Solutions / Email Security

Centeye Lighthouse™ — email security that reads intent, because the costliest email carries no payload.

A polished “CEO” wire request contains no link and no attachment — nothing a gateway can scan. Centeye analyzes the intent and the sender relationship behind every message on Microsoft 365 and Google Workspace, quarantines the fraud per your policy, and retains no message bodies.

Microsoft 365Google WorkspaceAPI-based · no MX change
This surface’s chapter of the attack
Lookalike invoice lands1:02 PM · first-contact sender
Wire pressure + secrecy1:02 PM · financial-intent cues
Auth passes — context doesn’t1:02 PM · verdict: suspect
Fraud calledrelationship + intent evidence
Quarantinedrecoverable · never deleted
What your clients get

Called by context. Resolved beyond the mailbox.

Business email compromise & impersonation, detected from context

Financial intent combined with pressure-and-secrecy cues forces a critical verdict — even when the message passes every authentication check. Context outranks appearances, and every verdict lists its evidence.

  • Lookalike & display-name spoof detection — typosquat domains, homoglyphs, and display names scored against the client’s actual executive roster, derived automatically.
  • Sender relationship baseline — Centeye learns who each client genuinely does business with, from metadata alone. A “supplier” with no real correspondence history receives no supplier trust.
  • Email authentication analysis — SPF/DKIM/DMARC evaluated on every message, plus a posture grade for the client’s own domain. Treated as evidence, not verdict — real BEC frequently passes authentication.
  • Attachment antivirus — malware scanning of attachments and embedded files.
  • Layered analysis, governed cost — deterministic checks first, learning models next, deep reasoning only where a message is genuinely ambiguous. The analysis budget is by design, not by surprise.

context authoritative over "looks clean"

The compromise chain, resolved — not just the message

A fraudulent email is usually one step of a longer chain. Centeye watches the mailbox behaviors that reveal it — and when the evidence indicates the sender’s account is compromised, the incident correlates to the identity plane and response executes there.

  • Malicious forwarding-rule detection — auto-forward and hide rules planted for silent read-along; detected and removed.
  • Rogue OAuth app cleanup — third-party apps granted mailbox access; detected and revoked.
  • Outbound compromise monitoring — a client mailbox mass-sending phishing is caught from metadata alone.
  • Identity-plane response — session revocation, lockout, and MFA enforcement executed from the same incident record.

email × identity · one incident

Honest outcomes, and privacy by design

A flagged message is either moved to a recoverable quarantine or delivered with an explicit “suspected” label. Never a silent delete — legitimate mail is never lost to an over-eager filter.

  • Evidence-first verdicts — every decision lists the trust lane, the lure cues, and the authentication result that produced it.
  • No message-body retention. Mail is analyzed in-stream; content is never persisted after verdict. Reporting is built from metadata and verdicts.

zero email-content retention · enforced by design

How it works

Behind the existing filter, in front of the fraud.

Connect via API

Microsoft 365 or Google Workspace, in minutes — no MX record change, no mail rerouting, built-in filtering stays on.

Baseline quietly

The relationship graph builds from metadata; verdict precision improves as the client’s real correspondence pattern establishes.

Set the outcome policy

Quarantine or label, per client; identity-plane escalations run pre-authorized or on approval, per your response modes.

Kavach · on this surface

Answers “why was this flagged?” with the evidence chain, hunts the same lure across every mailbox and every tenant, and executes the quarantine / rule-removal / OAuth-revoke play within policy.

Argus · for the client

Documents the incident for the client file — “the wire-fraud attempt stopped this month, and the evidence behind it” — in reporting your account managers forward as-is.

Common questions

What MSPs ask us first

Is Microsoft Defender for Office 365 enough?

Defender filters payloads at planetary scale, and it should stay on. The costliest attacks — BEC, executive impersonation, supplier fraud — carry no payload and are rehearsed against those exact filters before sending. Centeye adds the intent-and-relationship read behind the filter. Run both side by side and score what got through.

What is business email compromise, in practice?

A payload-free fraud: an attacker impersonates an executive or supplier — or writes from a genuinely compromised account — to redirect payments or extract data. Because there is nothing to detonate, it is caught by context: sender history, financial intent, pressure cues, and lookalike analysis.

API-based vs secure email gateway — why does it matter?

A gateway sits in the mail path and requires MX changes; an API deployment reads the tenant directly — minutes to deploy, no delivery risk, and visibility into internal and outbound mail a gateway never sees.

Do you read our clients’ email?

Messages are analyzed in-stream to reach a verdict; bodies are never stored. Reporting is built from metadata and verdicts only.

What happens on a false positive?

The message is in recoverable quarantine or delivered with a label — one click restores it, and the relationship baseline learns from the correction.

Two weeks, side by side with your current filter.

Watch-only, no MX change — you keep the findings report either way.