01 An alarm on your business inbox
Compromised mailboxes don't announce themselves. InboxGuards checks Google Workspace and Microsoft 365 audit records about every 5 minutes and raises the alarm when configured account-takeover signals appear. Provider ingestion can add delay. It is an alarm, not a staffed SOC or duty team, and it does not guarantee warning before money moves.
$4 per user / mo · 30-day guarantee · no credit card to start
demo panel · does not page anyone
The problem
An attacker who owns one mailbox doesn't need malware. They read the thread, wait for the wire, and rewrite the account number. The FBI's IC3 has logged tens of billions in losses to business email compromise — and the email that carries it is real, sent from a real, trusted account.
The signal is in the audit log: a new device, a forwarding rule, an inbox rule on Microsoft 365, a login from a city the user has never been to. Gmail user filters are not in those records. Alone, each signal is noise. Together, they are the attack. Most businesses never look at those logs — and by the time someone does, the wire has settled.
The alarm
Representative feed · reconstruction using InboxGuards' detection vocabulary
Signal set
Attackers quietly forward mail to a burner address or, on Microsoft 365, hide replies with inbox rules. Gmail user filters are not in the Google audit records InboxGuards reads — review those in Gmail settings. We flag forwarding on both providers and inbox-rule changes on Microsoft 365.
A login that can't be the user is the first tell of a takeover. We correlate device, IP, and geography against the user's history — even when MFA passed.
Privilege escalation is the point of no return. We alert on role grants, delegated mailbox access, and API client grants.
Two logins, two continents, twenty minutes apart — no human does this. Bulk exports and mass downloads are how the mailbox's value leaves the building.
We cross-check compromised-credential feeds for your domain and watch DMARC reports so spoofing your domain stays hard.
The math
Arming sequence
OAuth-based connection to Google Workspace or Microsoft 365. No service accounts, no mailbox access, no password storage. We read the audit logs the provider already keeps.
Turn on quiet hours so nights stay quiet. Alerts go to the address you named, and to Slack if you connect it. You own the response. There is no duty team, no SOC, and nobody on a desk watching your tenant.
Every ~5 minutes we check and write a verdict. A confirmed detection emails your team after that check finishes — minutes plus provider delay, not instantly. Optional hands-on remediation is available as a separately authorized $199 service.
“We assumed the bank would catch it. They didn't. The invoice was real — it came from a real mailbox we all trusted.”— a CFO whose firm lost a five-figure wire · paraphrased from a public BEC account
Pricing
$4 per user per month, or $40 per user per year (2 months free). Flat, per-mailbox, both platforms. No setup fee. Cancel anytime under the subscription terms. The average BEC wire is measured in tens of thousands — the alarm that catches it costs less than a sandwich per mailbox per month.