Sublime news

Meet ADÉ: The Autonomous Detection Engineer for email

September 11, 2025

Authors
AJ Williams
Product Manager
Aryan Luthra
ML Researcher

Sublime launches defensive AI agent that autonomously and continuously adapts detection coverage

Email attacks have grown in speed and scale thanks to AI. Security teams that were already inundated by novel threats and user reports are now seeing a level of sophistication, variation, and volume that did not exist prior to the advent of LLMs.

Most “AI for email security” arrives as a single, opaque model. We’re taking a different path. Our strategy is to build glass-box systems that work the way your team works – transparent, testable, and auditable. Agents coordinate verifiable tools, such as purpose-built ML models, to do real work, learn from feedback, and operate under human review. Our conviction: specialized agents with the right tools, knowledge, and context are the future of email security. They’re more precise than one-size-fits-all models, faster to adapt, and tailored to each environment. Because Sublime is a platform, we’ll keep leveling up at multiple layers: better agents, better tools, better coverage.

In the world of AI attacks, we believe in fighting fire with fire. First, we launched ASA, our defensive AI agent that autonomously triages user reports around the clock. Now we’re going a step further, with an AI agent that automatically responds to the evolving threat landscape.

Meet ADÉ, the Autonomous Detection Engineer that’s turning the table on attackers.

ADÉ breaks from the norms of both traditional (rules-based) and modern (AI-based) email security solutions. It is transparent and explainable AI, not a black box. It writes clear, AI-powered Detection Rules that analysts can understand and verify, not hidden logic that just needs to be trusted. And maybe most importantly, it closes coverage gaps per-environment rather than applying one-size-fits-all Rules to all Sublime users at once.

Here’s how ADÉ operates:

  1. A security analyst or ASA labels a missed attack as malicious and then hands it off to ADÉ.
  2. ADÉ analyzes the attack signals and compares them to existing Detection Rules to determine if it will update an existing Rule or create a new Rule from scratch.
  3. ADÉ validates the Rule against historical data and then refines it to minimize false positives.
  4. ADÉ presents the final Rule with a detailed explanation to a human to review and approve.

Thanks to ASA and ADÉ, security teams can close coverage gaps automatically, without being bottlenecked on vendor-initiated model updates or ever having to write a Rule.

ADÉ is a force multiplier for email security teams

ADÉ isn’t a replacement for analysts and detection engineers – it’s a defensive power-up that amplifies their impact. It helps teams close detection gaps faster from weeks to hours. Closing gaps faster means security evolves as quickly as adversaries do.

Unlike other LLM-based Rule generators, ADÉ completes 100% of the work for you. Proposals are already engineered to work effectively at scale in your environment.

ADÉ is transparent by design

To ensure human security teams maintain confidence in their new AI security assistant, we’ve provided features that promote transparency and operate intuitively:

Backtesting new Rules

ADÉ autonomously iterates, validates, and backtests the Rules it writes to ensure quality and efficacy. The backtest results are provided under the new Rule to maintain total transparency.

Explainable AI

ADÉ provides transparent detection logic with clear comments.

Streamlined approval flow

ADÉ provides thoughtful decision-making without unnecessary friction, all while making sure that a human is always in the loop.

Audit logging

For full transparency, we provide a complete audit log of ADÉ’s API calls.

ADÉ is a fundamental shift in email security

This launch accelerates our agent-based strategy. For your team, that means compounding value: transparent agents, better tools, and better coverage tailored to your environment. We’ll keep improving the agents you have today and introduce new ones over time to extend coverage across the mail security lifecycle.

Start using ADÉ today in your Sublime Enterprise environment to see how easily you can shift to autonomous, proactive security that continuously evolves with attacks. Or book a live demo to see what ADÉ can do for your security team today.

Heading

About the authors

AJ Williams
Product Manager

AJ is a Product Manager at Sublime. Prior to Sublime, she operated as a founding member of the Enterprise team at Stripe, where she launched an incident detection and alerting infrastructure.

Aryan Luthra
ML Researcher

Aryan is a Machine Learning Researcher at Sublime, where he focuses on the intersection of AI, ML, and cybersecurity. He holds degrees in Computer Science and Physics from UC Berkeley and has previously developed ML-focused threat actor tracking algorithms at Microsoft.

Get the latest

Sublime releases, detections, blogs, events, and more directly to your inbox.

Thank you!

Thank you for reaching out.  A team member will get back to you shortly.

Oops! Something went wrong while submitting the form.

Related Articles

November 3, 2025
Attack spotlight

ICS phishing: Stopping a surge of malicious calendar invites

Ahry Jeon
Product Manager
Brandon Murphy
Detection
October 28, 2025
Sublime news

Sublime raises $150M Series C to arm defenders for the post-LLM world

Josh Kamdjou
Co-founder & CEO
Ian Thiel
Co-founder & COO
October 23, 2025
Attack spotlight

Direct Send abuse on Microsoft 365: Just another failed authentication

Peter Djordjevic
Detection

Now is the time.

See how Sublime delivers autonomous protection by default, with control on demand.