After the filter. Before the click.

The phish that beat the filter is the one that matters.

Your spam filter already made its decision. ToneGuard works on what it let through — showing the reader why a message is manipulating them and what is really behind its links, without anyone clicking anything.

Read-only permissionsNothing storedDeployed by IT, not students
the add-in pane, running its built-in sampleLIVE

The actual pane — same files Outlook loads, showing a sample verdict. Poke it. Open it full-size ↗

The gap

Filters judge messages. Nobody was judging the moment of belief.

The message that costs a university money is the one that looked ordinary enough to be delivered — and it fails or succeeds in the seconds after a student opens it.

BEFORE DELIVERY

The filter catches almost everything

Secure gateways are good. That is exactly why what survives them looks ordinary — it was engineered to.

IN THE INBOX

The survivor looks like work

An invoice from a known name. A sign-in page pixel-identical to the real one. The reader has no instrument — just a hyperlink and a deadline.

AT THE CLICK

ToneGuard is standing there

It quotes the sentence doing the manipulating and shows a photograph of the page behind the link — evidence, at the moment it is needed.

What the reader sees

Not a score. Evidence.

Every warning carries the thing that triggered it — the exact sentence, the exact address, the exact page. Students learn to spot the next one on their own.

Pretext analysis

Names the manipulation — urgency, authority, fear — and quotes the sentence that does it.

Quoted from the messagePayment must be confirmed within 24 hours or the account will be suspended.”

Safe link preview

Destinations open in a single-use isolated machine, and the reader sees a screenshot. A fake sign-in page can be looked at without being touched.

The message shows / it actually opens
invoice_March.pdfhttps://secure-billing-review.xyz/view

Campus threat digest

What ToneGuard caught across campus, clustered into a warning your IT staff review and send in their own voice.

ON THE ROADMAP — NOT SHIPPING TODAY, AND WE SAY SO
Deployment

Ships like infrastructure, not like an app.

An administrator deploys tenant-wide. Students install nothing, sign in to nothing, and configure nothing.

Your admin uploads a manifest

Microsoft 365 admin centre or Google Workspace Marketplace — to a pilot group first, the whole tenant when you are ready.

The pane proves itself

A built-in setup check verifies sign-in, recognition, and exactly which analysis stages are live — before any student needs it to work.

Readers get evidence

Gmail checks automatically when a message opens. Outlook checks on demand. Every verdict shows its work.

Microsoft 365 · Outlook — permission: ReadItem, nothing moreGoogle Workspace · Gmail — reads only the open message
The standing rule

Three sentences ToneGuard is built to never say.

Security tools earn trust by what they refuse to claim. These refusals are enforced in code, not promised in policy.

Never said
“This message is safe.”A check that could not run is reported as unavailable — silence is never dressed up as a clean result.
Never said
“This link is fine.”A link it did not open is described exactly that way: checked for disguise, not opened. The difference is the product.
Never said
Anything the attacker wrote for it.Model output may explain a finding. It may never reassure — so a message that steers the model can lose a warning, but cannot manufacture a pass.
Pilot

Put it in front of one campus first.

Start with a test group, see what it catches, then deploy tenant-wide when your team has watched it work.

Start a pilot