Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Sublime Security announced a $150 million Series C on October 28, 2025, led by Georgian. The financing values the company’s pitch that email defense can move beyond static filtering toward organization-specific detection, automated investigation, and faster response. Sublime says it will use the money to expand its agentic-AI capabilities, accelerate product development, and grow its international operations.
The financing at a glance
| Round | Amount | Announcement date | Lead investor |
|---|---|---|---|
| Series A | $20 million | April 24, 2024 | Index Ventures |
| Series B | $60 million | December 12, 2024 | IVP |
| Series C | $150 million | October 28, 2025 | Georgian |
The Series C included new participants Avenir, 01A, Jon Oberheide, and Nicole Perlroth. Existing investors Index Ventures, IVP, Citi Ventures, and Slow Ventures also participated, according to Sublime’s announcement.
The three publicly itemized rounds total $230 million. SecurityWeek reported that Sublime’s broader total funding exceeded $240 million, suggesting additional capital beyond those headline rounds. It is more accurate to describe the disclosed rounds as $230 million and the reported overall total as more than $240 million—not to present $240 million as an exact figure.
Why investors are funding email security
Generative AI can lower the cost of producing convincing, targeted phishing and business-email-compromise messages. That creates demand for systems that can use more than sender reputation or fixed signatures.
#1 Best Overall
Sublime’s investment case is that email security should adapt to an organization’s own relationships, communication patterns, and threat environment. Georgian described its rationale in its investment commentary, while Sublime’s financing materials emphasize the need for AI-native defenses.
That does not mean traditional controls are obsolete. Effective protection still depends on reliable telemetry, identity context, policy enforcement, remediation, explainability, and governance. AI-assisted analysis may reduce analyst workload, but buyers still need evidence on false positives, missed threats, and operational impact.
What Sublime Security sells
Sublime describes its product as a cloud email-security platform for Microsoft 365 and Google Workspace, with support for IMAP and API-based message ingestion. Its documented capabilities include:
Recommended Free Tools
- Phishing, malware, malicious-link, impersonation, and business-email-compromise detection
- User-reported-message analysis
- Threat hunting across historical email
- Organization-wide campaign remediation
- Email-bomb and malicious-calendar-event protection
- Graymail classification and email DLP
- Threat-intelligence ingestion
- SIEM, SOAR, webhook, and S3 exports
- Custom detection engineering through Message Query Language, or MQL
The company says its detection engine combines machine learning, computer vision, natural-language understanding, OCR, behavioral analysis, file and URL inspection, sender reputation, and threat intelligence. These are described capabilities, not independent proof that Sublime outperforms Microsoft, Google, Proofpoint, Mimecast, Abnormal Security, or another competitor.
What “agentic AI” means in Sublime’s product
In this context, “agentic” refers to software performing a multi-step security workflow rather than merely classifying a message.
Autonomous Security Analyst
Sublime markets its Autonomous Security Analyst, or ASA, as an agent that investigates and triages suspicious or user-reported messages. The intended benefit is to reduce the manual work involved in determining whether a message is malicious and whether related messages form part of a broader campaign.
Autonomous Detection Engineer
Its Autonomous Detection Engineer, or ADÉ, is intended to create organization-specific detections, backtest them against historical email, and propose new coverage. Sublime’s documentation describes a workflow that can use configured precision standards and organizational context.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →The important distinction is that agentic AI does not automatically mean unlimited autonomous authority. In production, security teams should establish approval gates, precision thresholds, audit trails, rollback procedures, and clear limits on quarantine or bulk-remediation actions. A flawed rule deployed across an organization could disrupt legitimate business communications at scale.
MQL and the programmable-detection pitch
Sublime’s Message Query Language is a domain-specific language for analyzing email and hunting across historical messages. The company presents it as transparent and email-provider-agnostic, allowing security teams to inspect and customize detection logic instead of relying solely on opaque verdicts.
This creates a trade-off. Readable, programmable detections can provide more control and explainability, but they may also require specialized skills and ongoing maintenance. The AI agents are meant to reduce that burden; buyers should still ask how much human review, tuning, and incident ownership is expected after deployment.
Rank #3
How deployment differs from a traditional gateway
Sublime emphasizes API-based deployment that does not require changing MX records or redesigning mail routing. That can reduce rollout friction for Microsoft 365 and Google Workspace environments, particularly when a company wants post-delivery analysis and remediation alongside native controls.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
The platform also lists managed cloud, single-tenant SaaS, self-managed AWS, AWS GovCloud, Microsoft Azure, and Docker-based deployment options. The installation documentation says AWS and Azure deployments can scale to any number of mailboxes. A dedicated Docker guide, however, describes Docker as limited to 100 active mailboxes, intended for testing or smaller deployments, and supported on a best-effort basis. Another documentation page has displayed a different 600-mailbox figure; buyers should resolve that discrepancy directly with Sublime rather than assume Docker is an unlimited production alternative.
API deployment is not automatically equivalent to inline, pre-delivery enforcement. Organizations should determine whether they need messages stopped before delivery, post-delivery remediation, or both. They should also evaluate how Sublime’s actions interact with Microsoft Defender or Google’s native filtering, including duplicate quarantines, conflicting verdicts, and confusing user notifications.
Microsoft 365 implementation considerations
Sublime’s self-managed Microsoft 365 setup requires a Global Administrator or equivalent administrative privileges, Microsoft Graph application permissions, and administrator consent. The company recommends configuring Microsoft Safe Attachments to Block rather than Dynamic Delivery for compatibility, according to its Microsoft 365 documentation.
Security teams should review mailbox permissions, data residency, historical-message access, log storage, and remediation authority. Where possible, Microsoft 365 customers should also examine whether Exchange Online RBAC for Applications can narrow access to the minimum necessary scope.
Rank #4
Growth and customer claims
According to Sublime’s October 2025 announcement and its press release, annual recurring revenue grew 100% in the first half of 2025, its customer base grew fourfold since the beginning of 2025, and it retained 100% of its enterprise customers since inception.
Those are company-reported figures, not audited financial results or independently verified market-share data. Retention is not the same as detection accuracy, customer profitability, or satisfaction. The company named Spotify, Snowflake, Zscaler, Anduril, Centrica, Benteler, British Gas, Elastic, SentinelOne, and Compass as customers; logos demonstrate reported commercial adoption but do not establish deployment size, spending, performance, or exclusivity.
What the funding signals
The round can reasonably be read as a bet on three developments:
- Email security remains a large replacement and expansion market. Investors see room for a newer vendor despite Microsoft, Google, and established security providers.
- Detection engineering is becoming an automation target. Sublime is positioning triage, campaign investigation, and rule creation as software workflows rather than purely manual analyst tasks.
- Enterprise distribution matters as much as model development. The capital will also fund partnerships, support, compliance, and global expansion. A large round raises expectations for dependable international operations, not just better AI features.
How to evaluate Sublime against alternatives
Sublime should be compared with alternatives using the same operational criteria rather than a generic “AI versus legacy” label:
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11| Option | Relevant evaluation angle | Potential caution |
|---|---|---|
| Sublime | Adaptive detections, MQL, agentic triage, API and self-managed options | Validate efficacy, permissions, pricing, and self-hosting costs |
| Microsoft Defender for Office 365 | Native Microsoft integration and consolidated administration | May overlap with existing licensing and provide less of a separate programmable layer |
| Google Workspace security | Native Gmail protection with minimal additional vendor complexity | May not meet cross-provider or advanced detection-engineering requirements |
| Proofpoint | Mature enterprise email security, compliance, and broader services | Compare deployment complexity, customization, and total cost |
| Mimecast | Email security combined with continuity, archiving, and compliance capabilities | May offer more platform breadth than a narrowly focused buyer needs |
| Abnormal Security | Behavioral and API-based protection for BEC and targeted attacks | Compare transparency, automation controls, deployment, and pricing |
The right choice depends on whether the organization prioritizes native-suite integration, inline mail-flow control, API-based remediation, custom detections, compliance, self-hosting, or reduced analyst workload. A company that only needs protections already included in Microsoft or Google may not justify another vendor. A buyer primarily seeking archiving or continuity may also find a specialized adaptive-detection platform to be the wrong fit.
Best Value
Pricing and economics
Sublime’s plans page has advertised Core as free for individual security practitioners and lightweight deployments, including the first 100 mailboxes. Enterprise pricing is not presented as a public per-mailbox price and instead requires a sales conversation. That free tier can support an evaluation, but it should not be treated as an indicator of enterprise pricing, support levels, or production economics.
Self-managed deployment may add AWS or Azure infrastructure, storage, operations, monitoring, backup, upgrade, and support costs. Buyers should model cost per protected mailbox alongside analyst time, implementation effort, and the financial impact of false positives or missed attacks.
What remains unproven
- Independent detection and remediation benchmarks compared with native controls and competing vendors
- False-positive and missed-threat rates in varied enterprise environments
- Enterprise pricing and total cost at scale
- How much human approval is required for ASA and ADÉ in production
- Whether adaptive detections maintain precision as attack patterns change
- The practical cost and support burden of self-managed deployments
- How customers handle mailbox permissions, data locality, model processing, and log retention
The $150 million financing gives Sublime substantial resources to pursue its strategy. It does not, by itself, establish that the platform catches more threats, produces fewer false positives, or delivers better economics than alternatives. Those questions require customer-side measurements and independent testing.
Free tools Windows power users keep installed
One-click scans. No signup required.
Bottom line
Sublime’s Series C is a significant financing for an email-security company built around programmable detections and agent-assisted investigation. The strategic bet is not simply that AI can label more messages; it is that AI can help perform the repetitive, organization-specific work of investigating campaigns and engineering new detections. The investment will be meaningful for buyers only if Sublime converts that promise into measurable improvements in detection quality, analyst productivity, deployment friction, and cost—while preserving human oversight over high-impact actions.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

