MailGuard
See risky email before it becomes a costly decision.
MailGuard brings message intent, sender identity, relationship history, policy, and human review into one evidence-backed risk workflow for the teams that handle business-critical email.
The engineering package and local evidence workflow are complete. Authorized Microsoft 365, Azure, PostgreSQL, and representative-data staging remain in progress.
Context-rich
Combines message meaning with sender, domain, authentication, history, and relationship signals.
Reviewable
Explains why a message is risky and routes uncertain or consequential cases to a person.
Evidence-backed
Keeps inputs, signals, policy versions, decisions, and review outcomes connected.
Why it matters
Modern email fraud often looks like ordinary business.
A polished payment request can pass keyword filters. A familiar display name can hide a new domain. The useful question is not only “Is this spam?” but “Does this request fit who sent it, how they normally work, and what the organization allows?”
Identity ambiguity
Display names, lookalike domains, forwarding, and compromised accounts blur who is really asking.
Business context
Invoice changes, urgent transfers, credential requests, and secrecy cues depend on role and history.
Alert fatigue
A security warning without evidence or a review path simply creates another queue people learn to ignore.
Product capabilities
Risk analysis that connects content, identity, and context.
MailGuard is structured as a decision-support system: it gathers signals, produces an inspectable risk assessment, and preserves human control where consequences are high.
Semantic intent analysis
Detects payment, credential, secrecy, urgency, impersonation, and unusual-request patterns in context.
Sender & domain signals
Evaluates authentication results, address relationships, domain age inputs, reply paths, and header anomalies.
Relationship context
Uses approved communication history and trust-graph signals to identify deviations from normal behavior.
Risk scoring & reasons
Produces a calibrated score with concrete contributing signals instead of a black-box label.
Human review workflow
Routes cases by risk, records analyst decisions, and supports correction and escalation.
Audit-ready evidence
Packages source references, policy versions, decisions, review actions, and integrity hashes.
From input to outcome
From incoming message to a reviewable decision.
MailGuard keeps raw email, derived signals, policy, and human judgment separated but traceably linked so a team can understand both the result and its origin.
- 1
Ingest safely
Receive message and MIME data through an authorized, least-privilege connector.
- 2
Extract signals
Separate headers, links, attachments, language, requested action, identity, and authentication evidence.
- 3
Add context
Compare the request with approved history, relationship patterns, roles, policies, and known exceptions.
- 4
Assess risk
Generate a reasoned risk profile, preserve uncertainty, and select the required control.
- 5
Review and learn
Warn, hold, escalate, or allow according to policy; record human decisions for future calibration.
Shared governance core
Built on the EVEMISS Enterprise Communication Agent Core.
MailGuard shares identity, policy, model, tool, ledger, and observability foundations with VoiceDesk while keeping its own mail, trust, and analyst workflows.
Identity & tenant boundaries
Separate organizations, mailboxes, roles, cases, and data access.
Policy & risk gates
Map a risk assessment to warning, review, hold, or allowed actions.
Connector & secret control
Use least-privilege mailbox access and keep credentials outside model context.
Event ledger & observability
Preserve the chain from source and signals through policy, review, and result.
Where to start
Focus first on high-consequence business mail.
Payment change requests
Flag altered bank details, new beneficiaries, unusual urgency, and identity inconsistencies.
Executive impersonation
Connect display-name and writing cues with domain, relationship, and requested-action context.
Procurement & invoice fraud
Compare vendor identity, history, documents, and process rules before finance acts.
Credential & access requests
Surface links, authentication signals, unusual sign-in language, and policy exceptions for review.
Engineering status
A complete engineering package with external staging still open.
The current release proves the local runtime, migration, evidence, staging-runner, and calibration-gate behavior. It does not claim production detection performance or a live enterprise deployment.
✓ Verified in the current engineering package
- Python compilation and 43 automated tests passed in the packaged local validation.
- Alembic upgrade, schema check, downgrade, and re-upgrade paths completed successfully.
- Evidence redaction, SHA-256 manifest verification, deterministic calibration, and tamper-detection paths are covered.
- The eight-record demo dataset is correctly blocked by release gates rather than presented as performance evidence.
→ Still requires authorized external validation
- A Microsoft 365 staging tenant, Exchange Application RBAC, public Graph webhook, and real subscription lifecycle.
- Authorized mailbox MIME retrieval, PostgreSQL RLS runtime testing, Azure Managed Identity, and Key Vault.
- OTLP backend reception and end-to-end operational monitoring in a controlled environment.
- A representative labeled enterprise dataset, approved thresholds, live analyst workflow, and production operating controls.
Designed boundaries
Decision support, not invisible surveillance or automatic accusation.
MailGuard is designed to show evidence, preserve uncertainty, minimize data, and keep accountable people in control of consequential actions.
Explain the signal
Every warning should identify the facts that contributed to it.
Minimize the data
Only authorized, purpose-bound content and context should enter analysis.
Keep humans responsible
High-impact holds, investigations, and business decisions require defined review.
Calibrate before release
Small demos and synthetic examples validate plumbing, not enterprise detection quality.
MailGuard · EVEMISS Technology
Bring one mail workflow and its real review rules.
We are preparing controlled pilots for teams that can define a high-consequence email scenario, authorize a staging environment, and evaluate decisions with security and business owners together.
Discuss a pilot →