Disrupt 2026Meet Himaya at TechCrunch Disrupt 2026. October 13–15 · Moscone West, San FranciscoBook time with us

Agentic email security that investigates like a team of senior analysts

Himaya's agents read every message for intent in any language, with specialized training in Arabic and English. They check senders, links and files against threat intelligence, detonate attachments in a sandbox, and act on BEC, phishing, invoice fraud, account takeover and other attacks.

See it work

Every message investigated, every verdict explained

Watch Himaya trace a message from delivery to action: reputation, content, relationship graph and sandbox, scored and explained, with the compliance controls it satisfies.

Message trace · investigationQuarantined

Message metadata

Subject
Q4 contract for signature
Sender
invoices@northwind-billing.co
Recipient
maya@northwind.io
Attachment
Q4-contract.docm
SPFFailDKIMNoneDMARCFail

Email flow

  1. Email delivered18:51:30Delivered to maya@northwind.io. SPF fail · DKIM none · DMARC fail.
  2. Sender reputation check18:51:31northwind-billing.co was first seen 3 days ago and has never emailed this recipient.
  3. Content analysis18:51:32Invoice urgency and a request to enable editing. Content score 72/100.
  4. Relationship graph18:51:33No prior relationship with the sender. The domain imitates a known supplier. Graph score 81/100.
  5. Sandbox detonation18:51:34Q4-contract.docm ran a macro that called out to an unknown host.
  6. AI classification18:51:35Malicious, 94% confidence: macro malware disguised as a supplier contract.
  7. Himaya action18:51:35Quarantined and removed from the inbox. Sender blocked and recipient notified.

Detection scores

  • Reputation88
  • Content72
  • Graph81
  • Sandbox97
Overall risk91

Threat indicators

  • SPF hard fail
  • First-seen sender
  • Lookalike domain
  • Macro-enabled attachment
  • Sandbox network callout
  • Dangerous attachment

Compliance controls triggered

  • SAMA CSF3.3.3
  • NCA ECC2-7-1
  • SOC 2CC7.2
  • ISO 27001A.5.7
  • NIST CSFDE.CM-1
  • DORAArt. 10

Actions

Email quarantinedRemoved from inboxBlock senderMark as false positive
Himaya Intercept

Attachments that never reach the endpoint

Intercept changes how files travel: risky attachments are vaulted and swapped for a secure link, and open only in an isolated viewer. The email itself stays in the inbox.

Inboxmaya@northwind.io

Q4 contract for signature

Vendor Invoices <invoices@example.com>to me · 6:50 PM

Please review and sign the attached contract before Friday.

Himaya

Attachments secured by HimayaFiles open in an isolated secure viewer. Nothing is downloaded to your device.
Q4-contract.docm845 KBOpen in secure viewer
Link expires 3 days after delivery, per your organization's security policy.
Secure viewer · Q4-contract.docmIsolated sandbox · 10 min session
Supply Agreement: Q4

Opened in an isolated desktop. Nothing reached this device.

Vault

  • CapturedBytes copied as the mail arrived
  • HashedSHA-256 · 9f2c…41ab
  • ScannedRisky format: macro-enabled .docm
  • EncryptedVaulted for 30 days

Zero added latency. Delivery is never held.

Himaya InterceptRisky attachments become secure sandbox links
Risky files onlyExecutables, macro documents, scripts, flagged filesAll attachmentsMaximum isolation
Link lifetime 72h1 day10 days max
Require mailbox verificationA one-time code before a file opens
  • VaultAttachments are captured, hashed, scanned, encrypted and stored as mail arrives, with zero added latency.
  • RewriteRisky files, or every file if you choose, are removed from the delivered email and replaced with a secure link card.
  • Secure linkA private link that expires after 72 hours by default (10 days at most), with daily open limits, optional one-time-code verification and revocation.
  • Isolated viewerFiles open in a sandboxed desktop, never on the device. Malicious files are blocked at the link, and admins can release safe originals.
How it works

From message to verdict

  1. Step 1

    Ingest

    New mail is picked up continuously through the Gmail and Microsoft Graph APIs.

  2. Step 2

    Check

    SPF, DKIM and DMARC are read from the real headers. Senders, links, file hashes and IPs are looked up against threat intelligence and IOC feeds.

  3. Step 3

    Reason

    Content intelligence reads intent while the trust graph compares the sender with your organization's history. Reply-To mismatches that signal BEC are scored on their own.

  4. Step 4

    Act

    High-risk mail is moved out of the inbox into quarantine. A second pass re-examines open threats with sandbox results and can raise risk, never quietly lower it.

Capabilities

What Email Security covers

Authentication and reputation

SPF, DKIM and DMARC are parsed from every message. Sender domains, URLs and IPs are checked against commercial and open threat intelligence, and look-alike domains are caught by what their TLS certificates claim to be.

Relationship graph

Every sender and recipient relationship, built from inbound and outbound mail. People your team replies to earn two-way trust; one-way and look-alike senders stand out.

Content intelligence

Reads BEC language, payment redirection, credential harvesting, urgency and executive or brand impersonation in any language, with specialized training in Arabic and English.

URL and attachment analysis

Links are unshortened and checked against threat intelligence. Attachments are hashed and inspected for macro-enabled formats, dangerous extensions and encrypted archives.

Sandbox detonation

Suspicious links and files open in a throwaway container while Himaya watches what they do. A malicious result sends the message straight to quarantine.

Four clear verdicts

Quarantine removes the message and keeps an encrypted copy, spam goes to junk, escalate labels it and notifies the recipient, and dismiss restores reported mail.

VIP protection

Executives, finance leads and other high-value recipients get a stricter threshold before a threat is allowed through.

Employee phish reporting

An Outlook add-in and a Gmail add-on. Reported mail is investigated straight away and restored automatically if it turns out clean.

False-positive controls

Confirmed false positives lower future risk for that sender unless new hard evidence appears. Trusted sign-in and one-time-code mail is not quarantined on wording alone.

How we build it

Designed to be trusted

  • Every verdict is explained. Message Trace shows the score breakdown, evidence and reasoning behind each decision, stage by stage.
  • Hard evidence wins. A malicious sandbox result or known-threat history overrides softer signals, and authenticated mail from a trusted sender needs hard indicators before it is quarantined.
  • AI adjusts, it never overrides. Deterministic checks run first, models weigh the uncertain cases within set bounds, and fallbacks keep triage running if a model is unavailable.
  • Mistakes get corrected. Confirmed false positives shape future scoring for that sender unless new hard evidence appears.

Frequently asked questions

Do we need to change our MX records?

No. Himaya connects through the Gmail and Microsoft Graph APIs and acts on mail in the mailbox, so your mail routing stays as it is.

What happens to a quarantined message?

It is moved out of the inbox. Admins can release it if it was a false positive or permanently block the sender.

Can employees report suspicious mail?

Yes. Himaya provides an Outlook add-in and a Gmail add-on. A reported message is quarantined immediately and then investigated.

Does it catch Arabic-language phishing?

Yes. Content intelligence analyzes intent, impersonation and urgency in any language, with specialized training in Arabic and English.

See Himaya Email Security in your workspace

Book a walkthrough to learn more.