Pricing

Simple, per-mailbox pricing

Start protecting your team today. No professional services. No MX record changes. Billed monthly, cancel anytime.

Pricing tiers

Starter
$149/mo
Up to 50 mailboxes

For small teams deploying their first email security layer. Core phishing detection, Slack and email alerts, 14-day event retention.

  • 50 mailboxes
  • Spear phishing + BEC detection
  • URL sandboxing
  • Slack and email alert routing
  • 14-day event log retention
  • M365 and Google Workspace connection
  • Community support
Get started
Enterprise
Custom
Unlimited mailboxes and domains

For organizations with formal security programs. Multi-tenant, SSO, compliance documentation, dedicated onboarding.

  • Unlimited mailboxes and domains
  • SSO (Okta / Azure AD / Google Workspace)
  • Multi-tenant management
  • API access for custom integrations
  • Custom retention (1 year+)
  • Compliance documentation (SOC 2 controls notes, NIST SP 800-53 alignment)
  • Dedicated customer success manager
  • SLA-backed detection latency
Talk to sales

Feature comparison

Feature Starter Growth Enterprise
MailboxesUp to 50Unlimited
Email platforms✓ M365 + GWS✓ M365 + GWS
Spear phishing + BEC detection
URL sandboxing
Attachment malware sandbox
Social engineering LLM analysis
Analyst triage queue
SIEM forwarding (Splunk / Elastic)
PagerDuty on-call routing
Event log retention14 days1 year+
Weekly threat digest
REST API + Webhooks
SSO (Okta / Azure AD)
Multi-tenant management
Compliance documentation package
Dedicated customer success manager
SupportCommunityPriority SLA

Frequently asked questions

No. Phishaver connects to your email platform via read-only OAuth API access (Microsoft Graph API Mail.Read scope for M365; gmail.readonly for Google Workspace). There are no MX record changes, no mail forwarding rules, and no changes to your email delivery path. This means there is zero risk of mail delivery disruption during setup.

No. Phishaver is additive to M365 Defender, not a replacement. It specifically covers the targeted attack gap that M365 Defender's rule-based and reputation-based filters leave open: spear phishing from fresh domains, BEC from lookalike addresses, and LLM-crafted social engineering with no known signature. Both products operate independently and complement each other.

Email body content is analyzed in-memory during the detection pipeline. Only threat event metadata is retained (sender, subject snippet, threat type, confidence score, detection evidence) for the configured retention window (14 days for Starter, 90 days for Growth, configurable for Enterprise). Raw email content is not stored beyond the analysis window.

Setup completes in under 5 minutes for most organizations. You authorize Phishaver via your Microsoft 365 or Google Workspace admin console using standard OAuth. No professional services engagement required. First threat analysis results appear within minutes of connecting. For Enterprise customers requiring SSO and SIEM configuration, allow up to 30 minutes.

Phishaver is built with SOC 2 Type II controls in mind — compliance documentation is available to Enterprise prospects on request. This includes controls notes, not a certification claim. NIST SP 800-53 IA-4 and CIS Controls 9 alignment notes are also available on request for Enterprise customers. ISO 27001 information security controls alignment notes are available on request. None of these represent Phishaver holding formal certification — they document how our controls are designed to support compliance with these frameworks.

No MX changes required

Start your first month today.

Connect to M365 or Google Workspace via OAuth. No setup fee, no professional services. Cancel anytime.