Skip to main content

Gateway

Enforce before delivery. Control what leaves. Keep your data where you decide.

The Gateway checks every message before it reaches an inbox, and every message before it leaves. Its included API connection keeps watching internal mail and checks links at the moment of click.

No migration. Your email stays hosted where it is today, and the Gateway goes in without downtime.
Gateway status and setup: gateway running, filtering on for inbound and outbound mail, attachment size limit and quarantine retention

How it fits

An inline gateway without the migration.

Traditional gateways mean re-pointing your email to them. API-only tools clean up after delivery. The Gateway checks every message before it reaches an inbox, while your email stays hosted exactly where it is today.

No change to your email setup

Your mail stays hosted where it is, and your domain's email settings stay as they are.

No downtime

Switch over one domain at a time, run side by side, then turn on enforcement.

Before and after delivery

Blocked on the way in, and still pulled back if something turns harmful later.

Outbound included

Sensitive data going out is caught in the same pass. Not a separate product.

How detection works

More than a filter with AI bolted on.

Every message is checked for who is really writing, what they want from you, and whether the account behind it is still in the right hands, before it reaches anyone.

01

Who is this, really?

The sender is checked against your history with them: first contact, a long-dormant vendor, a look-alike domain, a borrowed display name, a broken sender signature.

display-name impersonation
look-alike domain · reply-to mismatch
02

What are they asking for?

AI

AI reads each message for intent the way a careful colleague would: changed bank details, urgent wire or gift-card requests, payroll changes, W-2 requests, pressure from “the CEO.”

financial intent · urgency
wire · invoice · payroll · W-2
03

Is the account still theirs?

Through the included API connection, unusual sign-ins are matched with unusual mail. A taken-over account has its sessions ended and its messages pulled back.

account takeover
unusual sign-in + unusual mail
04

Hold it, and explain why

Held before delivery, delivered with a warning, or redacted on the way out, with the named reasons shown to your team. An admin's release decision always stands.

held before delivery
reasons: shown to your team

What it stops

  • Business email compromise
  • CEO and vendor fraud
  • Account takeover
  • Impersonation & look-alike domains
  • Invoice & payroll fraud
  • Credential phishing
  • Phishing from a compromised colleague

What it does

Everything a gateway should do, plus the layer most never covered.

Stops threats before delivery

Fraud, phishing and malicious attachments are held before anyone can open them. Your team reviews and releases.

Catches sensitive data going out

Patient, customer and financial details are spotted, even buried in a sentence, then redacted or held.

Turns attachments into secure links

Risky files go out as links that expire, can be revoked, and show who opened them.

Watches mail between colleagues

The included API connection scans internal mail continuously and pulls back anything that turns harmful later.

Checks links at the click

A link that was safe on arrival and harmful by Tuesday is caught when someone clicks it.

Runs where you decide

Operate it in your own environment or a hosting partner's, so mail never passes through our cloud.

No migration

No change to where your email is hosted. No downtime.

Talk about replacing your gateway

Replacing Proofpoint or Mimecast?

A gateway replaced by a gateway. Not a migration project.

Nothing about how your mail flows changes. It's a configuration change, one domain at a time.

Stays the same

  • Protection on mail in, out and internal
  • Blocking before delivery, with review and release
  • Nothing to install for senders

What changes

  • Outbound data protection included, not a separate product
  • Attachments can become secure links
  • One console for email and file sharing
  • One contract instead of several

The work

  1. 01Route mail from your admin console, one domain at a time. Your domain's email settings stay the same.
  2. 02Bring your existing policies across
  3. 03Run side by side, then switch on enforcement
Where they still lead

We don't offer long-term email archiving or continuity. Sandbox testing is an add-on here, where some vendors bundle it. If archiving is a hard requirement, we'd rather tell you now than three months into an evaluation.

Pricing

Graduated per user. Every capability included.

The rate falls as you grow, with no jump at a band boundary. The API connection is included, on or off.

Full pricing
750–999 users (minimum)$28,000 / year
Example: 22,000 users$10.86 / user / year

Infrastructure is operated by you or a hosting partner. MnemoShare-operated hosting is quoted separately.

For your IT & security team

Need the technical detail?

Routing options, mail authentication, policy migration and self-hosted architecture.