Material Security
Company Overview
Material Security is an American cybersecurity company headquartered in Redwood City, California. Founded in 2017 by former Dropbox engineers, the company focuses on securing the "cloud office", specifically Microsoft 365 and Google Workspace. Material Security was built on the premise that traditional "perimeter-based" email security (like Secure Email Gateways) is insufficient for modern cloud environments because it cannot protect data after it lands in an inbox.
Material's approach applies Zero Trust principles to the mailbox itself. Rather than just trying to block malicious emails from entering, Material assumes that accounts will eventually be compromised. Its technology focuses on limiting the "blast radius" of a breach by protecting the sensitive data sitting in archives and preventing attackers from using a compromised account to move laterally or exfiltrate information.
Continue…The company is backed by prominent venture capital firms, including Andreessen Horowitz and Founders Fund, and serves a client base that includes high-growth technology companies and large enterprises.
Core Technology: API-First Security
Material Security differentiates itself from legacy vendors by using an API-based architecture rather than an inline Gateway (SEG).
* No MX Record Changes: Unlike gateways that require re-routing all email traffic (acting as a "man-in-the-middle"), Material connects directly to Microsoft 365 and Google Workspace via their native APIs.
* Internal Visibility: Because it sits "inside" the cloud environment, Material can analyze internal-to-internal traffic, historical emails, and user settings, areas that traditional gateways cannot see.
* Zero Latency: The solution does not sit in the mail flow, meaning it never delays email delivery or causes outages due to gateway failures.
Products and Services
Material's platform creates a unified security layer for the cloud office, combining threat detection, data protection, and posture management.
1. Leak Prevention (Data Protection at Rest)
This is Material's flagship differentiator. Most email security tools only scan emails as they arrive. Material protects the vast archive of sensitive data (tax forms, legal documents, password resets) that accumulates in mailboxes over years.
* Step-Up Authentication: Material scans the entire email archive for sensitive information. It then "redacts" this content in the user's inbox, replacing it with a verification challenge.
* The Workflow: When a user (or an attacker) attempts to open an old email containing sensitive data, they must verify their identity using Multi-Factor Authentication (MFA) (e.g., Duo, Okta) to unlock the content.
* Benefit: Even if an attacker hijacks an employee's email account, they cannot simply search for "password" or "invoice" to steal data, because they cannot pass the secondary MFA challenge.
2. Inbound Phishing and BEC Protection
Material provides advanced detection to stop attacks that bypass native Microsoft/Google filters.
* Behavioral Analysis: Using AI, the platform analyzes communication patterns to detect Business Email Compromise (BEC), VIP impersonation, and vendor fraud.
* Payload-less Detection: It identifies socially engineered attacks that lack malicious links or attachments (e.g., "Are you at your desk? I need a wire transfer").
* API-Based Remediation: If a malicious email is detected post-delivery, Material can instantly retract it from the user's inbox.
3. Account Takeover (ATO) Protection
Material focuses on detecting compromised identities and locking them down before damage occurs.
* Lateral Movement Prevention: The platform detects if a compromised account is sending internal phishing emails to colleagues.
* Automatic Remediation: Upon detecting a takeover (e.g., impossible travel, suspicious forwarding rules), the system can automatically suspend the account, revoke active sessions, and force a password reset.
* Risk Analysis: It identifies accounts with weak configurations, such as those missing MFA or using legacy protocols (IMAP/POP), which are common entry points for attackers.
4. Phishing Response and Automation
This module is designed to reduce the workload for Security Operations Centers (SOCs).
* One-Click Reporting: Employees can report suspicious emails directly from their inbox.
* Cluster Analysis (Herd Immunity): When one user reports a phish, Material?s AI analyzes the message and automatically finds similar messages across the entire organization. It then "claws back" (removes) those emails from all other inboxes, ensuring that one report protects the entire company.
* Automated Triage: The system automatically analyzes reported emails, determining if they are malicious, safe, or spam, and notifies the user of the result, closing the feedback loop without analyst intervention.
5. Posture Management
Material acts as a "health check" for the cloud office environment.
* Shadow IT Visibility: It scans for third-party applications (OAuth grants) that have been given access to email or drive data (e.g., a PDF editor that has read/write access to a CEO?s inbox) and allows admins to revoke them.
* Configuration Monitoring: It alerts administrators to dangerous settings, such as global forwarding rules or weak tenant-wide security policies.
Deployment Models
Material Security offers flexible deployment options to meet strict compliance and privacy needs.
* SaaS: A standard cloud-hosted model for rapid deployment.
* Single-Tenant (Private Instance): Uniquely, Material offers a single-tenant deployment option where the infrastructure is hosted in an isolated cloud environment dedicated to a single customer. This allows highly regulated organizations (fintech, healthcare, government) to keep all data processing within their own virtual perimeter, ensuring that customer data never mingles with others.