very extensive with maximum features.
What is most valuable?
The best features Sublime Security offers include detection as code, which gives a very powerful feature for users to write rules, custom objects, and the language provides some syntax that is definitely a good feature. The second one is why it detects spam emails or justifies why this is considered spam, which is the second most valuable feature.
I use the detection as code feature in my day-to-day life, which usually identifies junk emails and spam emails by default with the conditions and the vast dataset it has. Even if some emails may not get into that machine learning dataset, I can describe if it is from an external source and has rewards; I can remove it since it is considered spam. This feature changes the usual segregation and categorization, helping users not fall for known types of emails that the system may not detect. The explanation of justification, instead of just flagging something as spam, gives the user understanding such as, this is not a Google email; we really cannot click on it. It enhances user security, and even if another user sees this type of content based on gesture events for another email, they think not to use the image correctly.
Sublime Security has positively impacted my organization.
What needs improvement?
I would say there are very minimal changes needed regarding Sublime Security; for first-time users, it can be difficult knowing how to write the tool. Having some templates available would improve the experience.
My advice for others looking into using Sublime Security is that each edition would be helpful for initial users, and users should set templates in, which can be added; right now, I am not trying anything new, as this is cool.
For how long have I used the solution?
I have been using Sublime Security for three months.
What do I think about the stability of the solution?
Sublime Security is stable; I confirm this.
Which solution did I use previously and why did I switch?
I did switch to Sublime Security; it is part of my style of working.
Which other solutions did I evaluate?
Before choosing Sublime Security, I evaluated alternatives such as MyCast and Proofpoint, which I refused before finalizing on Sublime Security.
What other advice do I have?
Phishing versus phishing detection is also something I find good, and I have mentioned these things already.
Since I have been using Sublime Security personally, I have noticed specific improvements like fewer spam emails and improved detection, which saves me time. It helps me segregate emails instead of reviewing all things manually, as it detects spam emails. I do not have to go through every email, which makes me very efficient for other tasks. It also shows if some emails are current, and if I am about to register or receive registration links, it tells me why those emails are separated. I understand better instead of reading all the emails, and it summarizes the words or thumbnails of the emails. If an email is considered good, I continue, making my time more efficient.
Regarding the AI capabilities of Sublime Security, I think for detection, using ML to analyze content is already a feature present in Sublime Security, which also identifies phishing attempts.
I think Sublime Security shows false positives. I give this review a rating of nine.
Advanced email protection has enabled us to safeguard partners and reduce costly phishing risks
What is our primary use case?
Our main use case is two-fold. Primarily, as a channel partner, our core focus is channel enablement. We actively pitch, demonstrate, and distribute Sublime Security to our partner network, who then deploy it for end-user organizations. Secondarily, we 'drink our own champagne' by running it internally to protect our own business communications.
When we position it to our partners, we frame it as an advanced email security platform. It goes far beyond traditional junk filtering by actively hunting the sophisticated threats that bypass native defenses—specifically Business Email Compromise (BEC), CEO fraud, invoice scams, fake login pages, and malware attachments.
How has it helped my organization?
As a distributor, the positive impact for us is measured by how well the product performs for our partners and their end-users. Sublime Security has been a major positive because it perfectly fits our criteria for 'best-in-breed' solutions. Specifically, it delivers strong ROI, saves employee time, and significantly reduces risk exposure by preventing expensive breaches. Because it checks all these boxes, we've been able to successfully enable our partners across all our regions to confidently take it to market.
Another major positive is its deployment model. In today's cybersecurity landscape, 'rip-and-replace' is a massive hurdle for buyers. Sublime works flawlessly with existing tools, enhancing a customer's current stack rather than forcing them to rebuild it.
What is most valuable?
The standout features of Sublime Security revolve around its ability to catch advanced threats that bypass native defenses. Specifically, it excels at blocking malware attachments and stopping Business Email Compromise (BEC), such as CEO fraud and invoice scams.
A major advantage is its fast time-to-value because it isn't a rip-and-replace solution. Instead, it acts as a 'smarter layer' that enhances existing protections like Microsoft 365 or Google Workspace. While native security catches the obvious junk, Sublime uses flexible, customizable detection logic to catch the highly sophisticated attacks that easily slip through standard filters.
Finally, the platform gives you deep visibility and fast search capabilities across all email activity. Without a tool like this, investigations take far too long, and teams lack visibility into what actually breached the inbox. Sublime solves this by offering rapid detection, automated response actions, and the ability to quickly remove malicious emails in bulk.
What needs improvement?
Based on the feedback we receive from our partners and their end-users, there are two main areas for improvement: the learning curve and pricing for smaller organizations. First, while the platform is incredibly powerful, it isn't simply 'plug-and-play.' Security teams need to invest time into learning the product to extract its full value.
Second, the cost can feel a bit steep for small-to-medium-sized businesses (SMBs). However, we always caveat this by looking at the ROI: a single breach could put a small company completely out of business. While the upfront cost might seem high to them, preventing just one catastrophic breach means the tool instantly pays for itself.
For how long have I used the solution?
I have been using the solution for eighteen months.
What other advice do I have?
On a scale of one to ten, I rate Sublime Security a nine out of ten because I believe there are a couple of negatives regarding scalability for catering to enterprise and small to medium enterprises. Additionally, the product requires a learning phase, and it is not readily usable right away.
Sublime Security merits this rating because of a couple of changes that need to be addressed. If it catered to both small and enterprise businesses on a pricing scale, it would receive a ten, but it is not far away.