Disclaimer

Last updated 2 September 2026

InboxGuards does not provide security. It provides alerts and information. It is an alarm on your Microsoft 365 tenant or Google Workspace. It does not stand between you and an attacker, it does not stop anything from happening, and nobody is standing by to act on your behalf. When something looks wrong, you are told. What happens next is your decision.

What InboxGuards actually does

InboxGuards reads your own Microsoft 365 audit log (Office 365 Management Activity API) or Google Workspace admin audit log (Admin SDK Reports API) using read-only access you grant. It looks for patterns commonly associated with account takeover and business email compromise — sign-ins from unexpected locations, mailbox rules that forward or hide mail, delegation changes, app consent grants, and administrative role changes. When it finds one, it creates an alert in your portal and can email the address you nominate.

It also reads, with the same read-only access, basic security configuration and directory information from Microsoft 365 and Google Workspace — which users have multi-factor authentication enabled, whether security defaults are on, guest accounts, and sign-ins your provider itself flagged as risky — and reports that back to you as a posture summary and a monthly scorecard.

Once a day it also checks each user email address in your directory, and each email domain your users have, against two third-party breach-data services (Have I Been Pwned and LeakCheck) and tells you when an address appears in a known leak. It reports the leak's name, date, and the kinds of data exposed — never the leaked values themselves.

Around your email domain it does three further read-only things: if you publish a DMARC record pointing at our reporting mailbox, it reads the aggregate reports other mail providers send and tells you which servers sent mail as your domain and failed authentication; once a week it looks up common misspellings of your domain in public DNS and tells you which are registered and can handle mail; and if you list accounts that are leaving on your Departure Watch, findings about data movement by those accounts are raised to critical. None of these change anything anywhere.

That is the entire service. It reads and it tells you.

What InboxGuards is not

It is not a managed security service, a SOC, a managed detection and response provider, or a monitoring service staffed by people watching your account. No human at Orion CMD LLC reviews your alerts as part of the InboxGuards subscription.

It is not antivirus, spam filtering, email gateway protection, backup, multi-factor authentication, or a replacement for any of them. It does not block sign-ins, quarantine mail, disable accounts, delete rules, or change any setting in your tenant. Its access is read-only by design.

It is not insurance, and it is not a guarantee against loss.

No guarantee of detection

InboxGuards cannot detect everything, and does not promise to. Its findings depend entirely on what Microsoft or Google records in your tenant's audit log, when the provider makes those records available, and whether the activity in question produces a recorded event at all. Attacker techniques change. Audit logging can be disabled, delayed, incomplete, or unavailable for reasons outside our control. Dark-web findings depend on what Have I Been Pwned and LeakCheck have indexed and when; a “clean” address means no known leak in those two sources, not that no leak exists.

An absence of alerts does not mean an absence of compromise. Do not treat a quiet dashboard as proof that nothing has happened.

Posture reports and scorecards are information, not certification

The security posture panel and the monthly scorecard grade are point-in-time snapshots built from what Microsoft or Google reports to us. They can be incomplete, delayed, or blocked by missing permissions or licenses, and they can be out of date the moment a setting changes. A good grade is not a security audit, a certification, proof of compliance, or a promise that you will not be compromised — and a warning we surface (such as users without MFA) does not make us responsible for fixing it. Configuring and securing your tenant remains entirely your responsibility.

Response is your responsibility

Alerts include plain-English suggested steps. Those steps are general guidance, not tailored professional advice, and they may not fit your circumstances. You are responsible for deciding whether and how to act, and for the consequences of acting or not acting.

InboxGuards does not provide tenant remediation. Use an administrator or IT provider that already has your authorization, access, operating context, and appropriate contractual responsibility.

Availability

InboxGuards runs on scheduled checks and depends on Microsoft's or Google's APIs, our hosting provider, and your tenant remaining connected and correctly consented. Service can be interrupted, delayed, or degraded. We do not offer an uptime guarantee, and alerts may be late or missed during an interruption.

Limitation of liability

InboxGuards is provided on an “as is” and “as available” basis, without warranties of any kind, express or implied, to the fullest extent permitted by law. To the fullest extent permitted by law, Orion CMD LLC is not liable for any loss, damage, cost, or expense — including financial loss from fraud, business interruption, lost profits, or data loss — arising from your use of, or reliance on, InboxGuards, whether or not an alert was generated.

Nothing in this disclaimer excludes liability that cannot lawfully be excluded.

Not legal, financial, or compliance advice

InboxGuards and its alerts do not constitute legal, financial, insurance, or regulatory advice, and using it does not by itself satisfy any compliance obligation, insurance requirement, or contractual security commitment you may have. Check with your own advisors.

Questions

InboxGuards is owned and operated by Orion CMD LLC, Omaha, Nebraska. If anything here is unclear, ask before you subscribe — hello@inboxguards.com.

See also our refund policy.

Arm your inbox

Add bounded monitoring to supported audit records.