EVEMISSTechnology
All products
Engineering Preview · MVP Enterprise email risk assistant

MailGuard

See risky email before it becomes a costly decision.

MailGuard brings message intent, sender identity, relationship history, policy, and human review into one evidence-backed risk workflow for the teams that handle business-critical email.

The engineering package and local evidence workflow are complete. Authorized Microsoft 365, Azure, PostgreSQL, and representative-data staging remain in progress.

MailGuard screening enterprise email with identity context, risk indicators, and human review

Context-rich

Combines message meaning with sender, domain, authentication, history, and relationship signals.

Reviewable

Explains why a message is risky and routes uncertain or consequential cases to a person.

Evidence-backed

Keeps inputs, signals, policy versions, decisions, and review outcomes connected.

Why it matters

Modern email fraud often looks like ordinary business.

A polished payment request can pass keyword filters. A familiar display name can hide a new domain. The useful question is not only “Is this spam?” but “Does this request fit who sent it, how they normally work, and what the organization allows?”

Identity ambiguity

Display names, lookalike domains, forwarding, and compromised accounts blur who is really asking.

Business context

Invoice changes, urgent transfers, credential requests, and secrecy cues depend on role and history.

Alert fatigue

A security warning without evidence or a review path simply creates another queue people learn to ignore.

Product capabilities

Risk analysis that connects content, identity, and context.

MailGuard is structured as a decision-support system: it gathers signals, produces an inspectable risk assessment, and preserves human control where consequences are high.

01

Semantic intent analysis

Detects payment, credential, secrecy, urgency, impersonation, and unusual-request patterns in context.

02

Sender & domain signals

Evaluates authentication results, address relationships, domain age inputs, reply paths, and header anomalies.

03

Relationship context

Uses approved communication history and trust-graph signals to identify deviations from normal behavior.

04

Risk scoring & reasons

Produces a calibrated score with concrete contributing signals instead of a black-box label.

05

Human review workflow

Routes cases by risk, records analyst decisions, and supports correction and escalation.

06

Audit-ready evidence

Packages source references, policy versions, decisions, review actions, and integrity hashes.

From input to outcome

From incoming message to a reviewable decision.

MailGuard keeps raw email, derived signals, policy, and human judgment separated but traceably linked so a team can understand both the result and its origin.

  1. 1

    Ingest safely

    Receive message and MIME data through an authorized, least-privilege connector.

  2. 2

    Extract signals

    Separate headers, links, attachments, language, requested action, identity, and authentication evidence.

  3. 3

    Add context

    Compare the request with approved history, relationship patterns, roles, policies, and known exceptions.

  4. 4

    Assess risk

    Generate a reasoned risk profile, preserve uncertainty, and select the required control.

  5. 5

    Review and learn

    Warn, hold, escalate, or allow according to policy; record human decisions for future calibration.

MailGuard workflow from incoming email through semantic analysis, identity verification, relationship context, risk score, and analyst decision

Shared governance core

Built on the EVEMISS Enterprise Communication Agent Core.

MailGuard shares identity, policy, model, tool, ledger, and observability foundations with VoiceDesk while keeping its own mail, trust, and analyst workflows.

Identity & tenant boundaries

Separate organizations, mailboxes, roles, cases, and data access.

Policy & risk gates

Map a risk assessment to warning, review, hold, or allowed actions.

Connector & secret control

Use least-privilege mailbox access and keep credentials outside model context.

Event ledger & observability

Preserve the chain from source and signals through policy, review, and result.

Where to start

Focus first on high-consequence business mail.

Payment change requests

Flag altered bank details, new beneficiaries, unusual urgency, and identity inconsistencies.

Executive impersonation

Connect display-name and writing cues with domain, relationship, and requested-action context.

Procurement & invoice fraud

Compare vendor identity, history, documents, and process rules before finance acts.

Credential & access requests

Surface links, authentication signals, unusual sign-in language, and policy exceptions for review.

Engineering status

A complete engineering package with external staging still open.

The current release proves the local runtime, migration, evidence, staging-runner, and calibration-gate behavior. It does not claim production detection performance or a live enterprise deployment.

Verified in the current engineering package

  • Python compilation and 43 automated tests passed in the packaged local validation.
  • Alembic upgrade, schema check, downgrade, and re-upgrade paths completed successfully.
  • Evidence redaction, SHA-256 manifest verification, deterministic calibration, and tamper-detection paths are covered.
  • The eight-record demo dataset is correctly blocked by release gates rather than presented as performance evidence.

Still requires authorized external validation

  • A Microsoft 365 staging tenant, Exchange Application RBAC, public Graph webhook, and real subscription lifecycle.
  • Authorized mailbox MIME retrieval, PostgreSQL RLS runtime testing, Azure Managed Identity, and Key Vault.
  • OTLP backend reception and end-to-end operational monitoring in a controlled environment.
  • A representative labeled enterprise dataset, approved thresholds, live analyst workflow, and production operating controls.

Designed boundaries

Decision support, not invisible surveillance or automatic accusation.

MailGuard is designed to show evidence, preserve uncertainty, minimize data, and keep accountable people in control of consequential actions.

Explain the signal

Every warning should identify the facts that contributed to it.

Minimize the data

Only authorized, purpose-bound content and context should enter analysis.

Keep humans responsible

High-impact holds, investigations, and business decisions require defined review.

Calibrate before release

Small demos and synthetic examples validate plumbing, not enterprise detection quality.

MailGuard · EVEMISS Technology

Bring one mail workflow and its real review rules.

We are preparing controlled pilots for teams that can define a high-consequence email scenario, authorize a staging environment, and evaluate decisions with security and business owners together.

Discuss a pilot →
From the same product line VoiceDesk → AI phone task assistance for structured service workflows, built on the same governed communication core.