Skip to main content

Ṣọ for Enterprise

Protect every mailbox.
Keep none of the mail.

Managed mailbox protection for organizations. The Ṣọ Shield API for product and SOC teams. A partner platform for MSPs. One detection engine behind all of it, and it never stores email content.

90.7%
detection accuracy
90+
risk indicators per email
0
emails stored on our servers
< 1 day
org onboarding, one admin consent

Who Ṣọ is built for

One detection engine, three ways to buy it. Run it on your own mailboxes, build on the API, or resell it to the clients you manage.

For enterprises & IT teams

Protect every mailbox

Managed protection across your whole organization from one admin consent. No MX changes, no per-user installs, no rerouted mail.

See how it deploys

For product & SOC teams

Build on the detection engine

Seven API endpoints for phishing, BEC, URLs, domains, and documents. Embed detection in your own product, SIEM, or AI agents.

Explore the Shield API

For MSPs & MSSPs

Protect every client you manage

A multi-tenant partner platform: each client fully isolated, quarantine and a cross-client dashboard, and per-mailbox metering for wholesale billing.

See the partner platform

Two ways to deploy Ṣọ

Protect your own organization's mailboxes, or embed the detection engine inside something you build. Same engine, same zero-retention rule either way.

Ṣọ Email Security for organizations

Managed protection for every mailbox in your company through app-connect. One admin grants one consent, and the whole organization is covered. No MX changes, no per-user installs, no rerouted mail.

  • Google Workspace domain-wide delegation
  • Microsoft 365 admin consent
  • One consent covers every mailbox in the org
  • Onboarding in under 1 business day
Talk to sales about your org

Ṣọ Shield API

Embed the same detection engine in your own product or SOC pipeline. Seven endpoints, authenticated with an API key, priced in credits.

  • Phishing, BEC, and social engineering verdicts with confidence and severity
  • URL, QR code, domain, and header analysis
  • Cross-document fraud and invoice tampering checks
  • Self-serve keys, free tier of 3,000 credits a month

Two products, one detection engine

Protect your own people with Ṣọ Email Security, build on the same engine with Ṣọ Shield, or run both. Every verdict is produced without ever storing your mail.

Ṣọ Email Security

Managed protection for every mailbox

The full detection engine, applied to your organization's inboxes. It catches what reaches your people and holds the dangerous mail before they act on it.

  • Phishing and spoofed-sender detection
  • Business email compromise and wire-fraud protection
  • Lookalike and typosquatted sender domains
  • Malicious link and attachment scanning
  • QR-code phishing (quishing) detection
  • Dark web breach monitoring for your domains
  • Deepfake detection in video meetings
  • In-tenant quarantine with admin release, block, and delete
  • Plain-language alerts that explain every verdict
  • 90.7% detection accuracy across 90+ risk indicators

Ṣọ Shield API

Embed the detection engine in your own stack

The same threat detection, exposed as seven endpoints. Wire it into your SOC, your product, or your AI agents and get a structured verdict on demand.

  • Email analysis for phishing, BEC, spam, and malware
  • Business email compromise risk scoring, 0 to 100
  • URL risk checks for suspicious and disguised links
  • Domain impersonation and reputation checks
  • Email authentication (SPF, DKIM, DMARC) checks
  • QR-code destination scanning
  • Document comparison for altered invoices and payment details
  • Drop into your SOC, SIEM, product, or AI agents
  • Self-serve API keys with a sandbox for testing
  • Free tier: 3,000 credits every month, no card

Not sure which fits? Talk to sales and we will map it to how your organization runs email.

Design partner program · Now onboarding

A partner platform for MSPs and MSSPs

Manage email security for every client from one console, on wholesale pricing, under your own client relationships. We are building this multi-tenant layer with a small group of design partners now, so what follows is the working spec rather than shipped features or a promise of dates. Partners who join early shape it around their own client base.

Tenant hierarchy with hard isolation

Partner, then organization, then mailbox. Every client tenant is walled off from every other. No shared views, no cross-tenant access, ever.

Per-client allow and block lists

Set partner-wide defaults once, then override per client. Each organization keeps its own lists without losing your baseline policy.

In-tenant quarantine

A flagged message moves to a quarantine folder inside the client's own mailbox. We store only metadata and the verdict, never the content. Admins release, block, or delete.

Partner dashboard

A cross-client verdict feed, quarantine queues, and mailbox counts in one place. Per-mailbox usage metering feeds your wholesale billing.

MX-inline gateway, fail-open by design

Mail is scanned in memory in under 5 seconds at p95. On timeout, the message delivers unscanned. A backup MX routes around us entirely. Mail delivery is never at risk.

RBAC and audit log

Partner admin, org admin, and viewer roles, with every administrative action recorded. Your clients can see exactly who did what.

Running client tenants today and want a say in how this works? Ask about the design partner program.

Why enterprises pick Ṣọ

Nothing stored.
Nothing to breach.

Every email Ṣọ analyzes is processed in memory and discarded the moment the verdict is returned. There is no archive of your mail, or your clients' mail, sitting on our servers. Nothing to breach, nothing to subpoena, nothing to leak.

How Ṣọ works

Content is analyzed in memory against 90+ risk indicators. The verdict comes back, the content is gone. Quarantine keeps metadata and the verdict only, and the message itself never leaves the client's mailbox.

GDPR-compliant. Google CASA verified.

How legacy tools work

IRONSCALES, Barracuda, and Abnormal store email data to operate. Every message they hold is a copy of your business, and your clients' business, living on someone else's infrastructure for as long as they keep it.

Their retention becomes your risk.

Built with working MSSPs

We design against the operational reality of security providers who run many client tenants at once, not against a demo environment. Every partner feature starts from a question a practitioner actually asked.

  • Triage across tenants

    One analyst covering dozens of clients needs one verdict feed, not dozens of logins. Cross-client visibility is the default view, not an add-on.

  • Client trust is the business

    Hard isolation between tenants, and no retained email content anywhere, keeps your client agreements and your DPAs simple.

  • Margin lives in metering

    Per-mailbox usage data has to be accurate enough to bill wholesale against. We treat it as a billing record, not a vanity chart.

  • Nobody forgives lost mail

    Fail-open is mandatory in our gateway, not a toggle someone can flip. If Ṣọ is slow or down, your clients' mail still delivers.

Enterprise FAQ

The questions security teams and partners ask us first. Anything missing, ask sales@soemailsecurity.com.

Do you store our email content?

No. Email content is analyzed in memory and discarded as soon as the verdict is returned. Nothing is written to our servers. When a message is quarantined, it stays inside the client's own mailbox. We keep only metadata and the verdict, never the content.

What happens if the gateway is slow or goes down?

Mail still delivers. The MX-inline gateway is fail-open by design, and that is mandatory, not a setting. Messages are scanned in memory in under 5 seconds at p95. If a scan times out, the message is delivered unscanned. A backup MX routes around us entirely, so mail delivery is never at risk.

How long does onboarding take?

For organizations, under one business day. A Google Workspace or Microsoft 365 admin grants one consent and every mailbox in the org is covered. There are no per-user installs. For the Ṣọ Shield API, you can create a key in the self-serve dashboard and make your first call in minutes.

Who controls quarantine?

The client's admin does. A flagged message is moved to a quarantine folder inside the client's own mailbox, not onto our infrastructure. Admins can release, block, or delete each message. Ṣọ holds only the metadata and verdict needed to run the queue.

How does billing work for partners?

The partner platform meters usage per mailbox, per client, so you can bill wholesale from one number. Ṣọ Shield API plans are credit-based, from a free tier of 3,000 credits a month up to an unlimited enterprise plan. Partner and enterprise pricing is agreed directly with sales@soemailsecurity.com.

How do we migrate in, and how do we roll back?

App-connect deployments change nothing about your mail flow, so rollback is revoking the admin consent. The MX-inline gateway is a DNS change, so rollback is pointing MX records back. Because we never store email content, there is no data to export and nothing left behind on our side.

Bring zero retention to your organization

Tell us how many mailboxes you run, or how many client tenants you manage, and what you need from quarantine and billing. We reply within one business day.