Distributed Detection Model
How a message travels through Sublime
From first contact to verdict — every analysis layer, detection rule, response action, and AI agent. Click any node to explore.
Sublime protects all three email traffic types through your existing mail flow. No rerouting required — integrates via API or inline MTA with Microsoft 365, Google Workspace, and IMAP sources.
Every message is fully decomposed before analysis. Attachments are recursively unpacked, QR codes decoded, embedded images extracted for OCR, and all URLs pulled for live navigation. The result is a rich Message Data Model (MDM) that detection rules query against.
Unlike black-box models, every Sublime verdict is backed by the specific rules that fired and clear evidence of why. Analysts see exactly which rules matched and what signals triggered them — enabling instant remediation without a vendor ticket.
Attack score is computed in parallel with the detection verdict — not after it. It takes the set of fired rules and identified messaging insights, runs them through a dedicated model, and produces a numeric confidence signal for prioritizing response across a campaign.
Each detection rule triggers one or more actions automatically on match — no manual intervention required unless you want it.
Webhooks and native integrations push verdicts and threat data to your SIEM, SOAR playbooks, and Slack channels in real time. Tines and Splunk supported out of the box.
Built-in analytics show what's getting caught, who's most at risk, and what's being handled automatically. Every stat traceable to underlying data — no black box.
Autonomous by default · control on demand
How Sublime delivers value at every step
From first contact to closed coverage gap — every layer stops more attacks, eliminates busywork, and adapts at adversary speed. Click any node to see the business outcome.
Most vendors only protect one direction. Sublime covers inbound, internal, and outbound email through your existing mail flow — preventing data loss and policy violations with no rerouting required.
Attackers hide payloads in formats your team doesn't have time to inspect. Sublime decomposes every message before analysis — unpacks nested attachments, decodes QR codes, reads embedded images via OCR, and pulls every URL for live inspection. Nothing gets through unchecked.
Every verdict shows the exact detection that matched and the signals that triggered it. Analysts make confident calls, defend decisions to leadership, and remediate in minutes — not after opening a vendor ticket.
When multiple detections fire across a campaign, attack score gives your team a clear severity signal. No guessing which alerts matter — the highest-risk threats reach the top of the queue.
Threats are quarantined, banner-flagged, or routed to spam automatically — no daily review queue, no human in the middle of every decision. Your team intervenes when they want to, not because they have to.
Push verdicts, attack scores, and threat data into the tools your team already uses in real time. Tines and Splunk work out of the box. Sublime adds capability without forcing you to swap out tools your team already trusts.
Built-in Attack Insights show what's getting caught, who's most at risk, and what's being handled autonomously. Customers report a 5x efficiency gain — cutting weekly email security management from 10 hours to under 2.


