AI-native email security — private beta

Phishing
stops at the door.

The dangerous email looks like your CEO, your vendor, your bank. Doorcheck's AI checks the intent behind every message — and purges what doesn't belong from every inbox in seconds.

Live quarantine feedapp.doorcheck.io · UTC
PHISH
Action required: your mailbox will be suspended
it-support@rnicrosoft-online.com · lookalike domain — “rn” is not “m”
just nowquarantined
BEC
Re: Wire instructions for Friday's closing
ceo.office@bastlon-corp.com · exec impersonation + urgent payment ask
2m agoquarantined
VENDOR FRAUD
Updated remittance details — invoice #8841
billing@trusted-supplier.co · real account, hijacked — new bank details never seen in 3 years of invoices
9m agopurged ×31
PHISH
DocuSign: contract renewal awaiting signature
notify@docusign-mail.net · brand spoof — links don’t go to DocuSign
14m agoquarantined
PHISH
MFA reset requested for your account
security@okta-verify.support · credential lure — same pattern in 12 mailboxes
27m agopurged ×12
Caught before anyone clicks — nothing is deletedpurge = recall to quarantine
Plugs straight into
Microsoft 365Google WorkspaceExchange on-premcPanelIMAPSlackSplunkAny SIEM / SOARWebhooks & REST API
The problem

The most dangerous email
doesn't look dangerous

No malware. No scary attachment. No obvious link. Just business as usual:

“Can you send the wire today?”
“Here are our new bank details.”
“I’m locked out — can you reset this?”
“Please review this document.”

It looks like business. It sounds like someone you know. That's the danger — and it's exactly what Doorcheck is built for.

The AI difference

Your filters check the email.
Doorcheck checks the relationship.

Traditional security asks “is this email malicious?” Doorcheck's AI asks “does this email make sense?” — reasoning over the signals around the message:

Who is communicating?
Sender ↔ recipient history, not just SPF/DKIM.
Is this relationship normal?
First contact, or a five-year vendor thread?
Has the conversation changed?
New tone, new urgency, new reply-to address.
Is the request unusual?
Payments, credentials, and secrecy raise the score.
Does history back it up?
A “new bank account” that no invoice ever used.
Is it part of a campaign?
The same pattern landing in 40 other mailboxes.

The sender can be real. The mailbox can be real. The conversation can be real. The request can still be wrong.

How it works

Check. Catch. Clear.

One attack. One decision. Every copy gone.

01
Check
Doorcheck’s AI learns your communication graph — people, vendors, relationships, and what normal looks like for each of them.
02
Catch
Every message is scored for intent and context. Impersonation, BEC, phishing, and account takeover get caught even when they look legitimate.
03
Clear
Confirmed threats are traced across the organization and recalled from every inbox into quarantine — nothing is deleted, everything is audit-logged, and one click undoes a wrong call.
The metric that matters

Zero reached an inbox.
That's the whole pitch.

No employee clicked it. No finance team paid it. No analyst spent an afternoon cleaning it up. The best email threat is the one your people never see.

And when we get it wrong?

A wrong call costs one click.
Not an email.

"Purge" never means delete. Everything Doorcheck removes is recalled into quarantine — held intact, in your control, one click from the inbox. The full posture — encryption, GDPR, retention, audit — is on the Security & compliance page.

Nothing is ever deleted
Quarantine is a holding area, not a trash can. Every message Doorcheck recalls stays intact, searchable, and exportable until you decide.
One-click release
Mailbox owners see their own quarantine digest. Releasing a message puts it back in the inbox in seconds — no ticket, no admin round-trip.
Every release teaches the AI
A released message is a training signal: the communication graph updates, and the same legitimate pattern doesn’t get flagged twice.
Engage on your terms

Watch first.
Enforce when ready.

Doorcheck runs in the mode you choose — see exactly what it would do before you let it act, and keep every mailbox owner informed once you do.

Monitor mode
See every verdict — touch nothing
In monitor mode Doorcheck scores every message and shows what it would have quarantined — while mail flows completely untouched. Judge the AI on your real traffic before it acts on a single email.
Enforce mode
Flip the switch when convinced
One toggle turns verdicts into action: confirmed threats are recalled to quarantine automatically, campaigns are purged fleet-wide — every action audit-logged and reversible.
Mailbox reports
Nobody is left in the dark
Every mailbox gets its own report of what was blocked and why. Owners review their quarantine digest and release a wrong call themselves — one click, no ticket.
Sovereign by design

Your mail. Your hardware.
Your AI.

Doorcheck is AI-native and sovereignty-first: the same detection stack runs as SaaS or entirely inside your infrastructure — models included. Mail content never has to leave.

100%
of the AI can run on your own hardware
0
bytes of mail content leave a sovereign deployment
3
detection layers keep verdicts flowing — even fully offline
Coverage

Built for the attacks that look legitimate

Phishing
Polished, personalized, AI-written — caught by intent, not just links.
BEC
The invoice that costs you money is rarely “malicious”. We check it anyway.
Vendor fraud
Trusted sender ≠ trusted forever. We watch the relationship.
Account takeover
Same mailbox, same signature — different behavior. We notice.
Impersonation
Lookalike domains and display-name games, flagged on arrival.
Why Doorcheck

Less inbox archaeology.
More actual security.

AI handles the scale — detection, investigation, cleanup, coaching. Your team handles the judgment.

Behavioral AI
Communication-graph intelligence learns how your people actually write, pay, and reply — and catches the payload-less lures that filters wave through.
Find one. Purge all.
One detection maps the whole campaign. Search every mailbox and recall every copy to quarantine in one click — seconds from verdict to clean inboxes.
Protected in minutes
OAuth into Microsoft 365 or Google Workspace — or connect Exchange on-premise, cPanel, and IMAP. No MX changes, no mail-flow surgery.
Sovereign AI
Run the models on your own hardware. Self-hosted, multi-tenant, air-gap friendly — mail content never has to leave your infrastructure.
AI failover & token optimization
Multi-provider AI with automatic failover, local classifiers as the last line of defense, and token-optimized prompts that keep verdicts fast and costs flat.
One attack teaches all
Campaigns are clustered across every Doorcheck tenant. When one org is hit, the rest are inoculated within minutes.
Adaptive learning & training
Simulations adapt to who actually clicks; just-in-time coaching goes only to them — and the AI keeps re-learning from every verdict and report.
On-prem mail, first-class
Exchange on-premise and cPanel fleets get the same behavioral AI as the cloud suites — one console for every mailbox you run.
Answers, not alerts
Reported phish auto-triage themselves, posture is scored continuously, and every action lands in the audit log.
Where it shines

Built for whoever's defending

One console, every team size. Here's where Doorcheck fits right in.

01
Lean IT teams
No SOC required. Verdicts, purges, and training run themselves — you review a digest, not a queue.
02
Security teams
Full campaign hunting, cross-tenant intel, and audit-grade logs that slot into your SIEM.
03
MSPs
Multi-tenant console with per-client policies. Protect every customer from one pane of glass.
04
Regulated orgs
Encrypted at rest, audit-grade logs, SSO — and sovereign self-hosted AI when data must never leave.

Don't trust the email.
Check it.

Request a seat in the private beta. Connect your existing mail in minutes — early-access teams get white-glove onboarding and founding-customer pricing, locked for life.