Listing Thumbnail

    Sublime Email Security for Security Hub Extended

     Info
    Deployed on AWS
    Complete email security platform that stops advanced attacks, automates abuse mailbox triage, and adapts defenses quickly with AI agents. Our agentic platform protects, adapts, and responds in real-time, eliminating vendor bottlenecks.
    4.8

    Overview

    By stopping more attacks and reducing false positives, Sublime delivers a superior autonomous AI experience that requires less work. For advanced teams, the platform is fully extensible, allowing you to author your own detections and hunt for threats with a level of precision that one-size-fits-all solutions can't. Block sophisticated threats (BEC, novel phishing, QR-based phishing) and reduce the false positives that waste time and disrupt workflows. Sublime's tailored protections deliver a demonstrably higher catch rate, validated by the world's most demanding security teams. Protect Microsoft 365 and Google Workspace accounts with no MX changes. Deploy in Sublime Cloud or self-host on AWS.

    Highlights

    • stops advanced attacks, automates abuse mailbox triage, adapts defenses quickly with AI agents
    • Coverage tailored to your environment, Agentic automation

    Details

    Categories

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Sublime Email Security for Security Hub Extended

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (2)

     Info
    Dimension
    Description
    Cost/unit
    250 - 2,499 Mailboxes
    Monthly Price per Mailbox for 250 - 2,499 Mailboxes
    $8.75
    2,500 + Mailboxes
    Monthly Price per Mailbox for 2,500 + Mailboxes
    $6.25

    Vendor refund policy

    No Refunds at this time

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.8
    32 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    91%
    9%
    0%
    0%
    0%
    0 AWS reviews
    |
    32 external reviews
    External reviews are from G2 .
    Information Technology and Services

    Tailored, Transparent Email Security That Delivers Peace of Mind

    Reviewed on Sep 17, 2026
    Review provided by G2
    What do you like best about the product?
    I've been using Sublime's agentic platform to safeguard my emails, and it's been quite impressive. They genuinely provide the transparency and automation needed to tackle advanced threats without all the hassle. This isn't just another generic security solution. It's truly tailored to the specific threats my organization encounters, cutting down on false positives and giving me peace of mind. Their AI agents work seamlessly, giving my team way more flexibility and efficiency. Definitely a trusted and proactive solution!
    What do you dislike about the product?
    Nothing so far has pushed me away from the platform
    What problems is the product solving and how is that benefiting you?
    Email security with automation and high fidelity detections and response
    Mike M.

    Fantastic Architecture and Easy UI, Backed by a Super Responsive Team

    Reviewed on Sep 11, 2026
    Review provided by G2
    What do you like best about the product?
    The architecture is fantastic, the rules engine and how the platform is laid out is really solid. UI is easy to use. Can't wait for the MCP interface to make it even better! The sales and services team are fantastic, super responsive and really knowledgeable.
    What do you dislike about the product?
    Their Graymail feature is not full featured yet. They don't have an MCP interface yet.
    What problems is the product solving and how is that benefiting you?
    Layered email security.
    Computer Software

    Transparent, Editable Detection Rules with Fast Onboarding and Strong Phishing Coverage

    Reviewed on Sep 09, 2026
    Review provided by G2
    What do you like best about the product?
    The detection logic is fully transparent and editable, and that's the thing I'd point to first. Every rule is human-readable, so when we see a new phishing pattern we can fork an existing rule, tune the conditions, and have it live the same day instead of filing a vendor ticket and waiting a release cycle. The rules live as code, which means we version control them and code review them like any other engineering work.

    Onboarding was genuinely fast. It connects to our mail tenant over API rather than sitting inline, so there were no MX changes, no mail flow risk, and no added delivery latency. We were reviewing real detections within days of signing, and we could run in observation mode first to see what it would have caught before letting it take action on anything.

    The verdict detail is what changed our day-to-day workflow the most. Instead of a black-box risk score, we get the specific signals behind a detection along with full message and attachment analysis, so triage on a reported message takes a couple of minutes rather than a manual header-and-link investigation. Being able to query historical mail with a real query language means email is now something we can actually hunt across, which we didn't have before.

    Integrations have held up well. The API is complete enough that we pipe detections into our own SIEM and automation rather than living in one more console.

    Detection quality on business email compromise, vendor and executive impersonation, credential phishing, and QR-code lures has been consistently strong. Support is responsive and technically credible, with direct access to people who know the product instead of a tiered queue.
    What do you dislike about the product?
    1. Built-in reporting and dashboards are the weakest part of the product. For the metrics leadership asks for, we end up exporting data into our own tooling rather than using what ships in the console.
    What problems is the product solving and how is that benefiting you?
    The core problem it solves is that our previous email controls caught commodity spam and known-bad indicators but missed the attacks that actually cause damage: business email compromise, vendor and executive impersonation, payment fraud attempts, and credential phishing that carries no malware and no known-bad URL. Those messages were landing in inboxes, and we were finding out about them from user reports rather than from a detection.

    The second problem was that we had no way to act on what we knew. With a traditional gateway, our own threat intelligence and the patterns we saw in our own environment couldn't be turned into a control without opening a vendor ticket. Sublime closed that gap. When we see something new, we write or tune a rule ourselves and it's protecting the whole org that day.

    The third was visibility. Email used to be the one major surface our detection team couldn't investigate. We had no way to search historical messages, so questions like "who else received this" or "has this sender pattern shown up before" took hours of manual work or went unanswered. Now that's a query.

    The benefits have been concrete. Phishing triage that used to mean manually pulling headers, unpacking attachments, and checking links now takes a couple of minutes per message because the analysis is already done and the reasoning is visible. Fewer malicious messages reach users, so we spend less time on post-delivery cleanup and searching for who clicked. Our detection engineers can own email coverage directly instead of routing everything through IT or the vendor. And because it deploys over API with no mail flow changes, we got all of that without a migration project or any risk to mail delivery.
    Information Technology and Services

    Excellent Tool with Strong Admin Functionality and Dedicated Support

    Reviewed on Sep 04, 2026
    Review provided by G2
    What do you like best about the product?
    Excellent tool, efficacy right on par with Abnormal. More functionality from administrative perspective.
    What do you dislike about the product?
    I have not had any issues with the Sublime platform or their professional services! Continued support with dedicated engineer has been excellent.
    What problems is the product solving and how is that benefiting you?
    Much better efficacy than our previous solution, drastic reduction of phishing emails making it through to end users. The graymail feature is also cleaning up inboxes from excessive marketing emails.
    Kyle P.

    Crowdsourced Detection Rules That Build Herd Immunity Fast

    Reviewed on Aug 13, 2026
    Review provided by G2
    What do you like best about the product?
    I love the idea of crowdsourcing detection rules. You can take a new, novel phishing campaign and quickly turn it into a detection rule, backcheck it, and share it with the community, creating a kind of herd immunity, in a matter of minutes.
    What do you dislike about the product?
    I genuinely can’t think of anything I dislike.
    What problems is the product solving and how is that benefiting you?
    With many of the large email security vendors, analysts and engineers are largely at the mercy of the vendor when it comes to detection logic. You get whatever rules and detections they provide, with limited ability to really tune them to your environment.

    Sublime completely changes that. As an analyst or engineer, I can build custom detection rules around virtually any property or behavior observed in an email. Those rules aren't limited to stopping future messages either. I can take something I just discovered, write a detection for it, and immediately look back across 30, 60, 90+ days of email to determine whether it ever reached anyone in the organization. If it did, I can remediate it, while also protecting the environment from anything matching that detection going forward.

    The addition of AI-assisted and agentic workflows has made this even more powerful. Building and refining custom detections is incredibly fast, without taking away the transparency or control that makes Sublime so useful in the first place.

    I've also helped onboard Sublime at multiple companies, and deployment is refreshingly simple. You can connect an environment and start getting meaningful visibility and protection in a matter of minutes rather than turning implementation into a weeks-long professional services project.

    That combination of visibility, control, rapid response, and ease of deployment is what makes Sublime stand out for me.
    View all reviews