Skip to main content

How it works

Two solutions. You choose where enforcement happens.

Both protect Microsoft 365 and Google Workspace. The difference is when a threat is stopped, and whether you also control what leaves.

API and Gateway compared

APIConnects in hours. Nothing changes in how your mail flows.
GATEWAYStops threats before they're delivered, and controls what leaves.
How it connects
APIConnects to Microsoft 365 or Google Workspace by API.
GATEWAYMail is routed through MnemoShare before delivery and back. Your mail stays hosted where it is today, and your domain's email settings stay the same.
How threats are found
APISender identity checked against your history, AI reading each message for intent, and account-takeover signals, with named reasons.
GATEWAYThe same layers, applied before delivery.
When threats are stopped
APIAfter delivery: harmful mail is pulled out of every inbox it reached.
GATEWAYBefore delivery, and after it too, through the API connection that's included.
Sensitive data going out
APINot included.
GATEWAYCaught, then redacted, held, or sent as a secure link with proof of who opened it.
Mail between colleagues
APIScanned continuously.
GATEWAYScanned continuously.
Links
APIChecked again at the moment of click.
GATEWAYChecked again at the moment of click.
Getting started
APIAn admin approval. First detections within hours.
GATEWAYA routing change in your email admin console, one domain at a time. No downtime.
Best when
APIYou want fast, disruption-free protection on top of native filtering.
GATEWAYPolicy must be enforced before delivery, or outbound data is in scope.

The Gateway's mail flow

An inline gateway without the migration.

Traditional gateways mean re-pointing your email to them. The Gateway works alongside your email platform instead: mail arrives where it always has, is checked by us, and comes back for delivery.

Which fits you?

Two questions.

Answer both and we'll point you to the right solution. You can always start with one and add the other.

1. Must threats be stopped before anyone can open them?
2. Is sensitive data leaving by email a concern?
Answer both questions to see a recommendation.

Four ways to deploy

Two solutions, deployed the way your team works.

The protection is the same across all four. What changes is where enforcement happens.

API

API on its own

Best when you want protection layered on native filtering, fast.

Detection, removal from every affected inbox, and hijacked-account response.

GATEWAY

Gateway on its own

Best when policy must be enforced before delivery, or outbound is in scope.

Blocking before delivery, outbound data protection and secure-link delivery. API connection switched off.

GATEWAY

Gateway beside your current API tool

Best when an API service already handles inbound and is staying.

Enforcement before delivery plus outbound protection. Your existing tool is untouched.

GATEWAY · DEFAULT

Gateway with API connection on

Best when nothing should arrive, and anything that turns harmful later should still be pulled back.

Both halves working together, with no double scanning and no duplicate alerts.

Turning the Gateway's API connection on or off doesn't change the price.

Either solution

Both protect Microsoft 365 and Google Workspace, with every capability included.

See pricing

The low-risk path

Start with the API. Add the Gateway when you want enforcement instead of alerts.

See it on your own mail

Optional add-on

Sandbox testing for suspicious attachments

Suspicious files are opened in isolation and watched, through our partner VMRay, in their cloud or inside your own environment. Priced on top of either solution.

For your IT & security team

Need the technical detail?

Mail routing, API scopes and deployment architecture for each option.