# Abnormal

*/Startups/Abnormal*

## Startup Overview

This security platform integrates directly into cloud email tenants via API to map known good communication patterns and construct deep identity graphs. It automatically intercepts and quarantines advanced threats, including vendor impersonation, financial fraud, and lateral phishing, before they reach employee inboxes.

Enterprise security teams use this system to stop sophisticated email attacks that exploit human trust rather than software vulnerabilities. The platform eliminates the operational burden of managing complex routing rules, allowing defenders to instantly neutralize compromised account activity and targeted social engineering attempts.

Unlike traditional secure email gateways from Proofpoint or Mimecast that rely on legacy MX record routing, this API-native architecture deploys instantly from within the cloud tenant. By combining this internal integration with behavioral profiling, the system catches the payload-less identity attacks and lateral phishing campaigns that perimeter-based gateways and native Microsoft defenses consistently miss.

## Startup Founding Hypothesis

**Approach**: that profiles baseline identity behaviors to block anomalous requests
**Competitors**:
- [Proofpoint](/Competitors/Proofpoint)
- [Mimecast](/Competitors/Mimecast)
- [Microsoft Defender](/Competitors/Microsoft_Defender)
- [Legacy SEGs](/Competitors/Legacy_SEGs)
**Differentiator2x2**: deployed via cloud API rather than MX record routing, with behavioral-baseline precision

## Startup Solution Coordinate

**Solution**: [Behavioral Email Defense](/Agents/Behavioral_Email_Defense)

## Startup Position2x2

```mermaid
quadrantChart
  title Enterprise Email Security
  x-axis Legacy MX Routing --> API-Native Deployment
  y-axis Perimeter & Payload Scanning --> Behavioral Identity Profiling
  quadrant-1 Contextual Cloud Security
  quadrant-2 Behavioral Wrappers
  quadrant-3 Legacy Gateways
  quadrant-4 Basic Cloud Filters
  Abnormal: [0.88, 0.92]
  Microsoft Defender: [0.85, 0.45]
  Proofpoint: [0.25, 0.60]
  Mimecast: [0.20, 0.50]
  Secure Email Gateways: [0.15, 0.30]
```

## Startup Customer Journey

```mermaid
flowchart LR; A[CISO Prospect] --> B[Proof of Value Instance]; B --> C[Anomaly Detection Engine]; C --> D[Enterprise Tenant]; D --> E[SIEM Integration]; E --> F[Industry Peer];
```

## Startup Proof Points

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Pilot Goals**:
- 14-day parallel deployment alongside an existing SEG for a 1,000-mailbox tenant, aiming to prove the detection of advanced anomalies missed by the existing perimeter defense.
- 30-day proof of value focused on IT overhead, aiming to demonstrate a 90% drop in false-positive email alerts requiring manual administrative review.
- 7-day retrospective analysis using historical mailbox metadata, aiming to instantly map the organization's communication graph and identify hidden compromised vendor accounts.
**Target Metrics**:
- Target: 99% block rate on socially engineered attacks bypassing native Microsoft/Google defenses.
- Target: <15 minute full cloud API deployment time requiring zero MX record changes.
- Target: 90% reduction in IT administration hours spent reviewing false-positive email quarantines.
- Target: 100% detection rate of internal account takeover (ATO) attempts via behavioral metadata profiling.
**Target Case Studies**:
- Targeting mid-sized financial services firms (500–2,500 mailboxes) where the CISO eliminates vendor fraud and BEC attacks that slip past traditional SEGs, without adding quarantine management overhead.
- Targeting large healthcare providers where the IT Security Director secures internal lateral communication to prevent account takeover (ATO), deploying the API-based solution in under 15 minutes.
- Targeting decentralized manufacturing enterprises where the VP of IT relies on automatically recalculated communication baselines to stop invoice fraud across dynamic supply chains, eliminating manual rule tuning.
**Testimonial Targets**:
- CISO: Relief that the API-based integration catches sophisticated BEC attacks and vendor fraud that their legacy Secure Email Gateway (SEG) completely missed.
- IT Security Admin: Excitement over the drastic reduction in time spent managing quarantine tickets, made possible by the identity engine's dynamic behavioral baselines.
- Chief Risk Officer: Confidence provided by the financial guarantee backing the behavioral baseline detection against financial losses from BEC attacks.

## Startup Top Risks

**Risks**:
- Severity: existential · Description: Cloud email providers like Microsoft or Google restrict API access or implement rate limits that prevent real-time message quarantine. · Mitigation Status: unmitigated
- Severity: high · Description: Microsoft Defender significantly upgrades its native behavioral analysis capabilities, rendering a third-party add-on redundant for enterprise security budgets. · Mitigation Status: in-progress
- Severity: high · Description: The behavioral profiling engine generates false positives on critical executive or vendor communications, forcing security teams to disable automatic quarantine. · Mitigation Status: in-progress
- Severity: moderate · Description: Legacy secure email gateways like Proofpoint release their own API-native deployments, eroding the instant-deployment differentiator. · Mitigation Status: unmitigated

## Startup Competitors

- [Proofpoint](/Competitors/Proofpoint) — Incumbent Gateway
- [Mimecast](/Competitors/Mimecast) — Incumbent Gateway
- [Secure Email Gateways](/Competitors/Secure_Email_Gateways) — Status Quo
- [Microsoft Defender](/Competitors/Microsoft_Defender) — Bundled Platform Security
- [Avanan](/Competitors/Avanan) — API-Based Competitor
- [Tessian](/Competitors/Tessian) — Behavioral Competitor

## Startup Business Definition

**Name**: Stop Advanced Email Attacks for Enterprise Security Teams
**Layers**:
- **Thesis**: Headless SaaS
- **Template**: api-business
- **Buyer Chain**: B2B → CISO/VP Security → Enterprise Security Operations → Employee Inboxes
**Vision**:
- **Vision**: Enterprise Security Teams no longer carry the cost of stop advanced email attacks; the work runs reliably in the background, and the team that used to do it is free for higher-leverage work in enterprise security team.
- **Mission**: ship the API surface that solves stop advanced email attacks for Enterprise Security Teams.
**Industry**: Enterprise Security Team
**Coord Href**: /Startups/Abnormal
**Processes**:
- Name: Customer Intake · Owner: startup-cs-onboarding · Category: core · Description: Capture a new customer's signup or sales hand-off and route them into onboarding. · Added By Layer: operate-baseline
- Name: API Request Lifecycle · Owner: delivery-platform-engineer · Category: core · Description: Each API call lands, is served, is observed against SLOs. · Added By Layer: thesis
- Name: B2B Sales Cycle · Owner: buyer-chain-b2b-sales-rep · Category: core · Description: From qualified lead to signed contract; the sales rep owns, account management takes over post-close. · Added By Layer: buyer-chain
**Workflows**:
- Name: On New Customer Signup · Description: Event-driven: a new customer signs up → kick off onboarding + record the founding-OKR KR event. · Added By Layer: operate-baseline
- Name: On SLO Breach · Description: API SLO budget breach → escalate to API reliability + capture incident. · Added By Layer: thesis
**Departments**:
- Id: delivery-headless-saas · Code: DEL · Name: Delivery (Headless SaaS — API/Platform) · Description: Delivery primitives for a Headless SaaS Thesis (ADR 0034 §3 + §4 graduation exception). API/platform + DX Positions are Startup-internal pre-graduation because the product IS the software it ships. · Added By Layer: thesis
- Id: startup-operate · Code: OPS-S · Name: Operate (Startup-specific shared services) · Description: Per-Startup operate functions — Customer Success, Marketing, Revenue/Sales, Customer Ops. The Studio default carries portfolio-wide bookkeeping/AP/AR/tax/legal-prep (#239); this overlay adds the Startup-specific operate Positions that have to exist in every operating company. The four-layer specialization (Thesis/Template/spine/Buyer-Chain) then shapes these seats to the Startup's actual shape — additions/overrides happen in those layers, not here. · Added By Layer: operate-baseline
**Description**: An operating company shipping an API/platform that solves stop advanced email attacks for enterprise security teams.
**Founding Okr**:
- **Period**: First 90 days
- **Objective**: Prove the wedge — first enterprise security teams pay for stop advanced email attacks solved.
- **Description**: The founding OKR — every key result is a concept-stage TARGET (no operating history claimed), aimed at validating the Founding Hypothesis against the assigned wedge.
**Generated By**:
- **Generator**: C1
- **Generator Version**: 1.0.0
**Inherits From**:
- **Base**: STUDIO_DEFAULT_ORG
- **Version**: 1.0.0
- **Schema Version**: 2.1.4

## Startup Token Hero

**Genre**: founding-hypothesis
**Rendered**: Instead of relying on legacy gateways that miss payload-less fraud, Abnormal profiles baseline behavior to block sophisticated identity attacks — securing your enterprise before the first click.
**Mechanism**: spine-derived-v1
**Template Id**: spine-founding-hypothesis
**Vocab Fingerprint**: 6850974b8244570d

## Startup Token Positioning

**Genre**: moore-positioning
**Rendered**: AI-native email security for enterprises for CISOs at cloud-first organizations. Unlike legacy Secure Email Gateways — block socially engineered attacks that bypass perimeter filters miss.
**Mechanism**: spine-derived-v1
**Template Id**: spine-moore-positioning
**Vocab Fingerprint**: bb439c6530e858a1

## Startup Token Pitch Deck

**Genre**: pitch-deck
**Rendered**: Problem: SecOps teams spend hours managing complex Proofpoint MX records while payload-less impersonation attacks still slip into employee inboxes
Solution: Instead of relying on legacy gateways that miss payload-less fraud, Abnormal profiles baseline behavior to block sophisticated identity attacks — securing your enterprise before the first click.
Customer: CISOs at cloud-first organizations
Unlike: legacy Secure Email Gateways
**Mechanism**: spine-derived-v1
**Template Id**: spine-pitch-deck
**Vocab Fingerprint**: 11655a332dbbb78b

## Startup Token M E D D P I C C

**Pain**: SecOps teams spend hours managing complex Proofpoint MX records while payload-less impersonation attacks still slip into employee inboxes
**Metrics**: Target: Advanced threats are neutralized instantly, and IT teams reclaim 90% of the time previously spent on manual quarantine management.
**Rendered**: Pain: SecOps teams spend hours managing complex Proofpoint MX records while payload-less impersonation attacks still slip into employee inboxes
Economic buyer: Enterprise CISO
Metrics: Target: Advanced threats are neutralized instantly, and IT teams reclaim 90% of the time previously spent on manual quarantine management.
Competition: legacy Secure Email Gateways
**Mechanism**: spine-derived-v1
**Competition**: legacy Secure Email Gateways
**Economic Buyer**: Enterprise CISO
**Vocab Fingerprint**: cc5f403df83e5405

## Startup Token Cold Email

**Genre**: cold-email
**Rendered**: Subject: AI-native email security for enterprises for CISOs at cloud-first organizations

CISOs at cloud-first organizations — SecOps teams spend hours managing complex Proofpoint MX records while payload-less impersonation attacks still slip into employee inboxes Instead of relying on legacy gateways that miss payload-less fraud, Abnormal profiles baseline behavior to block sophisticated identity attacks — securing your enterprise before the first click.
**Mechanism**: spine-derived-v1
**Template Id**: spine-cold-email
**Vocab Fingerprint**: 426b0284e082ec88

## Startup Token Agent Spec

**Genre**: ai-agent-spec
**Rendered**: AI-native email security for enterprises. Instead of relying on legacy gateways that miss payload-less fraud, Abnormal profiles baseline behavior to block sophisticated identity attacks — securing your enterprise before the first click. Serves CISOs at cloud-first organizations.
**Mechanism**: spine-derived-v1
**Template Id**: spine-ai-agent-spec
**Vocab Fingerprint**: 0823581c4db51787

## Neighborhood

### Positioned bets

- [Cloud-Native SMB Payroll SaaS](/CompanyTypes/Cloud-Native_SMB_Payroll_SaaS) — positioned bet · CompanyTypes

### What it offers

- [Behavioral Email Defense](/Software/Behavioral_Email_Defense) — offers · Software

### Competitors

- [Proofpoint](/Competitors/Proofpoint) — competes with · Competitors
- [Secure Email Gateways](/Competitors/Secure_Email_Gateways) — competes with · Competitors
- [Avanan](/Competitors/Avanan) — competes with · Competitors
- [Mimecast](/Competitors/Mimecast) — competes with · Competitors
- [Tessian](/Competitors/Tessian) — competes with · Competitors
- [Microsoft Defender](/Competitors/Microsoft_Defender) — competes with · Competitors
- [Legacy SEGs](/Competitors/Legacy_SEGs) — competes with · Competitors

### Embodies

- [Headless SaaS](/Theses/Headless_SaaS) — embodies · Theses

### Composed of

- [Message Quarantine Service](/Services/Message_Quarantine_Service) — composes · Services
- [Identity Profiling Agent](/Agents/Identity_Profiling_Agent) — composes · Agents
- [Financial Fraud Agent](/Agents/Financial_Fraud_Agent) — composes · Agents
- [Communication Pattern API](/Software/Communication_Pattern_API) — composes · Software
- [Tenant Integration API](/Software/Tenant_Integration_API) — composes · Software

### Who it serves

- [Enterprise Security Team](/CompanyTypes/Enterprise_Security_Team) — serves · CompanyTypes

### What it addresses

- [Stop Advanced Email Attacks](/Problems/Stop_Advanced_Email_Attacks) — addresses · Problems

### Similar Startups

- [Forgouble](/Startups/Forgouble) — similar · Startups
- [Apimuri](/Startups/Apimuri) — similar · Startups
- [Summitgate](/Startups/Summitgate) — similar · Startups
- [Hopporosity](/Startups/Hopporosity) — similar · Startups
- [Corelamp](/Startups/Corelamp) — similar · Startups
- [Mythenith](/Startups/Mythenith) — similar · Startups
- [Burdoom](/Startups/Burdoom) — similar · Startups
- [Apyard](/Startups/Apyard) — similar · Startups
- [Domaintype](/Startups/Domaintype) — similar · Startups
- [Activefire](/Startups/Activefire) — similar · Startups
- [Purewire](/Startups/Purewire) — similar · Startups
- [Embergate](/Startups/Embergate) — similar · Startups
- [Zenithember](/Startups/Zenithember) — similar · Startups
- [Hollowhaven](/Startups/Hollowhaven) — similar · Startups
- [Porosityscaffold](/Startups/Porosityscaffold) — similar · Startups
- [Botpoint](/Startups/Botpoint) — similar · Startups
