WhiteMail
WhiteMail

AI email security that judges by context

Connect a mailbox and WhiteHat orchestrates seven specialist agents to inspect every message in real time — judging threats by intent and context, not known patterns.

7 detection layersExplainable verdictsEnglish-first (en-first)Data sovereignty · cloud or on-prem
[Urgent] Wire approval needed — Summit project
M
CFO Marcus Thorne <cfo@summit-finance.co>
To: Finance team

Please wire to the new account below by end of day.

It is contract-confidential — do not share or call to verify.

📎 Invoice_49916.pdf
WhiteMail investigationInvestigating…
  1. ·
    SA-01 Identity

    Display name is an exec but the domain is unrelated · Reply-To mismatch

  2. ·
    SA-02 Infrastructure

    SPF/DMARC fail · new look-alike domain (summit-finance.co)

  3. ·
    SA-03 Links & visual

    Links to a fake Microsoft 365 login page

  4. ·
    SA-04 Intent

    Urgent wire + secrecy pressure — BEC pattern

BLOCKBECImpersonation + urgent wire · risk 0.96
Threat landscape

Today's most dangerous emails don't look malicious

BEC, AI-generated phishing, quishing, supply-chain account takeover (VEC) — no attachment, no known signature. Rule- and reputation-based gateways miss them because they can't read context.

Business Email Compromise (BEC)Social-engineering fraud impersonating execs/vendors to trigger wires or data leaks — often with no link or attachment.Learn more

Impersonates execs or vendors to push urgent wires and account changes.

AI-generated phishingA deceptive message impersonating a trusted party to steal credentials, money, or sensitive data.Learn more

Flawless, polished lures that harvest credentials.

Quishing (QR phishing)Phishing that hides a malicious link behind a QR code to bypass URL filters.Learn more

Hides malicious links behind a QR code to slip past filters.

Vendor account takeover (VEC)A supply-chain BEC where a trusted vendor's account is hijacked to swap payment details on invoices.Learn more

A trusted vendor's account is hijacked and payment details are swapped.

Detection approach

Beyond rules — to context

Two ways to stop email threats — and why WhiteMail combines both.

Rule-based

Fixed rules block known patterns fast and precisely — but miss novel variants and clever mutations not in the ruleset.

AI · context

Like a person reading email, it understands intent and context to tell legitimate mail from threats even when no rule matches.

Traditional email security scans for 'words.'
Context-based security understands the 'situation' behind the email.

  • An email suddenly asking for a wire transfer from a vendor you've never dealt with before
  • An email sent from an unusual country or time zone
  • An urgent instruction email in the CEO's name, written in a tone that doesn't match how they usually write
  • An attachment that looks normal, but is out of place given the actual workflow

Known threats by rules, unknown by AI. WhiteMail combines deterministic rules with a self-hosted sLLM so neither blind spot is left open.

Pipeline

Connect → Analyze → Decide → Respond

A four-stage pipeline that finishes the moment mail arrives

Seven specialist agents

Spam, phishing, BEC, impersonation, attachments — one engine, no blind spots.

DEPLOYMENT

Cloud · On-premises · Hybrid

Three deployment scenarios to match your security requirements — drawn exactly as data flows across internet, firewall, and internal network zones.

Connect via mailbox API in five minutes, zero install. Analysis and storage stay in-region, TLS everywhere — the fastest path.

Autonomous response

It doesn't stop at detection — autonomous response

The work is what happens after the verdict. WhiteMail automates report handling, quarantine, employee guidance, and reporting — so it lifts the load off your analysts.

Differentiators

Why WhiteMail

Explainable verdicts

Every verdict comes with the full reasoning behind it — traceable to per-agent scores, signals, and escalation.

Data sovereignty

Runs in the cloud or fully on-prem; with a self-hosted sLLM, message content never leaves your perimeter.

English-first

English UI, signals, and verdict rationale throughout — detection covers global BEC, phishing, and impersonation.

Enterprise integration

IMAP/Gmail/Outlook, real-time push, and SIEM/SOAR export.

Multi-tenant

Per-org policy, dashboards, and roles — up to MSSP operation.

Cost-optimized LLM

Rules filter first; only ambiguous mail hits the model — costs stay controlled.

A memory that learns

Once it learns your organization's contacts and communication patterns, it catches attacks impersonating people you already know.

Deployment

Deploy to match how you operate

Start with non-disruptive monitoring, then switch to inline blocking when you're ready.

API integration (ICES)

Scan post-delivery via API and claw back malicious mail. Five-minute deploy, zero disruption.

Monitoring (journaling)

Receive a copy and report threats — prove value with no impact on mail flow.

Inline blocking

Block before the inbox via connector or gateway.

SIEM / SOAR

Stream every verdict to Splunk or Sentinel for automated response.

About us

We build email security that judges by context.

WhiteHat builds a security engine that understands a sender's intent and relationships the way a person reads email. Seven specialist agents collaborate to catch the targeted threats — BEC, AI phishing, quishing, supply-chain account takeover — that signature- and reputation-based tools miss. We design English-first, with data sovereignty in mind, and run the same engine in the cloud or fully on-prem.

Mission

Protect digital trust — so threats can never deceive people.

Approach

Context over patterns — explainable verdicts.

Principle

Customer data stays the customer's. Sovereign by design.

Protect your inbox in a minute

Start with no credit card. Try it instantly with the demo organization.

Get started free

Your biggest risk is not trying it out.