AI Email Security • Multi-Engine Detection • 6 Languages • CVE Intelligence

MailGuard AI

An enterprise email security platform with native detection in English, Arabic, Urdu, Roman-Urdu, Hindi and Sindhi, and Gulf/Pakistan/India regional threat intelligence. A multi-engine AI pipeline — rules, machine learning, regional-language models, malware delivery-vector analysis, network-layer monitoring, and QR Shield — reaches a single, explainable risk decision. Built for governments, banks, and critical infrastructure. Deploys on-prem or air-gapped. Your data never leaves your network.

Multi-engine AI detection pipeline Arabic, Urdu, Hindi & Sindhi — unmatched in the market On-prem & air-gap capable CVE-aware, auto-synced with CISA KEV SAMA CSF • NCA ECC • UAE IAR evidence-mapped
URL NLP SUB CVE AR QR Multi-engine AI • one risk decision
6
languages natively detected
Multi
independent detection engines
CVE
-aware, CISA KEV auto-synced
On-prem
or fully air-gapped
Live
pilot on your own traffic
1st
Sindhi-language phishing detection
▮ MAILGUARD AI — Threat analysis
→ Sender: ceo-noreply@microsofft.com
→ Subject: URGENT: Wire transfer approval needed
URL score:   0.72 — domain age 3d, no SPF
Text NLP:   0.89 — urgency + authority pattern
Subject:    0.84 — BEC lure signature
Vuln idx:   0.12 — no CVE match
Regional:    0.02 — no regional-language content
QR Shield:  0.00 — no QR codes
Ensemble score: 0 / 100
Verdict: ■ AUTO-BLOCKED — BEC
✓ Homoglyph detected: microsofft (double-f)
✓ Domain registered 3 days ago
✓ Writing style: 0.03 cosine sim vs CEO baseline
Illustrative example — request a live pilot to see this on your own mail
How it works

Multiple AI engines. One risk decision.

Every inbound email hits the MailGuard AI SMTP edge and is simultaneously scored by several independent detection engines — rules-based analysis, machine learning, regional-language models, malware delivery-vector analysis, and threat intelligence. The ensemble combines their outputs into a single 0–100 risk score. Score ≥85: auto-blocked. Score 50–84: quarantined. Below 50: delivered. Every decision is logged with a full forensic trail, SMTP headers, CVE mappings, and a plain-language AI explanation your SOC team can actually read.

This is not a signature-matching product. It uses pre-trained, continuously-updated models rather than requiring you to train anything yourself — so there is no lengthy tuning period before it is useful. The regional-language engines know Gulf, Pakistani and Indian scam patterns your existing SEG is completely blind to.

The engine room

Specialist engines running in parallel

Each engine contributes a specialist signal. The ensemble stops threats that any single engine would miss — especially attacks with no prior signature.

01
URL & Domain Analysis

Domain age, TLS validity, registrar reputation, redirect chains, look-alike and punycode domain detection, URL shortener unwrapping.

Real-time
02
Text Content ML

Pre-trained models detect BEC urgency patterns, executive impersonation signals, and phishing lures across English, Arabic, Urdu, Roman-Urdu, Hindi and Sindhi.

Real-time
03
Subject Line Analysis

Detects urgency, authority, fear, and reward-trigger patterns across every language the platform supports, plus US-market-specific scam patterns (IRS, SSA, delivery, gift-card BEC).

Real-time
04
Vulnerability Index Engine

Public CVEs mapped to email delivery vectors, auto-synced with the CISA Known Exploited Vulnerabilities catalog. CVSS-weighted scoring flags emails exploiting actively-exploited CVEs.

Auto-synced with CISA KEV
05
Regional Language Intelligence UNIQUE

Native Arabic, Urdu, Roman-Urdu, Hindi and Sindhi lure detection — GCC and South Asian brand impersonation, government-authority impersonation, and mobile-money/UPI scam patterns. No other commercial platform we are aware of covers Sindhi at all.

6 languages, natively
06
QR Shield Vision Pipeline

Every image attachment decoded: OCR → QR decode → URL extraction → ML scoring on the extracted link. Catches QR-code phishing that bypasses standard URL filters entirely.

Image decode & scoring

Multi-engine agreement boosts confidence

When several engines independently flag the same email, the combined confidence rises — catching attacks that each individual engine alone would rate as only borderline, including ones with clean SPF/DKIM/DMARC that a standard SEG would let straight through.

Autonomous response

Detection is only useful if something happens next

Autopilot lets MailGuard AI act immediately on very-high-confidence threats, instead of waiting on an analyst — but only for actions that are always safe to reverse. It quarantines a message rather than deleting it, and creates a removable block policy rather than a silent, untraceable change.

Acts in real time on confirmed high-confidence threats
Every action is reversible — nothing is ever silently destructive
Full activity log, with a one-click undo on any action taken
Configurable thresholds — off, recommend-only, or fully autonomous
▮ AUTOPILOT — monitoring, mode: autonomous
Incident: sender confirmed malicious (risk 96/100)
Action: block_sender — wire-fraud@corp-finance-alert.top
✓ Policy created — sender blocked across all mailboxes
✓ Logged to activity feed, fully attributable
Reversal available: ↻ Undo this action
Illustrative example — every Autopilot action in your own deployment is reversible the same way
Regional language intelligence

The threat every other SEG is blind to

Most global email security products are English-first. An attacker who sends «تحويل عاجل» (urgent wire transfer) in Arabic, or an equivalent lure in Urdu, Roman-Urdu, Hindi or Sindhi, bypasses standard English-trained detection entirely. MailGuard AI is built with purpose-made detection for each of these languages — not a translation layer bolted onto an English model.

Gulf and South Asian brand-impersonation detection, in-script
Government and financial-authority impersonation patterns (Gulf and Pakistan)
Sindhi-language detection — an initial pass, and to our knowledge unmatched by any commercial vendor
Six languages natively: English, Arabic, Urdu, Roman-Urdu, Hindi, Sindhi
Evidence-mapped to SAMA CSF, NCA ECC, UAE IAR, Qatar NCSA and Pakistan's SBP expectations
Language & script detection — illustrative examples
"Buy 5 Apple gift cards and send me the codes" — English: gift-card BEC
71
تحويل عاجل — Arabic: urgent wire transfer
96
فوری کے وائی سی اپڈیٹ — Urdu: urgent KYC update
79
Mubarak ho! Inaam jeeta — Roman-Urdu: prize scam
97
तुरंत केवाईसी अपडेट करें — Hindi: urgent KYC update
79
فوري: بئنڪ کاتو — Sindhi: bank/OTP scam
79
microsofft.com — English/Unicode: homoglyph domain spoof
91
Illustrative examples from our internal test suite — request a live pilot on your own traffic to see real results.
CVE threat intelligence — embedded
CVE-2024-21413 — Outlook RCE
CVSS 9.8KEV
CVE-2023-23397 — Outlook NTLM
CVSS 9.8KEV
CVE-2023-38831 — WinRAR RCE
CVSS 7.8KEV
CVE-2022-30190 — Follina MSDT
CVSS 7.8KEV
CVE-2017-11882 — Equation Editor
CVSS 7.8KEV
300+
CVEs indexed
54
CISA KEV active
Auto
-synced with CISA KEV
CVE Intelligence

300+ CVEs. Every one that arrives by email.

MailGuard AI embeds the complete NIST NVD + CISA KEV database — no internet required. Every email attachment and link is scored against 300+ CVEs covering 2010–2026, with 54 active CISA Known Exploited Vulnerabilities triggering auto-block regardless of other scores.

CVE-2024-21413 — Outlook RCE (CVSS 9.8)
CVE-2023-38831 — WinRAR RCE
CVE-2022-30190 — Follina 0-day
CVE-2017-11882 — Most-emailed exploit worldwide
RTF → OLE → 34 magic byte signatures
Protection capabilities

Every email attack vector covered

BEC & Spear Phishing

Executive impersonation, wire transfer lures, gift-card BEC, writing-style baseline analysis. Detects when an email doesn't match the sender's established communication patterns.

Real-time detection

QR Shield

OCR → QR decode → URL ML scoring on every image attachment. QR phishing routinely bypasses standard URL filters entirely — QR Shield closes that gap.

Every image attachment scanned

Attachment AI

34 magic byte signatures. VBA macro scan. CVE mapping: RTF→CVE-2017-11882, LNK→CVE-2017-8464, RAR→CVE-2023-38831. Archive bomb detection.

EXE, LNK, RTF, DOCX, PDF

Unicode & Homoglyph

Cyrillic homoglyphs, Turkish dotless-i tricks, zero-width characters, and right-to-left override characters — the same Unicode manipulation techniques used to hide prompt-injection attacks targeting AI assistants. Catches microsofft.com before it reaches the inbox.

Every message scanned

Outbound DLP

SSNs, IBANs, credit card numbers (Luhn-validated), health-record patterns, and passport numbers — detected in email body and attachments before leaving the network.

Every outbound message scanned

VIP Executive Protection

Writing-style baseline per executive. Impersonation attempt detection. Wire-fraud correlation. Look-alike domain monitoring for every C-suite member you configure.

Configurable per executive
Pipeline

From inbound SMTP to risk decision

01

MX Receive

Email arrives at the MailGuard AI SMTP edge. TLS enforced. SMTP smuggling blocked (CVE-2023-51764).

02

Auth Check

SPF, DKIM, DMARC evaluated. Failures feed the ensemble; no auth alone doesn't trigger block.

03

Multi-Engine Scan

All detection engines run in parallel. Attachments decoded, QR codes scanned, URLs extracted.

04

Ensemble Score

Weighted combination across engines produces a single 0–100 risk score.

05

Action

≥85: auto-block. 50–84: quarantine. <50: deliver. All decisions logged with full forensic trail.

06

SOC Audit

AI explanation in plain language. SMTP headers, CVE mappings, risk breakdown. SIEM/webhook export.

Compliance coverage

Evidence-mapped for the world's most regulated markets

MailGuard AI's own controls are mapped against the frameworks your procurement and audit teams will ask about, to support your own compliance work. This is evidence mapping to help your audit, not a certification held by Cyber Zeus Global — ask us for our current certification status.

SAMA CSF

Saudi Arabian Monetary Authority Cybersecurity Framework. Relevant for Saudi financial institutions.

NCA ECC

Saudi National Cybersecurity Authority Essential Cybersecurity Controls.

UAE IAR / NESA

UAE Information Assurance Regulation. Relevant for UAE critical infrastructure and government.

SOC 2

SOC 2 is in preparation, not yet certified. Ask us for our current status.

HIPAA

PHI-pattern detection in the outbound DLP engine, for organisations that handle health data.

ISO 27001

Evidence-mapped globally. Ask us for our current certification status.

GDPR

For organisations handling EU personal data. On-premises/air-gapped deployment keeps data under your own control.

This page maps MailGuard AI's controls against these frameworks to support your own compliance and audit work. It is not a claim that Cyber Zeus Global holds any of these certifications today — ask us directly for current status.

Deploy anywhere

On your infrastructure. Your network. Your rules.

MailGuard AI ships as a Docker Compose stack. Five minutes from zero to scanning. Air-gapped deployments ship with pre-trained models and the full CVE database embedded — no internet connection ever required. Email data never leaves your network.

Air-gapped / Offline

Fully isolated networks. No outbound connection. Pre-trained models. Embedded CVE database. Required for classified environments.

On-premises

Runs in your own datacentre. Linux x86/ARM. Docker Compose or bare metal. 8 services, single compose command.

Private Cloud

AWS, Azure, or GCP single-tenant deployment. Data residency enforced per region. No shared infrastructure.

M365 / Google Integration

Transparent gateway mode. Point your MX records at MailGuard AI — nothing changes for end users.

SIEM / SOAR Export

Real-time webhook to Splunk, Microsoft Sentinel, QRadar, Cortex XSOAR, PagerDuty, Slack, Teams.

Multi-tenant / MSSP

Full white-label. Per-tenant branding, billing API, MSSP console. One platform, your brand, your clients.

PlatformsLinuxWindowsDockerKubernetesx86 & ARM
Business case

Measurable return from the first month

Real

loss-avoided estimate on your own report, based on threats actually stopped and your own configured incident costs — not a generic industry multiple.

Live

pilot against your own email traffic — see exactly what your current gateway is missing, before you commit.

Fast

to deploy. Docker Compose, any Linux server, pre-trained models shipped in the package — no lengthy tuning period.

Tunable

detection thresholds, so you can balance catch-rate against false positives for your own environment and traffic pattern.

Actual results depend on your environment and traffic — request a live pilot to see real numbers on your own mail, not an industry-average estimate.

Where it fits

Built for high-stakes environments

Government & defense Central banks & financial services Critical infrastructure Sovereign wealth funds Healthcare & pharma Telecom operators Energy & utilities MSSPs & MSPs Law firms & legal
Global reach

Built for markets other vendors treat as an afterthought

MailGuard AI natively detects Arabic, Urdu, Roman-Urdu, Hindi and Sindhi attacks alongside English — and is evidence-mapped against the compliance frameworks that matter across the Gulf, Pakistan, India and North America. Same codebase, same detection depth, wherever you deploy it.

North America — SOC 2 in preparation, HIPAA evidence-mapped Middle East — SAMA CSF • NCA ECC • UAE IAR • Qatar NCSA Pakistan & India — SBP-aligned, native Urdu/Hindi/Sindhi detection UK & EU — GDPR-aware, evidence-mapped to ISO 27001

Stop the threats your current SEG is missing

Request a live demo. We will run MailGuard AI against your own email traffic and show you exactly what is getting through — regional-language BEC, QR phishing, CVE-linked exploits, and attacks your existing gateway never flags.

Request a Demo
Built for your scale

From a single team to the whole enterprise

Mailguard AI is designed to deliver value on day one for a small team, and to scale to a governed, multi-site enterprise deployment on the same platform.

For growing & mid-size businesses

Fast to stand up — no heavy integration project or dedicated team required
Predictable, seat-based licensing that scales with you
Runs in your cloud or on a single on-prem box
Immediate, plain-language insight your team can act on from day one

For large organizations

Multi-tenant, role-based access and full audit trails for governance
Deploys on-prem, air-gapped or in your private cloud — your data stays in your boundary
Integrates alongside existing enterprise systems, not instead of them
Signed, defensible evidence for every automated decision
In practice

Deployment scenarios

Illustrative walkthroughs of how Mailguard AI is used and the value it creates. Your figures are set on your own data during a proof-of-value engagement.

Proof of value

A scoped engagement on your own data shows the results before any wide rollout — measured, not promised.

Scale with confidence

Start with one team or site, then expand across the organization on the same platform — no re-buy, no re-build.

Governed by design

Every output is explainable and audit-ready, so risk and compliance teams can stand behind it.

Proof of value

See it on your own data

A scoped engagement shows the results measured on your own operation before any wide rollout — then scale across the organization on the same platform.

Book a proof of value