A controlled boundary in every deployment.
EyrieDefender supports customer-controlled and tenant-isolated deployment shapes while applying the same privacy rule: user data, reported-message content, URLs, attachments, and files are not shared externally for scanning or AI analysis.
Analysis stays with the customer data
Reported-mail ingestion, private AI analysis, signature evaluation, tenant IOC correlation, Assessor, and ZAP operate within the deployment boundary. Files are processed locally. If file reputation is needed, a cryptographic hash is generated locally and only that hash may be queried.
Tenant isolation
Each tenant has isolated case data, IOC history, model context, encryption controls, and audit records. Customer content is not pooled for cross-tenant analysis or training.
Report-only workflow
The investigation pipeline runs on messages submitted through the authorized reporting workflow. The reported item travels over an authenticated channel and remains within the controlled environment during adjudication.
Identity and access
Watchguard uses the user’s authenticated mailbox session. Assessor connects to the customer identity provider through standard controls, with roles and actions recorded for audit.
Data flow
A user reports a message. Private analysis produces a rationale, local IOC context is applied, and an analyst reviews the case. For a confirmed threat, ZAP previews and performs the approved mailbox action. Only a file hash may cross the external boundary for reputation lookup.
Ship it to your IT
Tell us which shape fits — on-prem or cloud, single-tenant or MSSP — and we will provide the appropriate deployment runbook.
