Pricing
Simple, per-mailbox pricing
Start protecting your team today. No professional services. No MX record changes. Billed monthly, cancel anytime.
Pricing tiers
For small teams deploying their first email security layer. Core phishing detection, Slack and email alerts, 14-day event retention.
- 50 mailboxes
- Spear phishing + BEC detection
- URL sandboxing
- Slack and email alert routing
- 14-day event log retention
- M365 and Google Workspace connection
- Community support
For security-aware teams handling phishing operationally. Full threat library, analyst triage queue, SIEM integration, 90-day retention.
- 250 mailboxes
- Full threat library (spear phishing, BEC, attachment malware, URL sandboxing, social engineering)
- Analyst triage queue with confidence scores
- Splunk / Elastic SIEM forwarding
- PagerDuty on-call routing
- 90-day event log retention
- Weekly threat digest report
- Email support (next business day)
For organizations with formal security programs. Multi-tenant, SSO, compliance documentation, dedicated onboarding.
- Unlimited mailboxes and domains
- SSO (Okta / Azure AD / Google Workspace)
- Multi-tenant management
- API access for custom integrations
- Custom retention (1 year+)
- Compliance documentation (SOC 2 controls notes, NIST SP 800-53 alignment)
- Dedicated customer success manager
- SLA-backed detection latency
Feature comparison
| Feature | Starter | Growth | Enterprise |
|---|---|---|---|
| Mailboxes | Up to 50 | Up to 250 | Unlimited |
| Email platforms | ✓ M365 + GWS | ✓ M365 + GWS | ✓ M365 + GWS |
| Spear phishing + BEC detection | ✓ | ✓ | ✓ |
| URL sandboxing | ✓ | ✓ | ✓ |
| Attachment malware sandbox | — | ✓ | ✓ |
| Social engineering LLM analysis | — | ✓ | ✓ |
| Analyst triage queue | — | ✓ | ✓ |
| SIEM forwarding (Splunk / Elastic) | — | ✓ | ✓ |
| PagerDuty on-call routing | — | ✓ | ✓ |
| Event log retention | 14 days | 90 days | 1 year+ |
| Weekly threat digest | — | ✓ | ✓ |
| REST API + Webhooks | — | ✓ | ✓ |
| SSO (Okta / Azure AD) | — | — | ✓ |
| Multi-tenant management | — | — | ✓ |
| Compliance documentation package | — | — | ✓ |
| Dedicated customer success manager | — | — | ✓ |
| Support | Community | Email (NBD) | Priority SLA |
Frequently asked questions
No. Phishaver connects to your email platform via read-only OAuth API access (Microsoft Graph API Mail.Read scope for M365; gmail.readonly for Google Workspace). There are no MX record changes, no mail forwarding rules, and no changes to your email delivery path. This means there is zero risk of mail delivery disruption during setup.
No. Phishaver is additive to M365 Defender, not a replacement. It specifically covers the targeted attack gap that M365 Defender's rule-based and reputation-based filters leave open: spear phishing from fresh domains, BEC from lookalike addresses, and LLM-crafted social engineering with no known signature. Both products operate independently and complement each other.
Email body content is analyzed in-memory during the detection pipeline. Only threat event metadata is retained (sender, subject snippet, threat type, confidence score, detection evidence) for the configured retention window (14 days for Starter, 90 days for Growth, configurable for Enterprise). Raw email content is not stored beyond the analysis window.
Setup completes in under 5 minutes for most organizations. You authorize Phishaver via your Microsoft 365 or Google Workspace admin console using standard OAuth. No professional services engagement required. First threat analysis results appear within minutes of connecting. For Enterprise customers requiring SSO and SIEM configuration, allow up to 30 minutes.
Phishaver is built with SOC 2 Type II controls in mind — compliance documentation is available to Enterprise prospects on request. This includes controls notes, not a certification claim. NIST SP 800-53 IA-4 and CIS Controls 9 alignment notes are also available on request for Enterprise customers. ISO 27001 information security controls alignment notes are available on request. None of these represent Phishaver holding formal certification — they document how our controls are designed to support compliance with these frameworks.
No MX changes required
Start your first month today.
Connect to M365 or Google Workspace via OAuth. No setup fee, no professional services. Cancel anytime.