Stop phishing and payment fraud. Stop sensitive data before it leaves.
Protection for mail coming in, going out and moving inside your organization, for Microsoft 365 and Google Workspace. Connect by API in hours, or run a gateway that enforces policy before anything is delivered.
Stops fraud and phishing
The expensive attacks look like business as usual: a vendor asking to update bank details, an executive who needs a wire sent today, an address made to look like someone you trust.
Every message is judged against who normally writes to you and what they normally ask for, and each detection comes with the reasons behind it, so your team can see why it was flagged.
What it catches
- Payment, invoice and payroll fraud
- Fake requests from executives and vendors
- Email from addresses made to look like people you trust
- Attacks sent from a compromised colleague’s account
What it does
- Checks links again at the moment someone clicks
- Pulls harmful mail out of every inbox it reached
- Spots hijacked accounts and ends the attacker’s sessions
Who is this, really?
The sender is checked against your history with them: first contact, a long-dormant vendor, a look-alike domain, a broken sender signature.
What are they asking for?
The message is read for intent: changed bank details, urgent wire or gift-card requests, payroll changes, pressure from “the CEO.”
Act, and explain why
Deliver, warn, hold for review or remove, with the named reasons shown to your team. An admin’s release decision always stands.
Keeps regulated data from leaving
A spreadsheet of patient records, account numbers pasted into the wrong reply, a formulation attached to the wrong thread. Sensitive content is caught on the way out, even when it’s buried in a sentence.
What it finds
- Medical record numbers, SSNs and insurance IDs
- Card, account and routing numbers
- Patient details written into the body of a message
What happens next
- Redact the text, or hold the message for review
- Send the attachment as a secure link that expires and can be revoked
- A record of who opened it, and when
You choose where enforcement happens
Start with the API and see detections on your own mail. Add the gateway when you want enforcement instead of alerts. Or run it in your own environment, so your mail never passes through our cloud.
API
Connects in hours. Nothing changes in how your mail flows.
- An admin approval in Microsoft 365 or Google Workspace
- Harmful mail removed from every inbox after delivery
- Hijacked accounts spotted and locked out
Gateway
Stops threats before they’re delivered, and controls what leaves.
- Works alongside your email platform, one domain at a time
- Outbound data protection and secure-link delivery
- Includes the API connection for internal mail and click checks
Test your people with the same scams we stop
Run simulated phishing campaigns and see who opened, who clicked, who entered credentials and, most important, who reported it. Included in the price, with no separate training contract.
Scenarios
- Executive impersonation and wire-transfer requests
- Invoice fraud and payroll redirects
- Credential harvesting and spear phishing
Results
- Sent, opened, clicked, submitted and reported, per campaign
- A report you can share with leadership
- Schedule a campaign or save it as a draft
More than inbound filtering
Most email security products are built to stop what comes in. Here is what MnemoShare adds.
| Capability | Typical email security | MnemoShare |
|---|---|---|
| Phishing and payment fraud | Caught inbound | Caught inbound, with the named reasons for every detection |
| Sensitive data going out | Often a separate product or module | Included: caught, redacted or held before it leaves |
| Attachments | Sent as-is, and can’t be taken back | Sent as secure links that expire, can be revoked, and show who opened them |
| Where it runs | The vendor’s cloud | Connect by API, run a gateway, or host it in your own environment |
| Phishing simulation | Often sold separately | Included |
| Pricing | Quote only, priced by module | Published, with every capability included |
See what it catches on your own mail. Talk to us about a pilot
Real-world use cases
The changed remit-to address
A billing clerk gets an email from a long-standing supplier with new bank details. The sender domain is one letter off, and the supplier has never asked this before. The message is held, with both reasons shown, before anyone pays.
The loan file sent to the wrong title company
A loan officer attaches a borrower’s full file to a reply. Account and Social Security numbers are detected on the way out, and the file is sent as a secure link instead, so access can be revoked the moment the mistake is spotted.
The compromised colleague
An employee’s account is taken over and starts sending “please review this invoice” links to coworkers. Mail between colleagues is checked too, and the messages are pulled from every inbox they reached.
The technical detail
Forward this section to the people who will evaluate the architecture.
Mail handling
- Full SMTP server with Postfix socketmap and content-filter integration
- MIME parsing with attachment extraction before any delivery decision
- Per-domain policy: pass, reject, or rewrite (redact, extract, or both)
Authentication & relay
- SPF, DKIM and DMARC handling; DKIM signing on outbound
- Rate limiting and sender allowlists
- MX resolution and outbound relay with policy enforcement
Detection & deployment
- Three detection tiers: patterns, named-entity recognition and an AI classifier
- Microsoft 365 and Google Workspace by API, or inline gateway
- SaaS or self-hosted on Kubernetes with the same detection stack
Architecture and configuration guides are in the documentation. Certification status is published on the Trust Center.
Frequently asked questions
Do our people have to change how they send email?
No. There is no plug-in, no new app and no training. Senders keep working the way they do today.
Does this replace Microsoft’s or Google’s own filtering?
It works on top of it. The API adds a smarter layer on the mail you already receive; the gateway adds enforcement before delivery and control over what leaves.
Where does our mail go?
Your choice. Use our hosted service, or run MnemoShare in your own environment so your mail never passes through our cloud.
We already have an email security vendor. Now what?
Many teams add MnemoShare beside what they have, for outbound data protection and secure delivery. Others replace their gateway at renewal. We do not offer long-term email archiving; if you need it, it stays where it is today.
Is there a version for smaller organizations?
Yes. MnemoShare Lite brings the same fraud protection, outbound data protection and phishing simulation to organizations with fewer than 750 users, with published per-user pricing.
Will you sign a BAA?
Yes. A HIPAA Business Associate Agreement is available on every plan as an add-on.
Ready to see MnemoShare in action?
Start a free trial, schedule a walkthrough, or dive into the docs.