初创公司尽调
尽调报告 Cybersecurity late-stage private 2026-08-08

Material Security

云工作区安全独角兽,产品和客户证明可信;但过时估值锚点和有限公开财务披露仍卡住定价支撑。

Material Security 在云工作区安全上有可信差异化,客户证据也异常扎实;但 2022 年独角兽估值已经过旧,当前财务记录又太不透明,仅凭公开证据不足以支持按全价下注。

封面要素

上次公开估值 01
1100 USD M [CV001]
累计融资 02
166 USD M [CV002]
总部 04
Redwood City, CA [CO002]
核心平台焦点 05
Google Workspace + Microsoft 365 [CO003]
投资建议 06
research-more [CV040]

公司概况

Material Security 是一家位于 Redwood City 的网络安全公司,成立于 2017 年,为 Google Workspace 和 Microsoft 365 销售 API-native 安全能力。平台现在覆盖邮件、文件、账户和工作流驱动修复,而不只是投递前过滤。公开来源确认,公司在 2022 年 5 月以 $1.1B 估值完成 $100M Series C,累计披露融资 $166M。到 2026 年,公司仍通过新的 OAuth、自动化和 AI 治理产品材料保持可见活跃;作为私有安全供应商,其具名客户证明异常强。

官网
material.security
成立时间
2017-01-01
创始人
Ryan Noon, Abhishek Agrawal, Chris Park
创立地点
Redwood City, California, USA
总部
Redwood City, California, USA
产品
Material Security 为 Google Workspace 和 Microsoft 365 提供云工作区安全,包括投递后邮件保护、历史邮件和文件的敏感数据控制、账户接管遏制、调查,以及更新的 OAuth / AI 治理工作流。
客户
运行 Google Workspace 或 Microsoft 365 的企业和高端中端市场组织,尤其是需要更强投递后保护、调查速度、数据治理和低摩擦 API 部署的买方。
商业模式
企业 SaaS 订阅模式,通过直销和合作伙伴 / marketplace 路径销售;公开定价、合同结构、扩张率和服务组合仍未披露。
阶段
late-stage private
融资情况
公开证据确认 2021 年 $40M Series B,以及 2022 年以 $1.1B 估值完成的 $100M Series C,使累计披露融资达到 $166M。未识别到之后的公开新股融资轮。
[CO001, CO002, CO003, CO012, CO014, CO022, CO023, CU024]

执行摘要

主要优势

  • Material 更像云工作区安全平台,而不是狭义安全邮件网关;公开证据覆盖邮件、文件、账户安全和工作流自动化。
  • 以私营厂商标准看,具名客户证据很强,覆盖公开 SaaS、医疗敏感场景、金融科技和大型企业环境。
  • 产品方向贴合 2026 年仍能拿到溢价倍数的网络安全细分市场,尤其是云安全、投递后补救、OAuth 治理和提升运营人员效率的工作流。
  • 公司看起来能提供低摩擦 API 部署,并讲出有力的运营 ROI 叙事;在企业竞标评估中,这类因素可能很关键。

主要风险

  • 当前 ARR、增长、留存、毛利率、烧钱速度和客户集中度都未公开;没有私有数据室支撑,价格依据很弱。
  • Google 和 Microsoft 既是关键平台伙伴,也是长期捆绑销售威胁,带来结构性依赖和竞争压缩风险。
  • Material 触达高度敏感的历史邮件和文件数据,一旦产品侧出现隐私或安全事故,声誉和商业后果可能被放大。
  • 最近一次硬估值锚点来自 2022 年 5 月;如果当前表现已撑不起独角兽定价,投资人就有高买风险。
  • 公开客户证据仍更偏 Google Workspace,而不是 Microsoft 365,平台均衡性问题尚未解决。

未决问题

  • 当前 ARR、收入增长、毛利率、烧钱速度和现金跑道。
  • 净收入留存、总留存、流失率,以及定价 / 折扣行为。
  • 客户集中度、部署规模分布和头部账户敞口。
  • 股权结构表、清算优先权,以及 2022 年 Series C 之后的任何融资预期。
  • 关于误报率、检测质量和平台级扩张经济性的独立基准证据。

目录

Chapter 01

01公司概况

1.1 身份、类别与可复用事实基础

Material Security 应被视为后期私有云工作区安全公司,而不是狭窄的邮件插件。当前官网、产品页和 Microsoft marketplace 列表都把它描述为一个平台,可在 Google Workspace 和 Microsoft 365 中保护邮件、文件和账户。这很重要,因为后续尽调问题取决于 Material 只是入站钓鱼层,还是敏感协作数据的更广控制平面。最耐久的身份事实有异常充分的支持:公司成立于 2017 年,总部位于 Redwood City,并通过活跃的产品更新和思想领导力页面持续公开运营至 2026 年。公司自身叙事一致认为,一旦攻击者越过收件箱,碎片化单点工具会留下缺口;合作伙伴触点也强化同一平台框架。实际结论是,Material 的身份在官方、合作伙伴和独立来源中一致,但公司在财务规模上的公开细节仍远少于产品范围。[CO001, CO002, CO003, CO004, CO022, CO027]

KPI 快照表
指标数值 / 状态日期置信度缺口 / 备注
成立20172017官方和独立来源均反复提及
总部Redwood City, California2026关于页面、Business Wire 和 Craft 信息一致
最新披露估值$1.1B2022-05Series C 估值;未发现更新的公开重新定价
最新披露累计融资$166M 由公司披露 / $162M 见 Craft2022-2026明确保留追踪器冲突
当前公开阶段后期私有网络安全公司2026根据融资、客户和合作伙伴关系推断
当前客户证明OpenAI、Figma、Mars、Lyft、MassMutual、Gusto、Gopuff、Headway 等2026公开 logo 与背书很强;准确客户数量未披露
当前披露 ARR / 收入所审阅来源未公开披露2026重大承销缺口
当前披露员工数未找到公司发布的可靠数字2026第三方数据库存在分歧

混合官方披露、独立报道和明确未解决缺口。

[CO001, CO002, CO011, CO012, CO014, CO022]
FO002: 公司快照逻辑

Material 当前故事把工作区原生产品范围、蓝筹客户证明和合作伙伴杠杆连接在一起。

[CO003, CO004, CO024, CO025, CO027, CO033]

1.2 创始人、领导层交接与治理可见度

Material 的创始团队是真实资产。当前关于页面列出 Ryan Noon、Abhishek Agrawal 和 Chris Park 三位联合创始人;First Round 和创始人访谈则把他们与 Dropbox、Parastructure、Google 和 Microsoft Research 联系起来。这些背景不是装饰,而是直接对应公司保护现代工作发生所在协作套件的焦点。尽调更关键的进展,是可见的领导层交接:Ryan 现在任董事长,Abhishek 任 CEO。公开来源支持创始人控制和产品愿景的连续性,但没有给出清晰董事会名单、投票结构或 Series C 后控制权地图。因此,公司在创始人市场适配和领导连续性上得分较高,但相对其估值历史,治理深度仍披露不足。后续章节可复用的关键点是:Material 看起来由创始人主导且运营可信,但仍需要直接尽调董事会组成、投资者权利和关键人物依赖。[CO005, CO006, CO007, CO008, CO009, CO010]

领导层与创始人表
人物职务相关背景重要性当前可见度
Ryan Noon联合创始人兼董事长Parastructure 创始人;Dropbox 工程负责人创始人连续性与外部可信度
Abhishek Agrawal联合创始人兼 CEODropbox 产品负责人;Microsoft Research 工程师当前经营负责人和产品市场翻译者
Chris Park联合创始人兼工程副总裁Parastructure 与 Dropbox 基础设施;Google 隐私技术连续性与平台执行力
John Hrvatin产品与设计副总裁曾在 Microsoft 和 Dropbox 负责产品在创始人之外补强产品管理深度
Scott Williams财务与运营副总裁在 Dealpath 搭建财务;帮助 Talkdesk 扩张在无公开 CFO 级披露下体现财务职能成熟度
Rajan Kapoor安全副总裁前 Dropbox 安全负责人显示内部在信任与安全姿态上的可信度

覆盖公开可见度最高、最关键的创始人与高管,而不是完整组织架构图。

[CO005, CO006, CO007, CO008, CO009, CO010]
FO003: KPI 快照

公开记录在身份和融资上很强,商业证明中等,当前财务披露薄弱。

[CO001, CO002, CO012, CO014, CO022, CO030]

1.3 资本形成、客户证明与规模信号

尽管更新经营指标仍不透明,Material 的公开融资记录足以锚定后期阶段。独立和官方 2021 年来源显示,公司完成 $40 million Series B,将累计融资推至 $62 million;2022 年 5 月 Series C 又以 $1.1 billion 估值融资 $100 million,使累计融资升至 $166 million。公司和投资者称这些资金将用于销售扩张、国际增长、政府 GTM 和产品延伸。客户证明也已越过早期设计伙伴阶段:Series C 公告点名 Chubb、Compass、Roblox 和 Brex 为新参考账户,而当前客户页面显示更广名单,包括 Gusto、Gopuff、Lyft、Dotmatics、Figma、Headway 等。一个需要谨慎的点是数据一致性:第三方追踪器并不总同意累计融资额,审阅的公开来源也没有给出可靠当前 ARR、董事会或员工数。投资者因此能得到规模方向和客户质量的扎实证据,但拿不到便于承销的完整财务仪表盘。[CO011, CO012, CO013, CO014, CO015, CO016]

利益相关方或投资者地图
利益相关方角色重要性公开证据尽调要求
Founders FundSeries C 领投方锚定独角兽轮次和成长期验证Series C 报道确认当前持股和董事会权利
Andreessen Horowitz早期领投 / 重复支持方从启动到增长轮提供长期投资者支持A16z 文章加融资公告澄清董事会角色和 pro rata 姿态
Elad Gil重复投资者和 Series B 领投方知名运营者投资人,早期信号价值强Series B 和 Series C 报道确认当前经济权益和影响力
Google Cloud平台与 GTM 合作伙伴Premier Partner 身份和 Marketplace 路径提升 Workspace 客户可信度Google 合作伙伴页面量化联合销售和采购影响
Microsoft Marketplace采购与发现渠道验证产品在 Microsoft 生态中的露出Marketplace 列表澄清转化率和合作伙伴来源 pipeline
参考客户需求证明蓝筹客户为私有供应商提供重要可信度转移客户和融资页面要求部署深度和续约证据

这是公开利益相关方地图,不是股权结构表。

[CO013, CO017, CO019, CO024, CO025, CO026]

1.4 里程碑、产品拓宽与当前方向

里程碑记录显示,公司从攻陷后邮件防御,拓宽为更广的云工作区韧性平台。创立逻辑直接来自 2016 年选举黑客事件的教训,以及一旦攻击者进入内部,收件箱安全就会失效的判断。First Round 称,公司在构建前就售出 early access,用真实买方需求验证市场,并以 Stellarite 名称运营至 2020 年发布。到 2021 年 Series B,Material 已经在营销可见性与控制、防泄露、账户接管防护和钓鱼群体免疫。到 2026 年,产品更新节奏已经明显越过传统邮件过滤:Material 正在推出 OAuth 修复、重建集成、更深工作流自动化,以及 AI / 隐私思想领导力。公司与 Google 的合作关系和 marketplace 定位强化了当前方向。合在一起看,时间线暗示 Material 在独角兽轮次后并未停滞;但最大剩余问题是,平台拓宽带来了多少经济规模。[CO018, CO020, CO021, CO022, CO023, CO025]

里程碑表
日期事件类型金额 / 状态参与方 / 背景含义
2016选举黑客背景强化创立逻辑反向起源故事和创始人访谈问题框架聚焦攻陷后的邮件风险
2017Material Security 在 Redwood City 成立创立创始人 Ryan Noon、Abhishek Agrawal、Chris Park公司成立
2018Andreessen Horowitz 领投 Series A融资$22M官方 Series B 公告提到前一轮早期机构验证
2018产品构建前已有六个 early-access opt-in扩张First Round 创始人故事大规模发布前已有早期商业拉力
2020-06公司以 Stellarite 代码名走出隐身产品First Round 和投资者报道公开进入市场
2021-05宣布 Series B融资$40M;累计融资 $62MElad Gil 加 a16z 和其他投资者用于扩张运营和研发的资本
2022-05宣布 Series C融资$100M,估值 $1.1B;累计融资 $166MFounders Fund 领投轮独角兽跃升和扩张资本
2026-04OAuth Remediation Agent 与重建集成上线产品活跃当前 Material 更新页面持续拓宽产品的证据

公司历史、融资和当前公开产品方向的单一记录时间线。

[CO001, CO012, CO015, CO016, CO020, CO021]
FO001: 公司里程碑时间线

融资、发布和当前产品里程碑显示,2022 年独角兽轮次之后公司仍在持续活动。

[CO012, CO016, CO020, CO021, CO022, CO023]

1.5 图表

Chapter 02

02市场分析

2.1 市场边界:收件箱安全只是支出池的一部分

Material 位于邮件安全市场内,但正确边界比传统类别标签暗示的更窄、也更现代。独立市场报告仍衡量一个宽泛宇宙,包含网关、过滤、加密和合规控制。但供应商和威胁证据都显示,企业买方越来越从保护云工作区的角度思考,而不只是筛查入站邮件。Material 自身产品页面明确结合邮件、文件和账户保护;Google 和 Microsoft 也在同一协作资产中强调合规、身份、主权和数据防泄露控制。因此,相关纳入支出不是每个邮件服务器或 SMB 反垃圾产品;而是当原生 Microsoft 365 和 Google Workspace 控制必要但不足时,企业添加的专业层。最大替代品是安全邮件网关、原生套件控制和更广平台安全套件。实际含义是,Material 在一个快速增长但架构正在迁移的细分中竞争,价值中心正从边界过滤转向集成式云工作区防御。[CM001, CM003, CM018, CM019, CM020, CM021]

市场定义表
细分 / 类别纳入支出排除支出买方 / 付款方对 Material 的重要性
传统安全邮件网关入站过滤、垃圾邮件、恶意软件、附件和 URL 邮件边界防护邮件流之外的协作文件安全与 OAuth 治理安全 / IT仍是主要替代品,但架构更老
集成式云邮件安全基于 API 的威胁检测、投递后修复、账户遥测、内部邮件可见性工作区表面之外的端点和网络控制安全 / ITMaterial 最接近的直接竞争桶
工作区数据保护DLP、文件共享控制、留存、邮件和文件中的敏感内容发现没有主动保护的一般归档安全 / 合规关键在于 Material 已超出仅收件箱用例
原生套件安全Google Workspace 和 Microsoft 365 内置控制、加密、身份、合规功能第三方专业覆盖层和托管服务IT / 平台负责人设定基线,也可能吸收部分需求
更广泛的安全套件含邮件模块的 XDR、身份、培训和事件工具纯生产力或 CRM 工具CISO / CIO争夺安全预算和捆绑能力

相关市场边界聚焦企业云工作区安全,而不是历史上出售过的每一种邮箱过滤产品。

[CM018, CM020, CM021, CM025, CM026, CM031]
FM001: 市场规模视角

Material 的真实机会,是更宽邮件安全市场中的一个更窄企业云工作区切片。

[CM001, CM004, CM018, CM019, CM025, CM026]

2.2 用多重视角测算类别规模

即便在收窄到 Material 可服务切片之前,这个类别也足够大。Fortune Business Insights 估计,全球邮件安全支出 2026 年为 $6.06 billion,2034 年达到 $14.44 billion;Mordor 估计,仅云端子集 2026 年为 $6.24 billion,2031 年达到 $11.22 billion。具体数字不同,因为一个视角捕捉更宽市场,另一个聚焦云软件,但方向一致:Microsoft 365 和 Google Workspace 采用、AI 辅助钓鱼、更严格合规预期驱动双位数增长。更重要的承销细节是分层。大型企业已占云邮件安全支出的大多数,受监管或数据密集行业权重更高,因为它们面对不成比例的欺诈、隐私和运营暴露。因此,不应把 Material 无差别地对照整个市场估值。它最可信的可服务可触达市场,是大型企业云工作区部分;这些买方愿意为 API-native 保护、DLP 和攻陷后控制付费。[CM001, CM002, CM004, CM005, CM015, CM016]

TAM / SAM / SOM 规模测算视角表
视角发布方 / 来源年份数值方法 / 相关性局限
全球邮件安全市场Fortune Business Insights2026$6.06B覆盖邮件安全的宽口径自上而下类别支出包含 Material 永远不会直接瞄准的细分
全球邮件安全市场预测Fortune Business Insights2034$14.44B显示长期顺风和 11.5% CAGR长期预测精度天然偏弱
云端邮件安全软件市场Mordor Intelligence2026$6.24B更接近 API-native 和云交付平台仍比 Material 更宽,因为包含大量网关型供应商
大型企业云切片Mordor Intelligence2025云市场收入的 69.35%可作为 Material 偏好买方基础的有用代理不是 Material 的直接 SAM 数字
Material 服务切片基于市场和产品证据的内部推断2026窄于完整 TAM最好用大型企业 Microsoft 365 / Google Workspace 专业安全层代理公开来源未披露准确可服务市场

将宽口径 TAM 与更窄、受证据约束的 Material 可信可服务市场结合。

[CM001, CM002, CM004, CM005, CM016, CM027]
FM002: 市场估算区间

不同可靠规模测算方法仍指向一个数十亿美元、双位数增长的市场。

[CM001, CM002, CM004, CM005, CM040]

2.3 买方地图与采用路径

买方地图异常清晰。安全和 IT 负责人通常掌握预算,法务或合规团队影响需求集,普通员工既是被保护用户,也是攻击者瞄准的薄弱环节。Proofpoint 调查证据显示,超过 70% 员工承认有高风险行为,这进一步说明人的行为仍是采购决策核心。威胁遥测也指向同一方向:IC3 仍显示巨大的钓鱼和 BEC 损失,Microsoft 2026 年报告显示数十亿钓鱼事件,以及个人分析师无法手工管理的自动化规模。因此,采用通常从具体痛点开始——钓鱼分诊、BEC、DLP 或错误配置风险——然后扩展到更广工作流自动化和攻陷后韧性。Material 最强的自然适配,是已运行 Google Workspace 或 Microsoft 365 的大型企业;这些买方希望获得更好覆盖,又不想被邮件流重架构打断。这会缩窄 TAM,但当平台真正减少欺诈、合规和响应痛点时,也会提高买方紧迫性和付费意愿。[CM006, CM007, CM008, CM009, CM010, CM013]

细分 / 买方地图
细分主要买方主要用户预算负责人 / 付款方采用触发因素Material 适配或错配原因
Microsoft 365 大型企业CISO / SecOps全体员工、财务、管理层中央安全或 IT钓鱼、BEC、DLP 或事件响应痛点若买方需要 API-native 覆盖层,适配度强
Google Workspace 大型企业安全工程 / IT全体员工和文件共享用户中央安全或 IT需要更深入看见 Gmail、Drive 和账户姿态Material 的 Google 深度公开可见,适配度很强
受监管 BFSI / 医疗安全 + 合规高风险业务用户受合规影响的安全预算欺诈风险、隐私控制、审计要求DLP 和攻陷后控制重要,适配度强
安全团队较小的中端市场IT 通才 / MSP普通员工群体IT 或托管服务预算需要更易部署和自动化存在适配,但预算和人员限制扩张
默认使用原生控制的 SMBIT 管理员员工IT 或业主价格敏感且复杂度低除非风险或监管异常高,否则适配度弱

买方地图反映企业现实:即使每名员工都是潜在目标和信号源,预算负责人通常仍集中在中央。

[CM013, CM016, CM017, CM022, CM023, CM029]
FM003: 买方 / 细分地图

买方吸引力因威胁紧迫性、合规负担、预算能力和部署复杂度而不同。

[CM013, CM020, CM021, CM023, CM029, CM030]
FM004: 采用漏斗或价值链地图

采购路径通常从紧急威胁问题开始,再扩展到更广工作区控制。

[CM006, CM008, CM011, CM012, CM025, CM031]

2.4 增长驱动真实存在,但捆绑和技能约束同样存在

顺风很明显:钓鱼仍普遍存在,BEC 仍代价高昂,远程和混合办公持续扩大攻击面,协作套件现在把通信和敏感文件集中在同一处。市场报告也把合规、数字主权和 AI 驱动的威胁升级列为结构性驱动。但这不是一个无摩擦市场。Google 和 Microsoft 原生控制每年都在改进,减少部分客户需要的专业支出。SME 和资源不足团队面对真实的预算、培训和技能障碍。数据驻留、主权和错误配置问题也会拖慢或复杂化部署,尤其是跨多个租户或地域时。就 Material 而言,投资逻辑在公司能证明其集成自动化和攻陷后控制显著优于原生套件安全与网关既有厂商时最强。好消息是,架构正朝 Material 的方向移动;难点是把架构优势转化为可重复的采购紧迫性和持续定价权。[CM011, CM012, CM023, CM024, CM031, CM032]

增长驱动与约束表
驱动 / 约束方向时间证据对 Material 的含义
BEC 损失仍然巨大正向当前IC3 2025$3B+ 年度损失让高管持续关注
仍观察到数十亿次钓鱼事件正向当前Microsoft Q2 2026威胁量支撑自动化专业工具
云套件迁移正向当前至中期Fortune 和 Google更多 Microsoft 365 / Workspace 租户扩大可服务市场
DLP 与文件控制需求正向当前Google + Material将支出从仅收件箱产品推向更广范围
数字主权与合规正向中期Google 法律 / 合规提升可审计控制和政策自动化的价值
技能短缺负向当前Mordor可能拖慢部署,或偏向托管 / 捆绑产品
原生套件改进负向当前Google / Microsoft / 竞品页面捆绑压力可能压缩专业厂商定价权
SME 成本敏感负向当前Fortune限制企业核心之外的类别扩张

表格混合结构性驱动与约束因素,后者缩窄 Material 的现实可触达市场。

[CM006, CM008, CM020, CM021, CM022, CM023]

2.5 图表

Chapter 03

03竞争格局

3.1 竞争格局:API 覆盖层对网关对原生套件

Material 所处竞争格局按架构可以清晰分层。Proofpoint 和 Mimecast 仍属于既有网关阵营:它们重路由邮件流、内联检查消息,并在附件沙箱、URL 重写、连续性和归档最重要的场景取胜。Abnormal 代表更新的 API-based ICES 阵营,通过 Microsoft 365 或 Google Workspace API 部署,并在无载荷 BEC 和账户接管上有优势。Material 属于同一 API-native 家族,但进一步推进到攻陷后的文件、账户和调查工作流。除这些直接同类之外,真实替代集合还包括 Microsoft Defender、Google 原生控制、Check Point、Cisco,以及能吸收部分预算的捆绑套件,尽管它们并非逐点完美匹配。关键结论是,买方不是在不同 logo 的相同工具中选择;他们在不同部署摩擦、不同优势、以及对“邮件安全”含义不同定义的架构之间选择。[CP001, CP005, CP006, CP020, CP021, CP025]

竞品画像表
竞争对手类别目标客户核心优势局限 / 关注点
Proofpoint既有网关厂商大型受监管企业沙箱、URL 重写、企业生态深度网关部署更重,高端套件定价更高
Mimecast网关 / 混合型既有厂商重视连续性和归档的买方在过滤之外提供归档和连续性在纯文本 BEC 和攻陷后控制上的楔子较弱
Abnormal AIAPI-native 直接同类聚焦 BEC 的 M365 / Google 企业面向无载荷欺诈和 ATO 的行为 AI不是归档或连续性产品
Microsoft Defender for Office 365 产品原生套件替代品Microsoft 优先企业捆绑基线和 XDR 相邻能力更深的攻陷后工作流可能需要专业覆盖层
Check Point / Cisco / KnowBe4相邻套件或分层替代宽套件买方和安全栈整合者捆绑杠杆和既有关系邮件可能只是多个模块之一,而非最深焦点
Material SecurityAPI-native 工作区专业厂商希望获得更深控制的 Google Workspace 和 M365 企业攻陷后遏制、文件 / 账户上下文、调查速度最差异化用例窄于整个市场

画像强调采购动作和架构取舍,而不是绝对产品优越性。

[CP001, CP002, CP003, CP004, CP020, CP021]
FP001: 竞争定位图

架构和攻陷后覆盖广度是两个最重要差异化因素。

[CP001, CP004, CP007, CP020, CP022, CP023]

3.2 能力对比:Material 最强处与既有厂商仍胜处

Material 最强的公开差异化不只是威胁检测。其产品和对比页面强调账户接管遏制、文件暴露控制、高风险应用和 OAuth 可见性,以及快速跨工作区调查。这是比仅收件箱过滤更广的承诺。Abnormal 是 BEC 和 ATO 行为检测上最接近的纯专业竞品,尤其适合希望在 Microsoft 365 或 Google Workspace 上快速 API 部署的买方。Proofpoint 在大型受监管企业中仍更难替换,这些企业看重深度沙箱、URL 重写和广泛合规生态。Mimecast 在归档和连续性成为重心时仍最强。结果是,Material 并非在每个工作流里都显然“更好”;当买方关心钓鱼落地后会发生什么,以及安全团队能否在不做重型网关迁移的情况下跨邮件、文件和账户遏制爆炸半径时,它最具差异化。[CP007, CP008, CP009, CP014, CP022, CP023]

功能 / 能力矩阵
采购标准MaterialAbnormalProofpointMimecast原生套件
BEC 与冒充检测强,具备投递后和跨表面上下文最强的纯行为型竞品好,但更偏网关足够,但在纯文本 BEC 上较弱基线保护,因许可证而异
账户接管遏制检测强,更广工作区控制较弱附加 / 跨产品信号原生重点有限身份基线强,但专业深度不一
攻陷后的文件与数据主要以邮件为中心可通过更广安全栈获得相对重视程度有限原生控制存在,但可能缺少统一专业工作流
归档与连续性有限有限可用 / 附加核心优势原生连续性因套件而异
部署摩擦低 API 部署低 API 部署拥有 MX / 邮件流时较高视模式为高到中若买方接受仅原生,最低
跨工作区调查与自动化中等中等中等套件内较好,跨外部工具一致性较弱

公开来源支持方向性能力对比;它们不能替代实时 POC。

[CP004, CP007, CP008, CP009, CP014, CP022]
FP002: 运营后果地图

真正的竞争差异不只是功能是否存在,而是每种架构把哪些运营问题留给安全团队。

[CP005, CP006, CP010, CP011, CP026, CP027]

3.3 定价、切换成本与多宿主动态

这个市场的竞争经济性受切换成本影响,不亚于受头部功能清单影响。网关既有厂商运营重量更高,因为它们要求 MX 修改、政策调优和邮件流所有权。API 覆盖层试用更轻,也更容易叠加在既有栈上。这很重要,因为许多买方不会做干净的替换决策。独立比较工作明确建议,在网关之上叠加 ICES 产品来处理 BEC 和账户接管,而不是把选择视为二选一。这一动态通过降低初始销售摩擦利好 Material,但如果客户保留 Proofpoint 或 Mimecast 来满足传统优势,钱包份额也可能扩张更慢。定价透明度同样较差:部分既有套件有公开方向性区间,但 Material 和 Abnormal 基本仍由报价驱动。因此,买方评估 ROI 时会高度关注部署速度、分析师时间节省和第二天使用体验。这就是为什么尽调不应只测试检测率,也要测试采购便利性、迁移工作量、与传统网关共存,以及新工具多快能在日常运营中变得不可或缺。[CP005, CP006, CP026, CP027, CP028, CP029]

定价 / 包装对比
供应商公开定价信号包装模式切换成本含义
Material Security报价制;未找到公开标价专业平台 / 覆盖层低到中易于试点,但标价基准更难比较
Abnormal AI报价制;未找到公开标价专业 API 覆盖层低到中围绕价值实现速度和 BEC 结果竞争
Proofpoint据报高端套件方向性区间约为每用户每月 ~$6-$10以网关为中心的套件当合规、沙箱和广度重要时常可被证明合理
Mimecast据报按层级每用户每月方向性区间约 ~$3-$8网关 / 归档 / 连续性套件若归档和连续性已是必需,可能显得高效
原生套件通常嵌入更广生产力 / 安全许可证与套件层级捆绑很低抬高专业厂商必须越过的增量支出门槛

公开价格点是独立比较工作的方向性大致区间;真实企业定价需要谈判。

[CP026, CP028, CP029, CP030, CP037]
FP003: 护城河 / 就绪度 KPI

当买方看重工作区深度和运营杠杆时,Material 得分最高,但捆绑压力仍然真实。

[CP016, CP018, CP019, CP026, CP027, CP032]

3.4 护城河耐久性与投资逻辑可能破裂之处

Material 的护城河可信但有条件。当客户看重 Google Workspace 深度、多表面调查、攻陷后遏制和减少分诊时间的自动化时,护城河增强。若 Microsoft、Google、Proofpoint 或其他套件供应商在修复、行为检测和数据防泄露工作流上足够快地缩小差距,使专业覆盖层变成可选项,护城河会减弱。Proofpoint 的 Tessian 集成很重要,因为它显示既有厂商没有在行为和意外数据泄露功能上停滞。原生套件压力也重要,因为生产力平台已经拥有底层身份、数据和事件流。公开评价显示 Material 客户喜欢该产品,但外部证据库在真实头对头胜率和长期替换成功上仍薄。因此,竞争逻辑取决于 Material 能否继续把架构优势转化为更好的工作流结果,而不只是更好的幻灯片。[CP012, CP013, CP015, CP016, CP018, CP019]

护城河耐久性 / 竞争风险登记表
护城河或风险威胁严重性重要性缓释 / 尽调要求
Google Workspace 深度Google 原生改进Material 最强的差异化表面也正是 Google 可直接改进的地方验证原生工具仍缺少的工作流深度
攻陷后控制既有厂商加入类似修复和 DLPProofpoint + Tessian 和更广套件可能缩小差距测试 Material 响应工作流是否仍显著更快
低摩擦 API 部署多宿主减慢完全替换轻松试点有助销售,但可能限制钱包份额衡量试点用例之外的落地扩张成效
评价情绪公开胜率证据薄强评分不能证明头对头替换索要竞争 bake-off 结果和续约队列
避开网关客户仍需要连续性 / 归档 / DMARC 深度一些账户会无限期保留网关澄清 Material 是补充还是替换既有栈

风险登记表讨论差异化耐久性,而不是产品是否有效。

[CP012, CP013, CP020, CP021, CP027, CP031]

3.5 图表

Chapter 04

04财务情况

4.1 收入模式与变现表面

Material 的公开触点都指向企业 SaaS 收入模式,但远没有给出投资者理想中需要的数字。公司作为面向 Google Workspace 和 Microsoft 365 的云工作区安全平台销售,通过演示、直销,以及 Google Cloud Marketplace 和 Microsoft Marketplace 等合作伙伴渠道完成采购。这种组合强烈暗示经常性订阅收入,而不是项目驱动、硬件或服务较重的模式。产品横跨邮件、文件、账户和工作流自动化,也意味着账户内有扩张空间,而不是单次一次性席位销售。缺失的是实际商业细节:没有公开价格表、没有合同价值区间、没有披露服务组合,也没有拆分多少收入来自初始落地、多少来自后续扩张。因此,正确解读不是模式不清楚;而是尽管平台结构相当易读,经济细节仍是私有信息。[CI001, CI002, CI003, CI004, CI011, CI012]

收入来源表
来源机制单位当前价值 / 状态质量尽调要求
核心平台订阅面向 Google Workspace / M365 账户销售的工作区安全软件可能按邮箱 / 用户 / 租户签约经常性,但未披露存在性置信度高;单位定价置信度低索要合同模板和价格手册
扩展模块 / 工作流文件、账户、姿态、调查和自动化表面可能是附加组件或捆绑平台扩展产品广度可见;经济性未披露索要模块附加率和扩张历史
合作伙伴 / Marketplace 影响的销售Google Cloud Marketplace 和 Microsoft Marketplace 路径采购渠道而非单独产品存在量化来源 pipeline 和 marketplace 转化
专业服务 / 上线实施和客户成功支持相对软件可能较小未公开拆分询问服务收入占比和利润率
培训 / 响应效率价值人力节省嵌入软件 ROI,不是单独收入线N/A经济价值清晰;变现路径不清测试定价是否捕获已实现 ROI

公开来源清楚支持软件平台模式,但不支持准确收入组合或定价单位。

[CI001, CI002, CI011, CI012, CI023, CI024]
定价 / 变现表
供应商 / 路径价格 / 单位 / 合同模式标价与实现价格未知项来源
Material Security报价制企业合同标价不公开席位基础、最低额、期限长度、折扣公司页面 + 评价网站
Abnormal / 同类 ICES 基准报价制企业合同不公开仅可作方向性可比独立比较工作
Proofpoint 高端套件据报 ~$6-$10 / 用户 / 月仅方向性实际企业套件需谈判独立比较工作
Mimecast据报按层级 ~$3-$8 / 用户 / 月仅方向性套件范围不一独立比较工作
Google / Microsoft 采购渠道Marketplace / 既有承诺路径可通过合作伙伴支出抵消现金支出Material 的净经济性未披露Google 合作伙伴 + Microsoft marketplace

方向性价格参照是基准辅助,不是 Material 的实际报价。

[CI003, CI004, CI012, CI022]
FI001: 收入模式桥

公开证据支持经常性企业软件模式,但不支持其下准确经济性拆分。

[CI001, CI002, CI011, CI012, CI022, CI023]

4.2 GTM 动作与单位经济性代理

因为 Material 不发布 CAC、回本周期或利润率数据,投资者只能使用客户结果代理指标。最清晰的公开证据是,产品似乎被设计来减少分析师时间、降低部署摩擦,并通过阻止或遏制昂贵事件来保住价值。Headway 明确偏好基于 API 的部署,因为它避开了网关式设置痛点;客户和用例页面则提到钓鱼分诊自动化、更快搜索,以及过去需要数天或数小时的工作流现在达到秒级响应。这些不是经审计的单位经济性指标,但有经济意义,因为它们描述了更低上线成本、更快价值实现和节省人力的自动化。客户名单也暗示企业级合同潜力,即便 ACV 未披露。重要局限是,所有这些仍是贴近营销的证据。它支持健康软件经济性的可信故事,但不能替代关于胜率、扩张、折扣或续约效率的直接数据。[CI013, CI014, CI015, CI016, CI017, CI018]

单位经济性表
代理指标数值 / 状态置信度重要性尽调要求
部署摩擦相比网关,基于 API 的摩擦低暗示实施成本较低,价值实现更快索要平均上线小时数和服务支出
分诊人力节省客户材料记录从小时到秒、或天到秒的说法支撑 ROI 和潜在回本索要量化的前后分析师工时数据
客户质量可见蓝筹企业 logo支撑高 ACV 潜力索要 ACV 分布和头部账户规模
扩张空间邮件 + 文件 + 账户 + 工作流支撑落地扩张经济性索要附加率和队列扩张数据
留存可见度不公开收入质量的重大缺口索要按队列的总留存和净留存

由于未披露直接 CAC、回本周期、NRR 和毛利率数据,本表使用公开代理指标。

[CI013, CI014, CI015, CI016, CI017, CI018]
FI002: 商业证明链

差异化在于部署速度和工作流节省如何可信地转化为便于扩张的企业软件经济性。

[CI013, CI014, CI015, CI017, CI019, CI021]

4.3 资本充足性与公开披露缺口

Material 的历史资本形成足够清晰:2021 年 Series B 融资 $40 million,2022 年 Series C 融资 $100 million,并在该轮后官方披露累计 $166 million。管理层称这些资金将支持销售、产品、国际和政府扩张。不清楚的是当前资产负债表状态。公开来源没有提供现金、烧钱、现金跑道、债务或当前融资依赖。因此,即使公司很可能带着有意义的现金垫进入 2023 年,也无法直接从公开证据承销资本充足性。更大的承销问题是时间:最后确认的估值锚点已经过去数年,仍没有公开经营披露显示独角兽轮次后效率或规模发生了什么。在这种情况下,公司可能仍保持商业健康,但投资者不能负责任地假设如此。缺少新的收入质量证据本身就是重要财务事实。[CI005, CI006, CI007, CI008, CI009, CI010]

资本充足性表
项目公开数值 / 状态置信度重要性尽调要求
Series B 资本融资 40 USD M;当时累计 62 USD M显示独角兽前的资产负债表支持确认准确净融资额和截至 2022 年的支出
Series C 资本估值 1.1 USD B 融资 100 USD M;累计 166 USD M最后一次硬资本和估值锚点索要最新现金余额和 2022 年后的资金使用
手头现金未披露无法评估现金跑道索要月度现金桥
烧钱速度未披露无法评估融资依赖索要按职能的烧钱和招聘计划
债务 / 项目融资未发现公开披露可能影响下行保护确认债务、风投贷款和契约
下一轮触发因素公开未知融资风险的核心询问管理层哪些里程碑会触发融资

历史融资是公开的,但当前资本充足性并不公开。

[CI005, CI006, CI007, CI008, CI026, CI036]
公开财务缺口表
缺失指标对承销的影响重要性准确尽调路径
当前 ARR / 收入需要检验 2022 年估值是否仍有意义索要当前 ARR、GAAP 收入和 YoY 增长
毛利率需要评估软件质量和服务拖累索要托管、支持和服务成本结构
NRR / GRR / 流失需要测试落地扩张动作的耐久性索要队列留存和续约分析
现金 / 烧钱 / 现金跑道需要评估融资依赖索要现金余额和月度烧钱桥
客户集中度需要评估头部账户依赖索要 top-10 客户收入占比
折扣与销售效率需要评估回本和竞争压力索要 CAC、回本周期、配额达成率和折扣中位数

公开财务不透明本身就是尽调发现,因为它阻断了高效估值工作。

[CI009, CI010, CI025, CI026, CI037, CI038]
FI003: 财务估算区间

公开证据支持资本历史,但不支持投资者真正需要的当前经营区间。

[CI005, CI006, CI009, CI010, CI026, CI037]

4.4 公开基准背景与最终财务判断

最干净的外部基准不是成熟公开安全同类的绝对规模,而是它们的披露行为。Microsoft、CrowdStrike、Zscaler 和 Okta 都维护当前 SEC 文件页面,公开市值来源显示,一旦收入质量、增长和耐久性变得可见,市场对安全软件估值的跨度极大。这不意味着今天应把 Material 在绝对估值上直接对比这些公司。它意味着承销下一步很明显:投资者需要公开可比公司提供的那种经营透明度,即使这些透明度只在尽调中提供,而不在公开市场披露。公开客户证明和产品动能暗示业务可能有吸引力的软件经济性,但现有证据库无法让外部人士确认利润率结构、留存或现金充足性。因此,正确财务结论是谨慎而非负面:模式纸面上有吸引力,但在管理层分享连接收入、效率和估值的当前指标前,承销案例仍不完整。[CI027, CI028, CI029, CI030, CI031, CI032]

FI004: 资本强度 / 现金流地图

Material 看起来是资产轻的软件业务,但外部投资者仍缺少评估现金充足性所需披露。

[CI005, CI006, CI007, CI008, CI026, CI035]

4.5 图表

Chapter 05

05产品与技术

5.1 架构与当前产品范围

Material 的公开产品故事连贯且技术上有辨识度。公司没有把自己描述成狭窄安全邮件网关或单点钓鱼过滤器,而是把平台定位为跨 Google Workspace 和 Microsoft 365 的云工作区安全层,覆盖邮件、文件、账户、姿态和运营工作流。架构很重要,因为 Material 反复强调基于 API 的集成,而不是 MX 记录修改或新的邮件路由瓶颈。这一选择意味着更容易与现有协作套件共存、部署摩擦更低,并能在消息投递后作用于数据和身份。结果是,产品边界看起来比传统邮件安全更宽,但仍锚定邮箱和工作区,而非整个企业安全栈。这种更宽但仍聚焦的范围很重要,因为它暗示 Material 想占住协作安全中一个可防守切片,而不是假装替代 SOC 栈的其余部分。独立合作伙伴和媒体材料也强化了低摩擦部署叙事。[CE001, CE002, CE003, CE004, CE005, CE039]

表面覆盖表
表面当前公开能力证据强度关键备注
邮件投递后钓鱼检测和修复核心产品锚点
文件 / Drive敏感数据分类、共享风险映射、修复重要扩张表面
账户 / 身份ATO 检测、step-up 控制、特权风险信号描述较广,但未充分量化
OAuth / 第三方应用持续应用风险审查和 token 撤销2026 年新差异化点
调查 / 运营跨租户搜索、时间线、集成、路由面向运营者的生产力楔子

Material 的公开范围宽于仅收件箱过滤,但仍以协作套件安全为中心。

[CE001, CE005, CE006, CE007, CE008, CE010]
架构表
设计选择Material 的说法含义对比
API 集成无需修改 MX 记录;通过工作区 API 连接快速设置并可共存不同于网关切换
保留邮件流保持既有路由降低上线期间运营风险避免瓶颈迁移
跨表面数据模型邮件 + Drive + 账户 + 日历支持攻陷后定界宽于仅收件箱
Marketplace 可用性Google 和 Microsoft 渠道采购杠杆不是性能证明
单租户选项可用于要求高的环境面向严格买方的隔离选项对受监管账户重要

技术架构和商业架构都支持在不扰动基础设施的情况下采用。

[CE002, CE003, CE004, CE020, CE021, CE026]
FE001: 平台范围地图

Material 的范围从邮件延伸到周边云工作区攻击面。

[CE001, CE005, CE007, CE008, CE010, CE016]

5.2 检测、数据保护与响应机制

Material 技术逻辑最强的部分,是试图补上仅收件箱防御留下的缺口。公司声称用额外认证保护历史敏感邮件,持续分类并修复高风险文件共享状态,使用跨表面信号检测账户接管行为,并在可疑活动确认后自动化响应动作。近期发布把这一逻辑延伸到 Google Drive 爆炸半径时间线、日历事件清理和 OAuth token 治理。合在一起,这些能力指向一种围绕攻陷后遏制和降低管理工作量的设计哲学。在恶意内容仍会穿透原生防御、攻击者越来越瞄准身份、文件和第三方授权而不只是初始邮件本身的世界里,这在战略上合理。因此,产品看起来不像独立过滤器,更像云办公套件内部调查与修复的运营层。[CE006, CE007, CE008, CE009, CE010, CE011]

响应自动化表
工作流当前公开描述重要性来源
用户上报钓鱼分诊自动审查和处置减少分析师苦活公司页面
日历清理删除或恢复与钓鱼相关的事件补上非收件箱持久化缺口Feb 2026 更新
Drive 爆炸半径时间线映射事件前后访问 / 共享的文件更快完成范围和影响分析Feb 2026 更新
OAuth 修复评估新授权并撤销高风险 token应对现代 SaaS / AI 后门Apr 2026 更新
跨租户搜索从一个控制台搜索多个工作区调查速度与完整性用例页面

自动化是当前材料中最清晰的产品主题之一。

[CE010, CE011, CE012, CE016, CE017, CE036]
FE002: 攻陷后响应链

技术差异化在投递之后最强,此时身份、文件和 OAuth 上下文变得关键。

[CE008, CE009, CE010, CE011, CE012, CE013]

5.3 ML 信任、可解释性与运营化

Material 的公开材料在可解释性和信任上比平均水平更周到,尽管仍由供应商撰写。公司明确回应黑箱担忧,称会向分析师展示检测逻辑和影响映射,并概述以完整性、透明度、对齐和掌握度为核心的可信模型内部框架。这一框架会吸引需要自动化、但仍要向高管、审计员和终端用户解释行动的安全团队。同时,公开记录仍主要是定性材料。Material 解释了自己如何思考信任和运营,但没有发布关于模型 precision、recall 或误报的独立基准数据。因此,产品技术结论是在设计成熟度和运营者同理心上偏正面,但仍需要围绕可衡量效果做尽调。这个缺口不会否定架构,但会把部分技术尽调负担牢牢放在实时演示、客户参考和私有指标上。[CE013, CE014, CE015, CE024, CE025, CE035]

ML / 信任表
主题公开证据强度剩余尽调要求
透明度描述了检测指标和影响映射查看实时分析师视图和决策日志
人类对齐使用客户反馈调优输出索要治理流程和覆盖控制
模型治理完整性 / 透明度 / 对齐 / 掌握框架索要内部测试节奏
合规姿态发布 SOC 2 Type 2 和政策集审查报告范围和例外
性能指标没有公开 precision / recall 基准索要独立验证或客户层面统计

Material 清楚解释了 AI 理念,但公开效果数字仍稀疏。

[CE013, CE014, CE015, CE024, CE025, CE035]
FE003: 信任与可解释性栈

Material 的公开 AI 姿态强调围绕系统为何行动的控制,而不只是检测到什么。

[CE013, CE014, CE015, CE024, CE025, CE035]

5.4 相比原生控制和传统网关的适配

Material 最好的公开定位,不是说 Google 或 Microsoft 缺少安全控制,而是说原生工具碎片化、运营更慢,并且在某些投递后和跨表面任务上更弱。同样,Material 面向安全邮件网关的卖点,聚焦运营简单性、更深响应和更广工作区覆盖,而不是声称投递前过滤已经过时。这是可信楔子,因为现代邮件主导攻击在原始消息落地后,常会变成身份误用、OAuth 滥用或敏感数据访问。公开客户故事通过强调比网关式工具更容易部署、覆盖更广,强化了这一架构论点。最大的细节是平台平衡:公司公开表面目前感觉更偏 Google,而不是 Microsoft,尽管 Microsoft 支持显然真实存在,并非愿景。实践中,这意味着产品似乎最适合云优先组织;它们既关心初始消息拦截,也同样关心运营速度和入侵后遏制。[CE018, CE019, CE020, CE021, CE022, CE026]

相比原生与 SEG 工具的适配
对比轴Material 定位最可信优势主要注意点
相比安全邮件网关API 模型,具备投递后和跨表面控制基础设施摩擦更低;攻陷后效用更强网关既有厂商在投递前过滤上仍强
相比 Google 原生在碎片化控制台之上提供统一视图和自动化节省运营者时间Google 已提供有意义的基线控制
相比 Microsoft 原生聚焦邮箱行为和入侵范围有助被攻陷账户定界公开深度看起来窄于 Google 叙事
面向受监管买方单租户和信任中心材料部署灵活性需要对数据处理做私下尽调
面向精简安全团队自动化和简单上线可能降低人力负担公开 ROI 仍多由供应商撰写

在公开论证中,Material 最清晰赢在运营简化和攻陷后深度。

[CE018, CE019, CE022, CE024, CE026, CE029]
FE004: 采用适配图

当团队需要低摩擦部署加深度投递后控制时,Material 最有吸引力。

[CE003, CE018, CE022, CE029, CE034, CE036]

5.5 图表

Chapter 06

06客户情况

6.1 今天公开使用 Material 的客户

作为私有网络安全供应商,Material 的客户证明异常可见。公司在客户页面、信任中心、案例研究和融资公告中点名了广泛品牌,包括公开公司、规模化私有科技公司、消费品牌和受监管组织。这并不意味着每个 logo 都是同等深度证据。有些只是 logo 或引用,另一些则是带实施细节和运营结果的案例研究。总体图景仍然有利:这不是一家躲在匿名推荐语后的供应商。投资者能看到真实的具名采用者基础,并可推断产品已越过早期设计伙伴阶段。最强证据集中在云优先企业和成长公司,它们关心在不依赖重型邮件路由变更的情况下保护 Google Workspace 或 Microsoft 365。Logo 广度也暗示 Material 已越过单一垂直利基,能够卖给多种对安全敏感的买方画像。[CU001, CU002, CU003, CU004, CU005, CU032]

具名客户证明表
客户证据类型行业 / 画像证明深度关键启示
OpenAI / Figma / Databricks / DoorDash / Lyft / MassMutual / Mars / Gusto 等客户客户页面 / 信任中心 logo 和引用规模化科技、保险、消费品牌Logo + 有限引用深度显示可识别品牌广度
PagerDuty完整案例研究公开 SaaS / 基础设施运营、合规和数据保护用途
Amplitude完整案例研究公开 SaaS / 分析用户驱动的投递后保护
Headway完整案例研究医疗敏感型初创公司Google Workspace + 敏感数据
Stake完整案例研究金融科技 / 投资Google Workspace + 治理 + UX
Chubb / Compass / Roblox / Brex融资公告引用保险 / 房产科技 / 游戏 / 金融科技Logo 级显示到 2022 年仍具参考价值
Lyft / Mars / Color / Gusto / Cabinetworks 等客户新案例研究交通 / 消费品牌 / 医疗 / HR SaaS / 制造将客户证明广度扩展到最初四个案例之外
Gopuff客户引用 + 2026 年现场讨论消费配送 / 重运营中等暗示客户愿意出现在更广运营讨论中

公开引用结合了深度案例研究和较轻的 logo 级证据。

[CU001, CU002, CU003, CU005, CU024, CU039]
细分与买方适配表
细分具名证据Material 适配原因置信度
医疗敏感型成长公司Headway保护敏感数据,并支持精简团队扩张
金融科技 / 受监管消费金融Stake、MassMutual、Brex结合钓鱼、治理和数据保护
公开 SaaS / 基础设施PagerDuty、Amplitude需要可扩展响应、可审计性和低摩擦上线
大型消费 / 企业品牌Mars、Lyft、DoorDash、Databricks支持跨平台调查和广泛风险降低
云优先、重度 Google Workspace 买方Headway、Stake、Mars 引用Google 深度在公开资料中特别可见
大型多平台企业Mars、Cabinetworks、Lyft支持 Google + Microsoft 大规模上线

最强的公开客户适配,是保护协作套件的云优先安全和 IT 团队。

[CU004, CU006, CU007, CU008, CU009, CU010]
FU001: 参考客户广度图

公开参考集中在可识别、对安全敏感、云优先的组织,而不是匿名 SMB logo。

[CU001, CU002, CU003, CU005, CU024, CU039]

6.2 案例研究中的用例与 ROI 模式

案例研究在客户购买 Material 做什么上高度一致。它们主要不是传统垃圾邮件减少,而是聚焦投递后钓鱼响应、保护敏感历史邮件、更广文件和 Drive 治理、身份控制、调查,以及减少分析师苦活。Headway、PagerDuty、Stake、Amplitude、Mars、Gopuff 和 Gusto 都把产品描述为一种在消息落地或账户已处于风险中之后压缩时间、扩大安全覆盖的工具。这个模式重要,因为它支撑公司更广平台叙事,并暗示客户支付的不只是检测质量,也包括运营杠杆。局限是,这些 ROI 表述是自选择且大多由公司撰写,因此只有方向性用途,不是审计级证明。跨行业可重复性正是客户证据比普通 logo 墙更重要的原因之一。[CU010, CU011, CU012, CU015, CU016, CU017]

客户结果表
客户 / 引用公开结果类别重要性
Mars搜索从数小时缩短到约 20 秒调查速度显示超越钓鱼过滤的价值
Gopuff6 分钟集成;问题从数天缩短到数秒速度 / 部署强运营价值故事
Gusto钓鱼分诊时间最多减少 91%自动化 ROI直接节省人力的说法
StakeMTTR 从数小时缩短到数秒运营效率高关注度 SOC 指标
Headway自动化用户报告、Drive 可见性、分诊减少覆盖 + 效率更广平台价值
Color几条消息的手工 20-30 分钟调查缩短到 2-5 分钟调查效率独立医疗风格证明

这些是公司撰写的 ROI 表述,应在参考客户访谈中验证。

[CU010, CU011, CU012, CU015, CU016, CU020]
FU002: 客户价值链

客户反复把价值链描述为:低摩擦上线带来更快响应,并在投递后提供更广控制。

[CU013, CU014, CU016, CU017, CU018, CU019]

6.3 实施摩擦与工作流嵌入

公开客户证明也暗示,Material 的部署模式是有意义的采用优势。Headway 明确偏好基于 API 的方式,因为它比网关更容易,并避免 DNS 变更。PagerDuty 描述了两分钟实施和低风险上线,评价来源则强调与现有邮件平台无缝集成。这些细节不能保证所有部署都轻松,但强烈说明客户为什么愿意试用并扩张产品:它似乎能解决棘手的云邮件和数据保护问题,而不要求基础设施手术。更重要的是,一旦部署,平台似乎会通过处理用户报告、审计、MFA 相关检查、文件权限和跨租户搜索嵌入日常工作。这类工作流粘性通常比分析师偶尔打开的狭窄告警工具更有价值。它也有助于解释为什么即使买方已经拥有大量原生工具,公司仍能赢单。[CU013, CU014, CU017, CU018, CU019, CU026]

实施与粘性表
信号公开证据含义置信度
API 部署Headway 相比网关更偏好该方式;无需 DNS 修改低摩擦试用和上线
快速上线PagerDuty 称实施大约花了两分钟支撑快速采用
工作流集成用户报告保护所有人;审计和 MFA 工作流被纳入嵌入日常工作流
评价网站适配提到无缝集成和低扰动支持易上线逻辑低到中
安全运营生态Panther 文档显示 webhook 事件流式传输到 SIEM对成熟 SOC 集成有用
规模化上线Lyft 一周触达约 ~8,000 名用户;Mars 试点约 ~20,000 个邮箱显示企业级上线可行性

采用故事结合了低设置成本和上线后的运营深度。

[CU013, CU014, CU017, CU018, CU026, CU027]
FU003: ROI 信号阶梯

最强的公开客户证明是速度和工作流改善,而不是经审计的财务节省。

[CU010, CU011, CU012, CU014, CU015, CU040]

6.4 客户证明结论与剩余盲点

客户章节以一个混合但正面的尽调观点收束。Material 显然在企业安全业务重要组织中有可信采用证明:公开 SaaS 公司、消费平台、金融和保险参与方、医疗敏感环境,以及可识别全球品牌。公司也似乎愿意让客户公开发声,这是可参考性的好信号。但投资者仍拿不到最终驱动价值的定量客户事实:没有总客户数、没有集中度披露、没有留存数据,也没有按细分的直接收入视图。因此,正确解读是客户质量好于客户可衡量性。这足以增强对产品市场适配的信心,但不能替代对账户经济性、续约行为或少数大型 logo 暴露的直接尽调。因此,客户质量应被视为优势,客户可衡量性应被视为剩余尽调任务。这个区分很重要,因为它能避免投资者把一组强 logo 过度解读为同样强的客户经济性证明。[CU021, CU022, CU023, CU024, CU025, CU033]

客户证据缺口表
缺失指标重要性公开状态尽调要求
总客户数显示采用广度和阶段不公开索要当前数量和活跃客户趋势
客户集中度需要判断头部 logo 依赖不公开索要 top-10 收入占比
留存 / 续约价值主张耐久性所需不公开索要 GRR / NRR 和队列续约
席位 / 邮箱规模需要解释 ACV 和扩张不公开索要部署规模分布
按平台的参考深度需要比较 Google 与 Microsoft 深度部分公开索要按供应商拆分的客户基础

客户故事在定性上有说服力,但定量上不完整。

[CU022, CU023, CU033, CU034, CU035, CU036]
FU004: 客户证明决策框架

当前客户证据足以支撑产品市场适配信心,但不足以精确定价账户经济性。

[CU021, CU022, CU023, CU024, CU025, CU033]

6.5 图表

Chapter 07

07风险

7.1 威胁环境与残余检测风险

Material 运营在企业软件中最具对抗性的角落之一。邮件、协作、身份和连接应用仍是持续目标,公开威胁证据显示攻击者一直在改变战术,而不是消失。Microsoft Q2 2026 数据仍显示数十亿钓鱼威胁、持续 BEC 活动、Teams 社交工程增长,以及日历邀请等载荷上升;这些载荷利用经典收件箱之外的可信协作表面。IC3、Proofpoint、Verizon 和 CISA 都指向同一方向:攻击者仍大量依赖人的行为、被盗凭据和低摩擦社交工程。对 Material 来说,成功永远不意味着完美预防。现实风险是,如果产品无法跟上演变中的工作流和威胁向量,会出现残余漏报率、误报和运营者疲劳。因此,投资者应把产品风险承销为一个移动靶问题,而不是一次性效果测试。[CR007, CR008, CR020, CR021, CR022, CR023]

按严重性排序的风险登记表
风险可能性影响缓释成熟度剩余暴露投资含义
Material 发生隐私 / 数据处理事件很高产品触及敏感历史数据,信任会很快受损
对 Google / Microsoft API 和政策的平台依赖中高可能压缩差异化,或要求快速工程调整
快速变化的钓鱼环境中残余漏报 / 误报风险中高直接影响客户信任和续约质量
围绕事件报告和隐私治理的监管升级提高合规成本和治理负担
原生或更大套件的捆绑压力中高中高可能削弱定价权或放慢新 logo 获取
财务指标不透明 / 估值锚点过时投资者仅靠公开数据无法准确定价下行

严重性排序结合概率与后果,而不是试图预测单一确定性结果。

[CR010, CR012, CR028, CR029, CR036, CR037]
FR001: 威胁压力链

风险从敌意威胁环境开始,即便工具改进,最终仍会落到剩余运营负担上。

[CR020, CR021, CR022, CR023, CR024, CR025]

7.2 隐私、平台与运营风险

核心运营风险与产品价值主张不可分割。Material 之所以能提供杠杆,正是因为它能跨云办公套件看见敏感历史邮件、文件权限、账户行为和相关遥测。同一访问能力也带来巨大下行:若供应商处理数据不当、遭遇入侵,或与客户隐私要求失去对齐,后果会很严重。隐私政策确认,公司会处理富含个人数据的内容,并可能在特定支持或响应情形中手工处理数据。公开记录也显示,公司集中在 Google Workspace 和 Microsoft 365 上,因此暴露于供应商 API 变化、limited-use 政策调整,以及平台所有者自身更广捆绑压力。Mars、Color 和 PagerDuty 等案例研究暗示公司在隐私架构和可审计性上思考周到,但也凸显一旦这些控制失效,代价会很高。换句话说,产品最强之处,也正是控制义务最严苛之处。合同层面的隐私对齐几乎与纯功能深度同等重要。[CR001, CR002, CR003, CR004, CR005, CR006]

隐私与数据处理风险表
风险领域公开证据重要性缓释因素 / 反向点尽调要求
敏感数据访问处理内容、权限、操作和设置任何事件都可能暴露极敏感材料处理方定位和客户控制审查架构、访问日志和最小权限控制
手工处理支持和响应可能需要手工处理人的流程成为控制面的一部分列明情形之外需请求同意索要 SOP、审批和 break-glass 控制
美国数据位置政策称数据中心在美国跨境和数据主权要求可能重要Mars 在实践中提到区域选项按层级澄清区域托管可用性
子处理方政策将客户指向专门的子处理方页面第三方延长供应商风险链标准 SaaS 现实审查子处理方地图和监控
删除 / 留存终止后 30 天删除,但有例外对退出和受监管留存重要清晰表述生命周期有帮助验证删除证据和法律保留处理

让 Material 有价值的同一组功能,也提高了内部控制失效的代价。

[CR001, CR002, CR003, CR004, CR005, CR015]
平台与依赖风险表
依赖公开证据风险缓释信号剩余担忧
Google Workspace深度供应商页面和客户证明API / 政策依赖和捆绑风险产品深度和客户适配强公开组合看起来偏 Google
Microsoft 365供应商页面加 Mars / Cabinetworks 证明需要维持功能对等和参考深度真实混合平台部署存在公开证明仍薄于 Google
客户 SOC 工具Panther 集成和 webhooks事件 schema 稳定性和合作伙伴协调重要外部集成显示成熟度集成 bug 可能向外扩散
身份 / OAuth 生态OAuth agent 和 AI 采用材料第三方应用和 bot 扩大攻击面Material 正在为此构建控制威胁节奏可能跑赢政策
原生安全基线Google 和 Microsoft 安全功能持续改进足够好的原生工具可能缩小楔子Material 聚焦投递后和工作流深度需要证明楔子保持耐久

依赖风险具有战略性,不只是技术问题:平台供应商既能赋能产品,也能压缩产品空间。

[CR009, CR010, CR011, CR012, CR013, CR014]
FR002: 数据敏感性风险图

Material 的价值和隐私风险来自同一条进入客户数据的底层访问路径。

[CR001, CR002, CR003, CR004, CR017, CR018]
FR003: 依赖风险矩阵

公开记录显示,最关键核心平台关系上的依赖和差异化并不均衡。

[CR009, CR010, CR013, CR014, CR019, CR020]

7.3 监管、治理与披露风险

Material 的客户基础和产品表面让它同时靠近多个趋严监管前线:隐私、AI 治理、事件报告、上市公司披露和跨境数据控制。Morgan Lewis 的 2026 年趋势报告强调,围绕文档、审计就绪、数据传输和事件升级的预期更强;Debevoise 和 DFIN 显示,网络安全披露实践仍活跃且仍有一定不确定。Google 和 Microsoft 也发布了大量法律、隐私和合规义务,企业客户希望其安全合作伙伴帮助满足,而不是让这些义务更复杂。这抬高了 Material 内部治理门槛。若公司未来上市,或重大客户事件迫使更广披露,投资者应预期审查对象不只是产品,也会包括公司自身决策、文档和控制成熟度。这会把尽调从产品审查抬升为治理审查。门槛越来越由正式框架设定,而不是非正式尽力而为。[CR029, CR030, CR031, CR032, CR033, CR034]

监管 / 法律风险登记表
领域当前公开信号对 Material 的风险受影响方尽调要求
事件报告CIRCIA 动能和 SEC 实践演变更快升级和文档预期Material + 企业客户审查事件 playbook 和客户沟通协议
隐私 / 跨境数据美国处理加上不断增加的传输审查数据位置错配或合同摩擦受监管 / 全球客户审查区域控制和 DPA 条款
AI 治理州级和国际规则趋严需要可解释性和人工治理纪律安全和法务买方审查模型治理委员会和测试材料
审计就绪客户需要 SOC 2、渗透测试、日志和可辩护流程控制缺口会造成商业成本销售、法务、客户成功审查审计例外和修复历史
上市公司披露未来 IPO 会引入更严格披露纪律治理缺口会变成资本市场风险投资者和董事会审查董事会报告、网络安全委员会结构和外部法律顾问准备
框架成熟度NIST CSF 2.0 和 SP 800-61r3 更新指南提高对治理牵头响应的预期董事会、安全、法务审查决策权和桌面演练计划

即便在 IPO 前,治理风险也重要,因为受监管客户越来越要求供应商具备上市公司级成熟度。

[CR006, CR029, CR030, CR031, CR032, CR033]

7.4 财务、依赖与投资逻辑破裂风险

最后一层风险是经济性的,而不只是技术性的。Material 在一个拥挤环境中竞争,云平台、安全邮件网关和专业供应商都在不同程度上重叠。公司差异化在买方需要投递后控制、历史数据保护和工作流自动化时看起来最强,但如果原生供应商或捆绑套件对一部分有意义账户而言已经足够好,这一优势可能缩窄。同时,公司在 ARR、烧钱、留存和集中度上仍保持私有不透明,因此投资者无法把战略风险和简单信息风险完全分开。因此,2022 年独角兽估值应被视为过时历史锚点,而不是今天下行有限的证据。正确风险结论是,Material 看起来具备战略相关性,但仍需要私下尽调,证明其敏感性高的架构、平台依赖和不完整披露不会压过产品优势。这也意味着,干净的技术演示本身并不够。[CR013, CR014, CR036, CR037, CR038, CR039]

缓释因素与投资逻辑破裂触发器表
项目今日公开信号有利 / 不利原因观察指标
单租户 / 隔离部署选项Mars 故事中可见可降低爆炸半径,并缓解隐私审批更多参考客户将隔离列为决定性因素
强调可解释性ML 信任和更深上下文材料可降低黑箱异议关于误报处理的独立证据
工作流自动化用户报告和分诊材料提升粘性和 ROI超越 Google 重度故事的客户参考
捆绑威胁原生平台控制持续改进可能降低付费意愿原生工具被替换的客户胜利
估值不透明没有当前公开 ARR / 留存 / 烧钱阻碍清晰下行承销任何新融资、董事会或指标披露

若买方不再需要 Material 的增量深度,或 Material 自身成为隐私控制责任,投资逻辑会最快破裂。

[CR015, CR039, CR040, CR041, CR042, CR046]
FR004: 风险结论桥

只有技术优势持续跑赢隐私、平台和披露弱点,投资逻辑才站得住。

[CR036, CR037, CR038, CR039, CR040, CR041]

7.5 图表

Chapter 08

08估值

8.1 当前融资背景,以及公开记录真正能支持什么

Material 的公开估值记录有一个异常清晰的锚点,之后却令人沮丧地不透明。清晰的部分是 2022 年 5 月的 Series C:融资 $100 million,估值 $1.1 billion,累计披露融资 $166 million。不透明的是投资者现在判断 2026 年独角兽估值是否仍成立所需的一切。公开资料没有 ARR、增长率、留存数据、烧钱披露,也没有客户集中度视图。因此,上一轮融资是有效的历史锚点,但不是当前定价工具。任何严肃估值讨论都必须先承认,最重要的变量——公司当前经营表现——仍然是私有信息。仅这一点就应让入场讨论保持克制。成熟买家会把 2022 年估值当作尽调起点,而不是终点。[CV001, CV002, CV003, CV004, CV026]

当前融资与证据表
项目公开状态重要性支持程度
最后硬估值2022 年 5 月 Series C 为 1.1 USD B唯一干净的估值锚点
累计披露融资Series C 后为 166 USD M说明资本支持,但不是当前现金
当前 ARR / 收入不公开阻止直接倍数工作
留存 / NRR / GRR不公开阻止对溢价倍数的信心
烧钱 / 现金跑道不公开阻止下行规模判断

估值问题与其说缺少可比公司,不如说缺少公司特定经营表现数据。

[CV001, CV002, CV003, CV004, CV026]
FV001: 估值证据桥

给 Material 估值的难点不是寻找可比公司,而是从过时的 2022 年价格桥接到当前经营现实。

[CV001, CV002, CV003, CV004, CV026, CV030]

8.2 公开可比公司与交易背景

公开市场背景有利于强势网络安全资产,但市场并不照单全收。Windsor Drake 的 2026 年研究显示,按不同切片,公开网络安全公司的收入倍数中位数约为 6x 至 7.8x;若云、身份和 AI-native 领导者的 Rule-of-40 质量与平台地位清晰,定价会高得多。CrowdStrike、Zscaler、Palo Alto Networks、Microsoft、Okta 等公开市值可比公司提醒投资者:一旦收入质量和战略相关性可见,回报上限可以很高。Proofpoint、Mimecast 等交易参照也重要,但主要证明以邮件和人为中心的安全资产可以支撑大型战略价值。它们不能机械套用,因为这些交易发生在不同宏观环境和倍数体系下,披露面也更成熟。换句话说,市场给的是背景,不是答案。若一家私有公司不披露当前经营指标,这一点尤其成立。[CV005, CV006, CV007, CV008, CV009, CV010]

可比估值表
可比对象类型当前公开信号重要性局限
CrowdStrike公开可比公司市值 ~218.33 USD B显示顶级云安全执行的回报成熟得多,也宽得多
Zscaler公开可比公司市值 ~27.27 USD B有用的云安全倍数参照产品范围不同
Palo Alto Networks公开可比公司市值 ~296.54 USD B显示战略平台估值天花板规模大得多且多元化
Okta公开可比公司市值 ~26.00 USD B身份 / 访问相邻参照GTM 和类别组合不同
Microsoft生态锚点市值 ~3.712 USD T展示平台所有者力量过宽,不能作直接可比
Proofpoint / MimecastM&A 参考12.3 USD B 和 5.8 USD B 私有化交易证明邮件安全的战略价值时间较久、成熟、处于不同制度

这组对象最好用于框定区间和逻辑,而不是盲目平均成价格。

[CV011, CV012, CV013, CV014, CV015, CV017]
公开倍数框架表
子行业 / 制度指示性倍数Material 需要满足什么?当前公开支持
公开网络安全中位数6.0x–7.8x 收入增长扎实且类别位置可信存在行业支持
云 / 身份 / SASE 领导者14x–22x 收入强增长、留存、平台价值、Rule-of-40 质量目前公开无法证明
AI-native 私有安全平台20x–30x 收入具体 AI 生产力收益加上强指标战略叙事存在,指标缺失
传统网络 / 成熟安全3x–8x 收入增长较慢或差异化较弱若 Material 指标良好则过于苛刻
过时融资锚点2022 年 1.1 USD B 估值只是一个历史点无法替代 2026 年指标

Material 的可能公允区间更取决于私有经营质量,而不是类别标签。

[CV005, CV006, CV007, CV008, CV009, CV021]
FV002: 可比披露矩阵

公开可比公司有大量披露,而 Material 当前几乎不提供同类财务细节。

[CV011, CV012, CV013, CV015, CV016, CV033]

8.3 Material 为什么可能享有溢价——以及为什么仍可能不配

Material 不只是旧式邮件网关,这会影响估值。产品现在覆盖 Google Workspace 和 Microsoft 365 上的邮件、文件、账户、OAuth 风险和工作流自动化。作为私有安全公司,Material 的客户证明较强,路线图也落在云、身份相邻工作流、AI 治理、投递后控制等仍能吸引估值溢价的领域。但关键限定是:必须有指标支撑。折价因素同样明显。投资者仍面对私有公司不透明、对 Google 和 Microsoft 平台的依赖、原生套件捆绑风险,以及没有公开证据证明增长、留存或利润率足以支撑前四分位网络安全倍数。因此,溢价故事合理但未证实。投资者应把溢价叙事视为还需要数字验证的假设。在此之前,举证责任在管理层,不在市场。[CV020, CV021, CV022, CV023, CV024, CV025]

溢价与折价因素表
因素支持溢价?原因当前公开置信度
宽广的云工作区平台范围比传统邮件过滤器更像平台
具名客户质量暗示企业相关性和参考价值
AI / OAuth / 工作流路线图契合高溢价网络安全叙事
当前 ARR / 留存不透明无法验证倍数质量
Google / Microsoft 依赖原生捆绑和政策风险仍在
上一轮估值过时旧价格可能高估当前经济性

溢价逻辑在概念上合理,但证据不足。

[CV020, CV021, CV022, CV023, CV024, CV025]
FV003: 战略价值图

Material 更接近高端云工作区安全逻辑,而不是传统网关逻辑,但证明缺口仍很大。

[CV019, CV020, CV021, CV022, CV023, CV024]

8.4 估值立场、情景与尽调门槛

基于公开证据,正确立场是有纪律地保持兴趣,并严格控制入场条件。若管理层能私下证明高端云安全经济性——高增长、强留存、有吸引力的毛利率,以及可支撑持续定价权的运营 ROI——乐观情景存在。若公司在这些维度扎实但不顶尖,基准情景成立,只能相对行业中位数给适度溢价。若原生套件缩小楔子,或财务数据暴露增长更慢、留存更弱、融资压力大于 2022 年估值暗示,悲观情景存在。公开记录无法裁决这些路径,投资者不应提前为乐观情景买单。因此,正确估值结论是有条件推进:继续尽调,但在接受溢价估值前,要求新数据或价格保护。喜欢公司和喜欢价格之间有实质差别。好公司在错误入场价下仍可能是坏投资。这就是此处的核心估值纪律。[CV027, CV028, CV029, CV030, CV031, CV032]

估值立场与尽调门槛表
情景 / 门槛今日公开解读私下必须成立的事实含义
乐观情景可能存在但未证实高增长、强 NRR、强利润率、扩张深度可能支撑网络安全溢价倍数
基准情景从公开证据看最可能指标好但不顶尖相对中位数有一定溢价;不是前十分位价格
悲观情景若楔子缩小或指标令人失望,则真实存在原生工具改进,或增长 / 留存走弱相对过时独角兽预期折价
入场纪律必不可少管理层必须打开账本不要提前为乐观情景买单
最终尽调要求强制ARR、增长、烧钱、NRR、集中度、融资计划价格观点在交付前仍是有条件的

投资者应要求新证据,而不是争论抽象倍数哲学。

[CV027, CV028, CV029, CV030, CV031, CV032]
入场纪律清单
门槛公开状态重要性公开数据下通过 / 未通过
当前 ARR 和增长披露需要把公司放到收入倍数曲线上未通过
留存 / NRR 披露需要证明网络安全溢价倍数合理未通过
毛利率 / 烧钱披露需要衡量效率和现金跑道未通过
客户质量可见支撑战略相关性通过
类别可比公司可用支撑外部背景通过
今日可支撑溢价价格不能提前为乐观情景买单未通过

本表把章节转成实际投资门槛,而不是叙事摘要。

[CV003, CV004, CV022, CV030, CV031, CV036]
FV004: 情景决策 DAG

估值决策树由收入质量和楔子耐久性的私有证明驱动。

[CV027, CV028, CV029, CV030, CV031, CV032]

8.5 图表

免责声明

本报告是基于截至 2026-08-08 公开信息的 AI 辅助尽调摘要,不构成投资建议。Material Security 是财务披露有限的私有公司,因此若无直接尽调访问,重大定价、治理和经营表现细节仍然未知。

证据索引

结论
编号陈述可信度来源
CO001 Material Security was founded in 2017. SO001, SO005, SO018
CO002 Material Security is headquartered in Redwood City, California. SO001, SO005, SO018
CO003 Material Security sells security for Google Workspace and Microsoft 365. SO002, SO003
CO004 The current platform bundles email, file, and account security into one workspace-security product. SO002, SO003
CO005 Ryan Noon co-founded Material Security and serves as chairman on the current leadership page. SO001, SO015
CO006 Abhishek Agrawal co-founded Material Security and is the company’s current CEO. SO001, SO004
CO007 Chris Park co-founded Material Security and is the current VP of Engineering. SO001, SO004
CO008 The founding team’s prior experience spans Dropbox, Parastructure, Google, and Microsoft Research. SO001, SO004, SO010
CO009 The current public record implies a founder-role transition from Ryan Noon as earlier CEO to Abhishek Agrawal as current CEO and Noon as chairman. SO001, SO005
CO010 Material’s visible executive bench also includes leaders for product, finance, sales, people operations, security, and marketing. SO001
CO011 Material says it protects fast-growing companies including OpenAI, Figma, Mars, Lyft, and MassMutual. SO001
CO012 Material Security raised a $100 million Series C in May 2022 at a $1.1 billion valuation. SO005, SO006, SO007, SO008
CO013 Founders Fund led the Series C and Andreessen Horowitz plus Elad Gil participated. SO005, SO006
CO014 Company and media sources peg total funding after Series C at $166 million. SO005, SO006, SO007
CO015 Management said Series C proceeds would expand sales and marketing, government footprint, international reach, and adjacent product scope. SO005, SO007
CO016 Material raised a $40 million Series B in May 2021 and said total funding then reached $62 million. SO011, SO012, SO013
CO017 The Series B was led by Elad Gil with participation from Andreessen Horowitz and other security-industry investors. SO011, SO012
CO018 By the Series B announcement, Material already marketed visibility and control, leak prevention, account-takeover prevention, and phishing herd immunity. SO012
CO019 Andreessen Horowitz publicly backed Material Security in 2020 and framed the company around protecting data after attackers reach the inbox. SO014
CO020 First Round reports that the founders started the company in 2017, sold early access before building, and emerged from stealth in 2020. SO010
CO021 First Round says the founders had six early-access opt-ins before building the first version in 2018. SO010
CO022 Current public materials show the company remained active into 2026 through new resource posts, customer stories, and product-update pages. SO019, SO020, SO021
CO023 The April 2026 update introduced an OAuth Remediation Agent and a rebuilt integrations experience. SO021
CO024 The current customers page names Gusto, Gopuff, Lyft, Dotmatics, Figma, Headway, HackerOne, Asurion, Instabase, Mariner Wealth Advisors, and Quora. SO019
CO025 Material describes itself as built in partnership with Google and says it holds Google Cloud Premier Partner status. SO022
CO026 Material says customers can buy through Google Cloud Marketplace and can deploy on a dedicated Google Cloud project. SO022
CO027 Microsoft’s marketplace listing describes Material as a unified suite spanning cloud email security, user-behavior analytics, posture management, and data-loss prevention for Office 365. SO023
CO028 The Microsoft marketplace listing also highlights smart data classification, access controls, and shadow-IT insight for Office 365. SO023
CO029 Craft lists Material as a private, active cybersecurity company founded in 2017 with Redwood City headquarters. SO018
CO030 Craft reports roughly $162 million total funding, below the $166 million total the company announced after Series C. SO018
CO031 First Round says the company initially operated under the code name Stellarite until June 2020. SO010
CO032 Material’s origin story consistently ties back to the 2016 election-hack wave and a thesis of protecting data after compromise. SO004, SO005, SO010
CO033 Current homepage and product messaging position Material against fragmented point solutions and legacy email-only controls. SO002, SO003
CO034 Public surfaces indicate an enterprise SaaS model that is sold through demos, partnerships, and marketplace procurement rather than transparent self-serve pricing. SO002, SO003, SO022, SO023
CO035 The visible funding history, blue-chip customer logos, and current partner surfaces support classifying Material as a late-stage private cybersecurity company. SO005, SO012, SO019, SO022
CO036 Material publicly emphasizes resilience and post-compromise damage limitation instead of perimeter-only blocking. SO002, SO005
CO037 The public source set reviewed does not disclose current board composition or control-rights detail after the Series C. SO001, SO005, SO010
CO038 Ryan Noon remains a public face of the company in interviews and founder-story content even after the role transition. SO004, SO015, SO016
CO039 Material’s customer references span regulated and high-growth sectors including finance, healthcare, software, logistics, and consumer platforms. SO019, SO005
CO040 Independent 2026 legal analysis shows privacy and cybersecurity enforcement pressure is intensifying for vendors handling sensitive enterprise data. SO025
CO041 Material says it is the only threat-detection-and-response platform built in partnership with Google. SO022
CO042 Independent founder-story coverage frames Material as broader cloud-workspace security rather than an inbox-only filter. SO017, SO010
CM001 Fortune Business Insights sizes the email-security market at $6.06 billion in 2026 and $14.44 billion by 2034. SM010
CM002 The same Fortune source says the market was $5.46 billion in 2025, implying roughly 11.5% CAGR from 2026 through 2034. SM010
CM003 Fortune says the cloud-based segment held 78.6% of the email-security market in 2025. SM010
CM004 Mordor Intelligence estimates the cloud-based email-security software market at $6.24 billion in 2026, up from $5.55 billion in 2025. SM011
CM005 Mordor projects the cloud-based market to reach $11.22 billion by 2031 at 12.45% CAGR. SM011
CM006 The 2025 IC3 report logged 24,768 business-email-compromise complaints and $3.046 billion of associated losses. SM001
CM007 IC3 recorded 191,561 phishing/spoofing complaints in 2025, making it one of the highest-volume cybercrime categories. SM001
CM008 Microsoft says it detected about 7.6 billion email-based phishing threats in Q2 2026. SM009
CM009 Microsoft reported nearly 9 million BEC attacks in April 2026 before volumes normalized in May and June. SM009
CM010 Microsoft observed a June 2026 automated BEC campaign that reached more than 67,000 users across 42,000 organizations in under three hours. SM009
CM011 Microsoft reports that Teams-based social-engineering activity and vishing are growing quickly, showing that attacks increasingly expand beyond the inbox. SM009
CM012 The same Microsoft report says ICS calendar invitations remain a distinct malicious payload type, reinforcing the shift from email-only to workspace-wide attack chains. SM009
CM013 Proofpoint says more than 70% of employees admit to risky behavior that leaves them vulnerable to phishing. SM004
CM014 Fortune identifies phishing, ransomware, business email compromise, and account takeover as central growth drivers for email-security spend. SM010
CM015 Fortune says North America held 32.05% of the email-security market in 2025. SM010
CM016 Mordor says large enterprises accounted for 69.35% of cloud-based email-security revenue in 2025. SM011
CM017 Mordor says IT and telecommunications represented 31.05% of the cloud-based email-security market in 2025, with BFSI growing quickly behind it. SM011
CM018 Mordor says secure email gateways still held 54.95% of platform-integration revenue in 2025 even as integrated cloud email security is forecast to grow faster. SM011
CM019 Mordor says integrated cloud email security is forecast for 13.55% CAGR through 2031 as enterprises retire gateway-heavy architectures. SM011
CM020 Google Workspace positions security around threat prevention, zero-trust controls, privacy, and digital-sovereignty capabilities. SM005, SM007
CM021 Google highlights client-side encryption, Assured Controls, and compliance certifications as part of native Workspace buying criteria. SM005, SM007
CM022 Fortune says remote work and migration to Microsoft 365 and Google Workspace are major drivers of email-security demand. SM010
CM023 Fortune says SMEs face adoption friction from subscription costs, integration work, training, and limited security skills. SM010
CM024 Mordor flags the cybersecurity skills gap, latency and data-sovereignty complexity, and customer misconfigurations as real restraints on category adoption. SM011
CM025 Material’s own market framing argues that fragmented point products and legacy gateways leave gaps once threats move into files, identities, and connected apps. SM013, SM014
CM026 Material’s product pages place DLP, file-sharing control, and account hardening inside the same platform boundary as phishing defense. SM014, SM015
CM027 Material’s served market is narrower than the full email-security market because its core offer is built around enterprise Google Workspace and Microsoft 365 environments rather than every mailbox environment. SM014, SM016, SM025
CM028 Material’s Google-partnership page implies the company is competing for the premium layer that sits on top of native cloud-office controls, not replacing the entire productivity suite. SM016, SM025
CM029 The buyer for advanced cloud email security is usually a central security or IT team, while end users are employees and the economic rationale comes from fraud, compliance, and incident-response reduction. SM005, SM010, SM011
CM030 Regulated sectors such as finance, healthcare, government, and large technology enterprises face especially strong demand because email and workspace data carry direct compliance and fraud consequences. SM005, SM010, SM011
CM031 The market increasingly rewards platforms that combine threat detection, DLP, access controls, and automated remediation rather than pure inbox filtering. SM010, SM011, SM014
CM032 Native Microsoft and Google controls raise the baseline, but they also create space for specialists that add behavioral analytics, cross-surface investigation, and workflow automation. SM005, SM008, SM009, SM014
CM033 Windsor Drake’s 2026 cyber valuation work implies investors still reward high-growth security platforms, but only where category breadth and proof justify premium multiples. SM012
CM034 Because Material is enterprise- and workspace-centric, its true TAM is better approximated by the cloud-based enterprise slice than by the whole global email-security market. SM010, SM011, SM014
CM035 Mordor says 70% of enterprises are actively replacing secure email gateways with integrated cloud email security, directly supporting Material’s architectural wedge. SM011
CM036 Fortune says the market is broad enough to support multiple winners, but bundling by Microsoft and Google is a persistent constraint on specialist pricing power. SM005, SM010, SM021
CM037 Competitor pages from Proofpoint, Mimecast, Check Point, Cisco, Microsoft, and KnowBe4 show that buyers still compare specialist platforms against legacy gateways and native cloud suites. SM018, SM020, SM021, SM022, SM023, SM024
CM038 The category’s center of gravity is shifting from pure prevention to response and resilience because attackers now chain email, OAuth, calendars, chats, and files together. SM009, SM011, SM014
CM039 Material’s market case is strongest in large enterprises that already run Microsoft 365 or Google Workspace and need deeper controls without mail-flow rearchitecture. SM011, SM014, SM025
CM040 Contradictory sizing methodologies do not overturn the core thesis that cloud-native email and workspace security remains a double-digit-growth market. SM010, SM011
CP001 The most important competitive split is architecture: Proofpoint and Mimecast are gateway-style platforms, while Abnormal represents the API-based ICES model. SP002
CP002 Ciphers says Proofpoint suits large enterprises that want deep attachment sandboxing and automated remediation in one stack. SP002
CP003 Ciphers says Mimecast’s strongest wedge is combining gateway filtering with archiving and continuity. SP002
CP004 Ciphers says Abnormal is the strongest of the three for payloadless BEC and account takeover because it is built as behavioral AI rather than a gateway. SP002
CP005 Ciphers says API-based ICES deployment avoids MX-record changes and often produces detections within 24-48 hours. SP002
CP006 Ciphers says secure email gateways require mail rerouting through MX changes and add more operational weight than API overlays. SP002
CP007 Material’s own comparison page positions it as an API-based platform with the deepest Google Workspace coverage among the tools it benchmarks. SP001
CP008 Material’s comparison page says the product contains and remediates account-takeover risk rather than only detecting malicious messages. SP001, SP020
CP009 Material says its platform correlates email with what happens next in mailbox rules, Drive access, and downloads. SP001, SP021
CP010 Material says its automated user-report response can cut phishing triage by up to 91% at Gusto. SP001, SP024
CP011 Material says its depth is strongest in Google Workspace and that buyers wanting only a perimeter spam filter will not use the whole platform. SP001, SP023
CP012 Proofpoint’s Tessian page says Proofpoint combined its threat and data-loss stack with Tessian’s AI-powered behavioral and dynamic detection. SP011
CP013 That Proofpoint-Tessian combination increases competitive pressure on vendors that differentiate through behavioral detection and accidental-data-loss workflows. SP011, SP025
CP014 Material’s LP and product pages frame the company as broader than email-only tools by combining email security with file and account protection. SP012, SP013, SP021
CP015 Material’s use-case page says Google-native tools do not scale well enough for mature security programs, especially for posture and response workflows. SP014
CP016 Material’s investigation use-case page says searches that used to take hours can take seconds across multiple cloud workspaces. SP015
CP017 TrustRadius describes Material as a visibility, defense-in-depth, and security infrastructure layer for Microsoft 365 and Google Workspace. SP016
CP018 PeerSpot shows Material carrying a 4.8 rating distribution on its review page. SP017
CP019 Gartner Peer Insights also shows Material carrying strong customer-review scores in 2026. SP018
CP020 Native Microsoft Defender is a serious substitute in Microsoft-centric accounts because it is already embedded in the productivity suite and extends into XDR workflows. SP007, SP022
CP021 Native Google Workspace security is a serious substitute at the baseline layer because it already bundles threat prevention, compliance, and sovereignty controls. SP019, SP023
CP022 Proofpoint remains strongest where attachment sandboxing, URL rewriting, and large-enterprise compliance depth matter more than workspace-native post-compromise controls. SP002, SP004
CP023 Mimecast remains strongest where archiving and continuity are hard requirements, not where a buyer mainly wants cross-workspace account and file controls. SP002, SP005
CP024 Abnormal remains the closest pure-play rival when buyers prioritize behavioral detection for BEC and account takeover on Microsoft 365 or Google Workspace. SP002, SP006
CP025 Check Point, Cisco, KnowBe4, and Microsoft expand the field beyond the three most discussed platforms, especially in accounts already buying broader security suites. SP007, SP008, SP009, SP010
CP026 Material benefits from the fact that multi-homing is common: Ciphers explicitly recommends layering an ICES product on top of an existing gateway rather than treating the choice as either-or. SP002
CP027 That layering dynamic lowers rip-and-replace friction for Material but can also slow full-platform displacement and cap share-of-wallet gains. SP002, SP025
CP028 Ciphers reports public directional price bands for Proofpoint and Mimecast, while Material and Abnormal do not publish list pricing. SP002
CP029 Ciphers characterizes Proofpoint bundles at roughly $6-$10 per user per month and Mimecast tiers at roughly $3-$8 per user per month, both still quote-based in practice. SP002
CP030 Material and Abnormal are both quote-based, which makes public price discovery weaker than for incumbent gateway estimates. SP002
CP031 Gateway vendors keep an advantage where archiving, continuity, URL rewriting, and pre-delivery sandboxing are mandatory buying criteria. SP002, SP004, SP005
CP032 Material’s moat is strongest where buyers care about post-compromise containment, file exposure, risky OAuth apps, and investigation workflow speed. SP001, SP014, SP015, SP021
CP033 Material’s Google-partnership and provider pages suggest unusual depth in Google Workspace, which is a differentiator but also narrows the most natural buyer set. SP019, SP023
CP034 Competitive intensity will rise if Microsoft, Google, and gateway vendors continue to add their own remediation, DLP, and behavioral-detection features. SP011, SP025
CP035 Customer-review signals are positive for Material, but public evidence on head-to-head win rates versus Proofpoint, Mimecast, or Abnormal remains thin. SP016, SP017, SP018
CP036 The market increasingly compares vendors on day-two operational load—tuning, false positives, remediation speed, and search ergonomics—not just detection claims. SP001, SP003, SP015
CP037 CybersecTools and Material’s own comparison page both frame Microsoft Defender as the default baseline for Microsoft shops, with specialists added when advanced threats or broader controls matter. SP001, SP003, SP007
CP038 Material does not look like the universal winner across every buying motion; it looks strongest when the customer wants API-native deployment, Google/Workspace depth, and controls that continue after a phish lands. SP001, SP002, SP021, SP023
CI001 Material is sold as a cloud-workspace security software platform for Google Workspace and Microsoft 365. SI001, SI002
CI002 Public product and marketplace surfaces imply a recurring subscription model rather than a hardware or appliance sale. SI001, SI002, SI016
CI003 Material does not publish public list pricing on the reviewed company pages. SI001, SI002, SI019
CI004 Independent review and comparison sources also treat Material pricing as quote-based rather than list-priced. SI020, SI021
CI005 The 2021 Series B added $40 million and took total funding to $62 million. SI005, SI007
CI006 The 2022 Series C added $100 million at a $1.1 billion valuation and brought total funding to $166 million. SI004, SI008
CI007 Management said Series C proceeds would fund sales and marketing expansion, product extension, international growth, and a larger government footprint. SI004
CI008 Management said the Series B proceeds would expand business operations and R&D. SI005, SI007
CI009 Public sources reviewed do not disclose current ARR, GAAP revenue, or revenue growth for Material as of the run date. SI001, SI003, SI004, SI008
CI010 Public sources reviewed do not disclose current gross margin, burn, cash, or runway. SI001, SI003, SI004, SI008
CI011 The company’s customer set and product surface imply enterprise SaaS contracts rather than SMB self-serve transactions. SI003, SI010, SI012
CI012 Material’s Google partnership and Microsoft marketplace presence create additional procurement routes that can lower commercial friction. SI015, SI016
CI013 Material’s comparison and provider pages repeatedly emphasize API deployment with no network or MX-record changes. SI019, SI016, SI001
CI014 That API-first deployment suggests lower implementation cost and faster proof-of-value than a gateway migration. SI016, SI019
CI015 Headway’s case study says the team wanted an API-based solution because setup was easier than an email gateway. SI011
CI016 The same Headway case study says Material reduced phishing-triage time and automated user-report handling. SI011
CI017 Material’s customer page quotes Gopuff saying integration took six minutes and problems that took days could be solved in seconds. SI010
CI018 Material’s comparison page says automated user-report response can cut phishing triage by up to 91% at Gusto. SI019, SI010
CI019 Material’s multi-surface search use case says searches that used to take hours can take seconds. SI017
CI020 The current public logo set includes large brands such as OpenAI, Figma, Mars, Lyft, MassMutual, Gusto, and Databricks. SI003, SI010
CI021 The customer roster and procurement routes imply that average contract value is likely enterprise-grade even though no public ACV is disclosed. SI010, SI015, SI016
CI022 Material’s Google-partnership page says customers can apply GCP commitments and buy through Google Cloud Marketplace. SI015
CI023 Public customer proof emphasizes recurring workflows such as continuous phishing defense, posture management, and response automation rather than one-time consulting. SI010, SI011, SI017
CI024 Material’s positioning around email, files, and accounts suggests there may be multiple attachable modules or expansion surfaces inside one customer relationship. SI001, SI002, SI021
CI025 The current public evidence base does not show a material services-heavy delivery model. SI001, SI010
CI026 The last hard valuation mark is now stale enough that investors need current operating proof to justify any 2026 entry price. SI004, SI008, SI030
CI027 The public market gives investors a benchmark set with current SEC filers such as Microsoft, CrowdStrike, Zscaler, and Okta that disclose far more than Material does. SI022, SI023, SI024, SI025
CI028 Microsoft’s investor-relations page shows fiscal-year 2026 10-Q and 10-K availability, illustrating the disclosure standard public comps offer. SI022
CI029 CrowdStrike, Zscaler, and Okta each maintain dedicated SEC-filings pages that make quarterly and annual financial history easily available. SI023, SI024, SI025
CI030 CompaniesMarketCap pegs CrowdStrike at roughly $218.33 billion market cap in August 2026. SI026
CI031 CompaniesMarketCap pegs Zscaler at roughly $27.27 billion market cap in August 2026. SI027
CI032 CompaniesMarketCap pegs Palo Alto Networks at roughly $296.54 billion market cap in August 2026. SI028
CI033 CompaniesMarketCap pegs Microsoft at roughly $3.712 trillion market cap in August 2026. SI029
CI034 Those public benchmarks show how much valuation support scaled security platforms can earn once they disclose durable revenue and margin proof. SI022, SI023, SI026, SI027, SI028, SI029
CI035 Material appears capital-light from an infrastructure perspective because it is cloud software rather than hardware or network-appliance deployment. SI001, SI015
CI036 Even so, the company still required substantial external capital through 2022 to fund GTM expansion and product growth. SI005, SI006, SI007, SI004
CI037 Public sources reviewed do not disclose any debt facility or project-finance structure. SI004, SI005, SI007
CI038 Financial underwriting is currently blocked more by missing revenue-quality evidence than by any visible product-market-fit weakness. SI009, SI010, SI019, SI030
CE001 Material positions itself as a unified cloud-workspace security platform spanning email, files, accounts, posture, and operations. SE001, SE008, SE009
CE002 Material supports both Google Workspace and Microsoft 365 in current public product pages. SE001, SE002, SE008, SE009
CE003 Material consistently markets an API-based deployment model that avoids MX changes and preserves existing mail flow. SE007, SE018, SE008, SE009
CE004 That architecture lets Material coexist with incumbent email platforms rather than forcing a gateway cutover. SE018, SE008, SE009
CE005 Material’s product boundary includes post-delivery phishing remediation instead of only pre-delivery filtering. SE002, SE018
CE006 Material claims to protect sensitive data already sitting in historical inboxes by requiring additional authentication to access protected mail. SE009, SE016
CE007 Material claims continuous classification and remediation of risky Google Drive and file-sharing exposures. SE006, SE013, SE017
CE008 Material claims to detect account takeover using behavioral signals across email and Drive rather than login telemetry alone. SE008, SE009, SE016
CE009 Material claims it can contain compromised accounts with granular controls instead of only full account lockout. SE009, SE016
CE010 Material’s April 2026 update introduced an OAuth Remediation Agent that identifies new app connections, scores contextual risk, and can automatically revoke risky or dormant tokens. SE014
CE011 Material’s February 2026 update added automated calendar remediation tied to phishing clean-up workflows. SE015
CE012 The same February release added anomalous Google Drive activity timelines to help analysts scope incident blast radius. SE015
CE013 Material says its detections now expose specific indicators and impact mapping, aiming to reduce black-box security decisions. SE015, SE004
CE014 Material’s trust-in-ML post says the company emphasizes integrity, transparency, alignment, and mastery in how models are built and explained. SE004
CE015 Material says customer feedback loops influence model tuning so detections stay aligned with different operating requirements. SE004
CE016 Material’s use-case content says the platform unifies data from multiple Google Workspace and Microsoft 365 tenants into one search console. SE005, SE034
CE017 Material says searches that once took hours in native tools can take seconds in its platform. SE005, SE015
CE018 Material’s Google Workspace positioning says it extends native tools with unified visibility, automated triage, data-sprawl controls, and compromise detection. SE006, SE008
CE019 Material’s Microsoft 365 positioning says it detects anomalous session behavior like bulk reads and unusual forwarding and maintains immutable access audit trails for breach scoping. SE009
CE020 The Google partnership page says customers can apply GCP commitments and buy via Google Cloud Marketplace. SE010
CE021 The Microsoft Marketplace listing shows Material is also distributed through Microsoft’s ecosystem. SE012
CE022 Material’s SEG comparison says the product protects email, files, and accounts, offers OAuth grant management, and avoids shadow mail stores and daily queue triage. SE018
CE023 Material’s Google Workspace content says it can secure sensitive data in mailboxes with step-up MFA without blocking normal collaboration. SE006, SE016
CE024 The trust center advertises SOC 2 Type 2, audit logging, role-based access control, MFA, code analysis, and backup-related controls. SE003
CE025 The trust center lists a public pentest report, security whitepaper, and policy set, which is a stronger-than-average disclosure surface for a private security vendor. SE003
CE026 Material publicly claims a single-tenant deployment option for customers with rigorous requirements. SE005
CE027 Material’s 2026 product updates show active expansion into OAuth governance, calendar attack cleanup, sensitive file-sharing maps, AI-powered file search, and integration routing. SE013, SE014, SE015
CE028 The product demo page frames the security battlefront as shifting from classic email filtering to cloud-workspace, OAuth, and file exposure. SE019
CE029 Headway’s case study says the team chose an API-based solution because setup was easier than a gateway. SE020, SE032
CE030 PagerDuty’s case study says OAuth apps had become a major threat vector the company wanted to address. SE022, SE014
CE031 Amplitude’s case study says Material helped protect inboxes without requiring changes to existing mail routing. SE021, SE032
CE032 Stake’s case study positions Material as a way to secure the broader cloud workspace rather than only the inbox. SE023
CE033 Independent industry sources show BEC, phishing, and email-led attacks remain material, which supports Material’s continued focus on collaboration suites. SE025, SE026, SE029
CE034 Google and Microsoft each provide substantial native controls, so Material’s technical case depends on operational simplification and cross-surface depth rather than greenfield functionality. SE027, SE028, SE030, SE006, SE009
CE035 Material’s public record is strong on workflow descriptions but thin on quantitative detection efficacy, benchmark false-positive rates, and model-performance metrics. SE004, SE015, SE018
CE036 The highest-confidence technical differentiators visible publicly are post-delivery remediation, at-rest data controls, cross-surface investigation, and OAuth governance. SE002, SE013, SE014, SE015, SE018
CE037 Material appears deepest in Google Workspace today because more public use cases and feature writeups are expressed in Google-specific terms than in Microsoft-specific ones. SE006, SE008, SE013, SE014, SE015, SE016
CE038 Even so, the Microsoft 365 page shows Material is not Google-only; it also frames specific healthcare breach-scoping use cases for M365 environments. SE009
CE039 Panther’s onboarding documentation shows Material can emit Issue Change and Audit Log events by webhook into external security tooling. SE034
CE040 Panther’s integration page describes Material as a unified email-security, user-behavior-analytics, and DLP solution for Microsoft 365 and Google Workspace and says onboarding takes only minutes. SE035
CE041 Material’s 2022 Series C announcement said the product was entirely cloud-based, deployed in 30 minutes, and could be exclusively managed by the customer. SE031, SE036
CE042 Review-site descriptions independently reinforce that Material integrates with existing email platforms and aims to avoid workflow disruption. SE032, SE033
CU001 Material publicly references a large set of named customers including OpenAI, Figma, Mars, Lyft, MassMutual, Gusto, Databricks, DoorDash, Postman, and PagerDuty. SU001, SU002, SU010
CU002 The 2022 Series C announcement added Chubb, Compass, Roblox, and Brex as new referenceable customers. SU011, SU012, SU013
CU003 The trust center also lists PagerDuty, Postman, Lyft, Databricks, DoorDash, Mars, and MassMutual as organizations that review and trust Material. SU010
CU004 The named customer set spans technology, fintech, insurance, healthcare, consumer internet, and consumer brands. SU001, SU003, SU004, SU005, SU006, SU010
CU005 Publicly named customers include both public companies and scaled private companies. SU004, SU005, SU001
CU006 Headway shows healthcare-adjacent customer proof centered on protecting sensitive mental-health data in Google Workspace. SU003
CU007 Stake provides fintech customer proof focused on phishing, data protection, and governance inside Google Workspace. SU006
CU008 PagerDuty provides public-company proof for email risk management, data protection, compliance, and phishing response. SU005
CU009 Amplitude provides public-company proof for post-delivery phishing response and user-driven protection. SU004
CU010 Mars appears in a Material use-case page as a customer citing cross-platform search that dropped from hours to roughly 20 seconds. SU007
CU011 Material’s customer page quotes Gopuff saying integration took six minutes and certain investigations went from days to seconds. SU001
CU012 Material’s comparison page says automated response reduced Gusto’s phishing triage time by up to 91%. SU025, SU001
CU013 Headway says it wanted an API-based solution because setup was easier than an email gateway and did not require DNS changes. SU003
CU014 PagerDuty says its technical implementation took roughly two minutes and rolled out with low risk and few dependencies. SU005
CU015 Stake says MTTR for phishing reports went from hours to seconds. SU006
CU016 Headway says Material automated user-report response, improved visibility into Drive files, and reduced phishing-triage burden. SU003
CU017 Amplitude describes a workflow where a single user report can protect every other employee inbox immediately. SU004
CU018 PagerDuty says Material improved auditability, policy compliance, and authentication practices around email risk. SU005
CU019 Stake says Material helps the company identify risky behavior before it becomes a problem and harden Google Workspace posture proactively. SU006
CU020 Public customer proof repeatedly emphasizes post-delivery protection, phishing remediation, data protection, and governance rather than only inbound filtering. SU003, SU004, SU005, SU006, SU025
CU021 Material’s buyer fit looks strongest for cloud-first security teams that run Google Workspace or Microsoft 365 and need more operational depth than native tools provide. SU008, SU021, SU022, SU023, SU025
CU022 The public evidence for Google Workspace customer fit is richer than the evidence for Microsoft 365 customer fit. SU003, SU006, SU021, SU023
CU023 Microsoft 365 support is still real in the public customer proof because Material’s core product pages and funding announcement explicitly reference Microsoft 365 or Microsoft email. SU008, SU022, SU011
CU024 Referenceability appears unusually strong for a private security vendor because Material names many customers and publishes several detailed case studies. SU001, SU003, SU004, SU005, SU006, SU010
CU025 At the same time, much of the customer evidence remains company-authored rather than independently verified customer commentary. SU001, SU003, SU004, SU005, SU006, SU010
CU026 TrustRadius describes Material as providing visibility, defense-in-depth, and security infrastructure for Microsoft 365 and Google Workspace. SU019
CU027 PeerSpot describes Material as seamlessly integrating with existing email platforms and enhancing security without disrupting workflows. SU020
CU028 Panther’s integration materials describe Material as a unified email-security, user-behavior-analytics, and DLP solution used with Google Workspace and Microsoft 365. SU026, SU027
CU029 The First Round profile indicates customer discovery and product-market-fit work were central from the company’s early years, which supports the depth of later referenceability. SU014
CU030 Founder-interview sources frame the customer problem around protecting data already sitting in email rather than only blocking inbound threats, which matches later customer use cases. SU015, SU016
CU031 The customer stories suggest Material becomes part of daily security workflows because it touches user reports, investigations, MFA, file sharing, and account-governance tasks. SU003, SU004, SU005, SU006
CU032 The public customer set includes organizations with meaningful compliance exposure such as healthcare, insurance, and publicly traded SaaS platforms. SU003, SU005, SU010
CU033 There is no public count of total customers in the reviewed sources. SU001, SU002, SU018
CU034 There is no public disclosure of customer concentration or top-account revenue mix in the reviewed sources. SU001, SU011, SU018
CU035 There is no public disclosure of gross or net retention in the reviewed sources. SU001, SU018
CU036 The strongest investor takeaway is that Material has credible enterprise adoption proof, but not enough public data to underwrite customer economics quantitatively. SU017, SU019, SU020, SU026, SU027
CU037 Material’s willingness to keep publishing named customer references from 2020 through 2026 suggests continuing confidence in customer advocacy. SU004, SU005, SU006, SU011, SU019
CU038 The customer evidence implies a target buyer in security, IT, or compliance functions rather than line-of-business teams. SU003, SU005, SU006, SU019, SU020
CU039 Cabinetworks gives Material a Microsoft 365-heavy reference where the buyer explicitly wanted broader visibility into sensitive data and post-breach risk than legacy email tools offered. SU028
CU040 Color provides another healthcare-sensitive reference and says investigation effort fell from roughly 20-30 minutes per message to 2-5 minutes for several messages in Material. SU029
CU041 Lyft says Material deployed to about 8,000 corporate and partner users within a single work week without workflow disruption. SU030
CU042 Mars ran a pilot across nearly 20,000 mailboxes on both Microsoft 365 and Google Workspace, reinforcing Material’s fit for large multi-platform environments. SU031
CU043 Gusto’s dedicated case study corroborates the up-to-91% phishing triage reduction claim already quoted elsewhere in Material’s materials. SU032
CU044 Material maintains dedicated customer-facing use cases for automating user-reported phishing and distributing the security burden, which supports the idea that customer adoption is workflow-centric. SU034, SU035
CU045 Material also positions itself broadly as email security for both Google and Microsoft cloud office environments, reinforcing that the target customer is protecting a collaboration suite rather than just an inbox. SU033
CU046 Material’s 2026 AI-adoption field discussion featured Gopuff’s head of cybersecurity, indicating customer engagement that extends beyond canned logo usage into public operating conversations. SU036
CU047 Material publishes detailed workflow content on automating user-reported phishing and Tines-based triage, reinforcing that customer value is tied to operational process design rather than only detection rules. SU037, SU039
CU048 A second Mars resource focused on identity protection and sensitive content shows that some customers engage Material across multiple control categories, not just a single phishing use case. SU038
CR001 Material’s privacy policy says the service processes cloud-office metadata, user-generated content, permissions, actions, and access settings that may contain personal data. SR001
CR002 The privacy policy says Material acts as a processor on behalf of enterprise customers for data processed through the service. SR001
CR003 The same policy says Material may manually handle customer personal data for support, security response, anonymized internal use, or legal compliance. SR001
CR004 Material’s privacy policy states that its data centers are located in the United States. SR001
CR005 The privacy policy says customer personal data is deleted within 30 days after termination, subject to legal exceptions. SR001
CR006 Material’s trust center advertises SOC 2 Type 2, audit logging, MFA, RBAC, a pentest report, and a two-hour recovery time objective. SR002
CR007 Material’s ML-governance material emphasizes integrity, transparency, alignment, and mastery, showing management is aware of black-box and drift risks. SR003
CR008 But public materials still do not provide independent precision, recall, or false-positive benchmarks for Material’s detections. SR003, SR031
CR009 Material’s public product dependency is concentrated in Google Workspace and Microsoft 365 environments. SR004, SR005, SR007
CR010 That dependence means provider API, scope, policy, or pricing changes could directly affect Material’s functionality and margins. SR004, SR005, SR022, SR024
CR011 Google and Microsoft each market substantial native security, privacy, and compliance controls to workspace customers. SR022, SR023, SR024, SR025, SR026
CR012 Material’s risk is therefore not only technical failure but also being bundled around by large platforms that keep expanding native controls. SR004, SR005, SR022, SR024, SR025, SR026
CR013 Headway and Stake both show strong Google-Workspace-centric proof, which creates public-perception risk that Microsoft depth may lag Google depth. SR008, SR009, SR004
CR014 Cabinetworks and Mars show that Material also addresses Microsoft 365 or mixed-platform estates, reducing but not eliminating platform-balance risk. SR011, SR012, SR005
CR015 Mars says Material’s single-tenant architecture, customer access to infrastructure, and regional hosting options helped satisfy privacy and global-data concerns. SR011
CR016 Single-tenancy can reduce shared-environment blast radius, but it can also increase operational complexity relative to a pure multi-tenant SaaS model. SR011
CR017 PagerDuty says Material improved auditability and compliance posture around email risk, implying product failure would have meaningful control consequences for customers. SR010
CR018 Color and Headway both show that customers use Material to avoid either missed phishing reports or risky retention/deletion tradeoffs for sensitive mail. SR008, SR032
CR019 Panther’s documentation shows Material emits webhook events and audit-oriented telemetry into external SOC tooling, increasing the importance of event integrity and schema stability. SR027, SR028
CR020 Material’s new OAuth Remediation Agent reflects a real threat trend: third-party app connections and AI agents are expanding the attack surface around workspace data. SR029, SR030
CR021 Microsoft says it detected about 7.6 billion email-based phishing threats in Q2 2026. SR015
CR022 Microsoft also saw weekly malicious Teams voice-phishing attempts grow to nearly ten times the mid-2025 baseline by the end of Q2 2026. SR015
CR023 Microsoft says credential phishing remained the dominant objective of malicious payloads during Q2 2026. SR015
CR024 Microsoft says calendar-invite payloads nearly quadrupled in June 2026, which supports Material’s focus on non-inbox surfaces like calendar cleanup. SR015
CR025 IC3 says 2025 complaints surpassed $20.877 billion in reported losses and BEC alone accounted for about $3.05 billion. SR014
CR026 CISA’s ongoing advisories and the Verizon DBIR both reinforce that human-factor attacks, phishing, stolen credentials, and exploitation remain persistent. SR016, SR018
CR027 Proofpoint’s State of the Phish material says risky user behavior and sophisticated MFA-bypass, vishing, and QR-code tactics remain important. SR017
CR028 This threat environment means even good products will face residual miss risk, false negatives, and fast adversary adaptation. SR014, SR015, SR016, SR017, SR018
CR029 Morgan Lewis says 2025-2026 enforcement trends increased expectations around audit readiness, cross-border data governance, and coordinated incident response. SR019
CR030 Morgan Lewis also highlights CIRCIA momentum and 72-hour / 24-hour reporting expectations for covered critical-infrastructure incidents and ransomware payments. SR019
CR031 Debevoise says cyber incident disclosures under Item 8.01 have significantly outpaced Item 1.05 filings through May 2026, showing reporting practice is still evolving. SR020
CR032 DFIN’s summary of SEC cyber rules reinforces that a future public-company Material would need mature incident-governance and disclosure discipline. SR021
CR033 Google Workspace compliance documentation highlights HIPAA, data-processing, transfer, and certification obligations that matter because Material often sits on top of Workspace data. SR023
CR034 Google Trust Center and Microsoft Trust Center both emphasize extensive compliance and security commitments, which raises buyer expectations for ecosystem partners like Material. SR022, SR024
CR035 Material’s public concentration in regulated or high-sensitivity use cases such as healthcare, finance, and public SaaS means a customer-facing incident could create outsized reputational damage. SR008, SR009, SR010, SR032
CR036 The business model remains publicly opaque on ARR, burn, retention, and concentration, which is itself a financial-model risk. SR013, SR001
CR037 The 2022 $1.1 billion valuation does not tell investors whether current growth, efficiency, or cash sufficiency still support that level in 2026. SR013
CR038 Competitive pressure is real because Google, Microsoft, secure email gateways, and adjacent vendors all offer overlapping pieces of the problem. SR006, SR022, SR024, SR025, SR026
CR039 A thesis-break risk would be evidence that large customers can get most of Material’s value from native controls plus lightweight workflow glue. SR004, SR005, SR022, SR024, SR027
CR040 Another thesis-break risk would be a meaningful privacy or security incident affecting Material’s own handling of historical email and file content. SR001, SR002, SR011
CR041 Key monitoring indicators include customer references on Microsoft 365, independent efficacy evidence, regulatory artifacts, and any fresh financing or governance disclosures. SR005, SR020, SR021, SR013
CR042 Overall, Material’s risk profile looks manageable but real: the company benefits from strong architecture and operator empathy, yet it bears meaningful privacy, platform, regulatory, and disclosure risk because of the sensitivity of the data it touches. SR001, SR002, SR011, SR019, SR020
CR043 Material publishes a dedicated subprocessors page, confirming that third-party vendors are part of the data-handling chain investors need to review. SR033
CR044 CISA’s CIRCIA materials formalize the direction of travel toward 72-hour cyber-incident reporting and 24-hour ransomware-payment reporting for covered infrastructure entities. SR034, SR035
CR045 NIST’s CSF 2.0 and SP 800-61 Rev. 3 reinforce that mature cyber programs now require governance-led incident response instead of purely ad hoc technical handling. SR036, SR037
CR046 Google and Microsoft each maintain formal data-processing addenda for enterprise customers, highlighting the contractual privacy expectations Material must fit into as an ecosystem partner. SR038, SR039
CV001 The last hard public valuation anchor is Material’s $1.1 billion Series C announced in May 2022. SV001
CV002 The public record shows $40 million Series B in 2021 and $100 million Series C in 2022, for $166 million total funding disclosed by the company. SV001, SV002
CV003 Public sources reviewed do not disclose current ARR, GAAP revenue, or growth rate for Material as of the run date. SV001, SV002, SV003
CV004 Because current revenue is undisclosed, outsiders cannot compute an actual implied EV/revenue multiple for Material. SV001, SV009, SV010
CV005 Windsor Drake’s Q2 2026 report places the public cybersecurity median near 6.0x to 6.5x NTM revenue. SV010
CV006 The same report says cloud security and SASE leaders trade around 14x to 22x NTM revenue, while AI-native private security platforms can clear roughly 20x to 30x revenue. SV010
CV007 Windsor Drake’s broader 2026 report also places the public cyber median around 7.8x revenue and cloud / identity leaders in the low-to-mid teens or higher. SV009
CV008 Windsor Drake says top-quartile cyber performers with Rule of 40 scores above 50 earn a 50% to 100% premium over the median. SV010
CV009 Windsor Drake says the public-to-private cyber premium has compressed to about 2x in 2026 from about 7x in 2023. SV010
CV010 Windsor Drake says strategic acquirers deployed an estimated 92% of cyber M&A capital in 2025. SV010
CV011 CompaniesMarketCap pegs CrowdStrike near $218.33 billion market cap in August 2026. SV011
CV012 CompaniesMarketCap pegs Zscaler near $27.27 billion market cap in August 2026. SV012
CV013 CompaniesMarketCap pegs Palo Alto Networks near $296.54 billion market cap in August 2026. SV013
CV014 CompaniesMarketCap pegs Microsoft near $3.712 trillion market cap in August 2026. SV014
CV015 CompaniesMarketCap pegs Okta near $26.00 billion market cap in August 2026. SV015
CV016 CrowdStrike, Zscaler, Microsoft, Palo Alto Networks, and Okta all maintain public filing or annual-report surfaces that provide far more operating disclosure than Material does. SV016, SV017, SV018, SV019, SV020, SV021, SV022, SV023
CV017 Proofpoint was acquired by Thoma Bravo for approximately $12.3 billion in 2021 and taken private. SV024
CV018 Mimecast was acquired by Permira for approximately $5.8 billion in 2022 and taken private. SV025
CV019 Those transactions remain relevant proof that email-security assets can support large strategic values, but they are dated and come from a very different rate and software-multiple regime. SV024, SV025, SV009, SV010
CV020 Material’s product scope now spans email, files, accounts, and OAuth-governance workflows, so it is better thought of as a cloud-workspace security platform than a narrow legacy gateway. SV003, SV026, SV027, SV028, SV029
CV021 That broader platform framing can support a premium to legacy email-security references if customers show strong retention and expansion. SV003, SV009, SV010
CV022 Material’s named-customer quality is strong for a private vendor, with references across public SaaS, healthcare-sensitive, fintech, and large enterprise environments. SV004, SV005, SV006, SV007
CV023 Strong customer proof can justify multiple support only if accompanied by revenue durability metrics such as NRR, gross retention, and gross margin. SV004, SV009, SV010
CV024 Material’s Google and Microsoft positioning plus OAuth and AI-related updates fit the parts of security that public markets still award premium multiples to when evidence is strong. SV026, SV027, SV028, SV029, SV030, SV010
CV025 The main discount arguments are private-company opacity, platform dependency on Google and Microsoft, competitive bundling risk, and the absence of current financial disclosure. SV003, SV008, SV026, SV027, SV031
CV026 The 2022 unicorn mark is stale enough that investors should not carry it forward without fresh proof on growth, retention, and cash efficiency. SV001, SV009, SV010
CV027 A bull case would require Material to look like a premium cloud-security platform with high growth, strong retention, and clear operator ROI, supporting a multiple above the public cyber median. SV010, SV022, SV024
CV028 A base case would assume Material is a good but still partly opaque growth company that deserves some premium to median software, but not a top-quartile cyber multiple without proof. SV009, SV010, SV025
CV029 A bear case would assume native platforms or bundled suites narrow the product wedge while private metrics fail to justify the 2022 mark, forcing a discount to stale expectations. SV008, SV026, SV027, SV031
CV030 Public evidence alone does not support paying up for a premium 2026 price above the last disclosed valuation without private data. SV001, SV003, SV010
CV031 The most supportable public-only stance is disciplined diligence with price skepticism, not outright rejection of the company. SV004, SV010, SV030
CV032 Confidence in any price opinion should remain moderate-to-low because key financial metrics are private. SV003, SV010
CV033 Public comps also show how large the reward can be when security vendors prove durable platform status, but those examples are far more mature than Material. SV011, SV012, SV013, SV014, SV015, SV016
CV034 Proofpoint and Mimecast M&A comps are most useful as strategic-proof references for email security, not as direct pricing anchors for a 2026 growth-round decision. SV017, SV018, SV019
CV035 Exit readiness looks plausible because the company has recognizable customers, broadening product scope, and buyer-relevant positioning, but public-company readiness is not verifiable from open data. SV004, SV016, SV020
CV036 Any serious price discussion should request current ARR, growth, burn, gross margin, NRR, concentration, and board-level financing expectations before accepting a premium multiple. SV003, SV010
CV037 A thesis-break trigger would be evidence that customers can get enough post-delivery and governance value from native Google or Microsoft controls at materially lower cost. SV026, SV027, SV031
CV038 Another thesis-break trigger would be a financing or retention picture that implies the 2022 mark is already below fair value rather than above it. SV001, SV010
CV039 Material’s premium case is qualitatively stronger than a plain email-security story because customer materials emphasize workflow leverage, data protection, and account security beyond spam blocking. SV004, SV005, SV006, SV007, SV008
CV040 Overall, the valuation case is attractive only conditionally: the company likely merits continued attention, but the public record supports valuation discipline rather than enthusiasm at any price. SV001, SV004, SV009, SV010, SV030
CV041 From public evidence alone, Material clears the relevance and quality gates but fails the pricing-confidence gates because the key financial metrics remain private. SV004, SV010, SV016
来源
编号出版方标题引文
SO001 Material Security About Us and Leadership | Material Security Ryan co-founded Material in 2017 and has served as Chairman since 2023.
SO002 Material Security Security for Google Workspace and Microsoft 365 | Material Security Modern, AI-driven attacks deliberately span email, identities, data, and connected apps.
SO003 Material Security Cloud Workspace Security Platform | Material Security Material is a dedicated security platform for Google Workspace and Microsoft 365.
SO004 Material Security Our Founding Story | Material Security Listen to Ryan and Abhishek talk about how the 2016 election hacks led to the creation of Material Security.
SO005 Business Wire Material Security Reaches $1.1 Billion Valuation for ‘Zero Trust’ Security on Microsoft and Google Email Material Security... secured $100 million in Series-C funding at a valuation of $1.1 billion.
SO006 SiliconANGLE Email security startup Material Security raises $100M on unicorn valuation of $1.1B Including the new funding, it has raised $166 million to date.
SO007 Help Net Security Material Security raises $100 million to extend the product into new areas and expand internationally
SO008 Fenwick Fenwick Represents Material Security in $100M Series C Financing | Fenwick
SO009 citybiz Material Security Closes $100 Million Series C
SO010 First Round Review Material Security's Path to Product-Market Fit In 2017, former Dropbox engineers Ryan Noon, Abhishek Agrawal and Chris Park quietly launched an enterprise software company.
SO011 Material Security Material Security Series B Announcement | Material Security We're sharing today that Material has raised an additional $40M of funding to our $22M Series A led by Andreessen Horowitz in 2018.
SO012 Business Wire Material Security Raises $40 Million Series B To Protect the World’s Email From the Next SolarWinds Attack bringing the company’s total funding to date to $62M.
SO013 Fenwick Fenwick Represents Material Security in $40M Series B Financing | Fenwick
SO014 Andreessen Horowitz Investing in Material Security
SO015 Hacker Valley Media Episode 110 - Becoming Material Security with Ryan Noon and Abhishek Agrawal
SO016 Software Engineering Daily Material Security with Ryan Noon - Software Engineering Daily
SO017 Sagetap Founder Story: Material Security | Sagetap
SO018 Craft Material Security Company Profile - Office Locations, Competitors, Revenue, Financials, Employees, Key People, Subsidiaries | Craft.co Type Private Status Active Founded 2017 HQ Redwood City, CA, US.
SO019 Material Security Helping Secure Our Customers | Material Security It would take days to triage a problem... I need six minutes to do the integration and seconds to solve problems at scale.
SO020 Material Security What AI Adoption Actually Requires | Material Security
SO021 Material Security Fewer Entry Points, Smarter Defaults | Material Security Introducing the OAuth Remediation Agent.
SO022 Material Security Google Partnership | Material Security Material is a Google Cloud Premier Partner.
SO023 Microsoft Marketplace Material Security We provide a unified suite of cloud email security, user behavior analytics, posture management, and data loss prevention.
SO024 Gartner Peer Insights Material Reviews, Ratings & Features 2026 | Gartner Peer Insights 4.8 Rating Distribution
SO025 Morgan Lewis Cybersecurity & Privacy 2026: Enforcement & Regulatory Trends
SM001 FBI IC3 2025 IC3 Annual Report Business Email Compromise 24,768 complaints and $3,046,598,558 loss.
SM002 Verizon Business 2026 Data Breach Investigations Report (DBIR)
SM003 CISA Cybersecurity Alerts & Advisories | CISA
SM004 Proofpoint 2024 State of the Phish Report: Phishing Statistics & Trends | Proofpoint US More than 70% of employees admit to risky behavior that leaves them vulnerable.
SM005 Google Workspace Cloud Security and Data Protection Services | Google Workspace Protect your organization from threats, prevent data loss, and meet compliance requirements.
SM006 Google Cloud Trust Center - Security and Compliance
SM007 Google Workspace Help Google Workspace legal and compliance
SM008 Microsoft Trust Center Microsoft Trust Center Overview | Microsoft Trust Center
SM009 Microsoft Security Blog Email threat landscape: Q2 2026 trends and insights | Microsoft Security Blog Microsoft detected approximately 7.6 billion email-based phishing threats throughout the quarter.
SM010 Fortune Business Insights Email Security Market Size, Share | Industry Report [2026-2034] The market is projected to grow from USD 6.06 billion in 2026 to USD 14.44 billion by 2034.
SM011 Mordor Intelligence Cloud-based Email Security Market - Size, Share & Growth Report 2026 - 2031 Cloud-based email security software market size in 2026 is estimated at USD 6.24 billion.
SM012 Windsor Drake Cybersecurity Valuation Report 2026 | Windsor Drake
SM013 Material Security Security for Google Workspace and Microsoft 365 | Material Security
SM014 Material Security Cloud Workspace Security Platform | Material Security
SM015 Material Security Email Security Solutions for Google Workspace and Microsoft 365 | Material
SM016 Material Security Google Partnership | Material Security
SM017 Material Security SEG Alternative for Google Workspace | Material Security
SM018 Proofpoint Email Security Service: Threat Protection Solutions | Proofpoint US
SM019 Abnormal AI Behavioral AI Email Security Platform | Abnormal AI
SM020 Mimecast Advanced Email Security
SM021 Microsoft Security Microsoft Defender for Office 365 | Microsoft Security
SM022 Check Point Email Security Services - Check Point Software
SM023 Cisco Cisco Secure Email Threat Defense
SM024 KnowBe4 Cloud Email Security for Microsoft 365 | KnowBe4
SM025 Material Security Unified SecOps for Google Workspace | Material Security
SP001 Material Security Best Email Security Tools for 2026 | Material Material Security ... API ... Google Workspace and Microsoft 365 ... Contains and remediates.
SP002 Ciphers Security Proofpoint Vs Mimecast Vs Abnormal Security 2026 Proofpoint and Mimecast are secure email gateways ... Abnormal Security is an Integrated Cloud Email Security platform.
SP003 CybersecTools Best Email Security Platforms in 2026
SP004 Proofpoint Email Security Service: Threat Protection Solutions | Proofpoint US
SP005 Mimecast Advanced Email Security
SP006 Abnormal AI Behavioral AI Email Security Platform | Abnormal AI
SP007 Microsoft Security Microsoft Defender for Office 365 | Microsoft Security
SP008 Check Point Email Security Services - Check Point Software
SP009 Cisco Cisco Secure Email Threat Defense
SP010 KnowBe4 Cloud Email Security for Microsoft 365 | KnowBe4
SP011 Proofpoint Tessian is Now Proofpoint | Proofpoint US We have now brought together ... Proofpoint ... with Tessian’s AI-powered behavioral and dynamic detection.
SP012 Material Security Automated Email Security for Google & M365 | Material Security
SP013 Material Security Email Security for Google & M365 | Material Security
SP014 Material Security Reduce Workspace Security Complexity | Material Security
SP015 Material Security Accelerate Search and Investigations Across Multiple Cloud Workspaces | Material Security searches that used to take hours now take seconds.
SP016 TrustRadius Material Security Overview, Reviews, Pricing 2026 | TrustRadius
SP017 PeerSpot Material Security Reviews, Competitors and Pricing 4.8 rating distribution
SP018 Gartner Peer Insights Material Reviews, Ratings & Features 2026 | Gartner Peer Insights
SP019 Material Security Google Partnership | Material Security
SP020 Material Security Email Security Solutions for Google Workspace and Microsoft 365 | Material
SP021 Material Security Cloud Workspace Security Platform | Material Security
SP022 Microsoft Marketplace Material Security
SP023 Material Security Unified SecOps for Google Workspace | Material Security
SP024 Material Security Helping Secure Our Customers | Material Security
SP025 Windsor Drake Cybersecurity Valuation Report 2026 | Windsor Drake
SI001 Material Security Cloud Workspace Security Platform | Material Security
SI002 Material Security Email Security Solutions for Google Workspace and Microsoft 365 | Material
SI003 Material Security About Us and Leadership | Material Security
SI004 Business Wire Material Security Reaches $1.1 Billion Valuation for ‘Zero Trust’ Security on Microsoft and Google Email
SI005 Business Wire Material Security Raises $40 Million Series B To Protect the World’s Email From the Next SolarWinds Attack
SI006 Andreessen Horowitz Investing in Material Security
SI007 Material Security Material Security Series B Announcement | Material Security
SI008 SiliconANGLE Email security startup Material Security raises $100M on unicorn valuation of $1.1B
SI009 Craft Material Security Company Profile - Office Locations, Competitors, Revenue, Financials, Employees, Key People, Subsidiaries | Craft.co
SI010 Material Security Helping Secure Our Customers | Material Security
SI011 Material Security How Headway Protects Mental Health Data | Headway | Material Security
SI012 Material Security Amplitude Protects Inboxes With Material | Amplitude | Material Security
SI013 Material Security Email Security Upgrade | Pager Duty | Material Security
SI014 Material Security How Stake Secures Its Cloud Workspace | Stake | Material Security
SI015 Material Security Google Partnership | Material Security
SI016 Microsoft Marketplace Material Security
SI017 Material Security Accelerate Search and Investigations Across Multiple Cloud Workspaces | Material Security
SI018 Material Security Reduce Workspace Security Complexity | Material Security
SI019 Material Security Best Email Security Tools for 2026 | Material
SI020 TrustRadius Material Security Overview, Reviews, Pricing 2026 | TrustRadius
SI021 PeerSpot Material Security Reviews, Competitors and Pricing
SI022 Microsoft Investor Relations Microsoft Investor Relations - SEC Filings
SI023 CrowdStrike Investor Relations SEC Filings | CrowdStrike Holdings, Inc.
SI024 Zscaler Investor Relations SEC Filings | Zscaler, Inc.
SI025 Okta Investor Relations Okta Inc. - Financials - SEC Filings
SI026 CompaniesMarketCap CrowdStrike (CRWD) - Market capitalization
SI027 CompaniesMarketCap Zscaler (ZS) - Market capitalization
SI028 CompaniesMarketCap Palo Alto Networks (PANW) - Market capitalization
SI029 CompaniesMarketCap Microsoft (MSFT) - Market capitalization
SI030 Windsor Drake Cybersecurity Valuation Report 2026 | Windsor Drake
SE001 Material Security Cloud Workspace Security Platform | Material Security
SE002 Material Security Email Security Solutions for Google Workspace and Microsoft 365 | Material
SE003 Material Security Material Security Material Trust Center | Powered by SafeBase
SE004 Material Security Building Trustworthy ML at Material Security
SE005 Material Security Accelerate Search and Investigations Across Multiple Cloud Workspaces | Material Security
SE006 Material Security Reduce Workspace Security Complexity | Material Security
SE007 Material Security Best Email Security Tools for 2026 | Material
SE008 Material Security Material Security for Google Workspace
SE009 Material Security Material Security for Microsoft 365
SE010 Material Security Google Partnership | Material Security
SE011 Google for Developers Google Workspace | Google for Developers
SE012 Microsoft Marketplace Material Security
SE013 Material Security Map Sensitive File Sharing in Drive and Simplify Customization in Material
SE014 Material Security Introducing the OAuth Remediation Agent | Material Security
SE015 Material Security Automated Remediation + Deeper Context | Material Security
SE016 Material Security The Material Advantage for Google Workspace
SE017 Material Security Beyond Basic Google DLP: Smart Tricks for Bulletproof Data Security
SE018 Material Security Material Security vs. SEGs
SE019 Material Security Material Product Demo: Securing Google Workspace & M365
SE020 Material Security How Headway Protects Mental Health Data | Headway | Material Security
SE021 Material Security Amplitude Protects Inboxes With Material | Amplitude | Material Security
SE022 Material Security Email Security Upgrade | Pager Duty | Material Security
SE023 Material Security How Stake Secures Its Cloud Workspace | Stake | Material Security
SE024 Material Security Helping Secure Our Customers | Material Security
SE025 Microsoft Latest Insights and Trends for Security Leaders | Security Insider
SE026 FBI IC3 2025 Internet Crime Report
SE027 Google Workspace Help Advanced phishing and malware protection | Gmail | Google Workspace Help
SE028 Microsoft Learn Why do I need Microsoft Defender for Office 365?
SE029 CISA Current Activity
SE030 Google Cloud Google Workspace security and compliance
SE031 Business Wire Material Security Reaches $1.1 Billion Valuation for ‘Zero Trust’ Security on Microsoft and Google Email
SE032 TrustRadius Material Security Overview, Reviews, Pricing 2026 | TrustRadius
SE033 PeerSpot Material Security Reviews, Competitors and Pricing
SE034 Panther Docs Material Security Logs | Panther Docs
SE035 Panther Security Integrations for Modern SOC Operations | Panther
SE036 Help Net Security Material Security raises $100 million on a $1.1 billion valuation
SU001 Material Security Helping Secure Our Customers | Material Security
SU002 Material Security About Us and Leadership | Material Security
SU003 Material Security How Headway Protects Mental Health Data | Headway | Material Security
SU004 Material Security Amplitude Protects Inboxes With Material | Amplitude | Material Security
SU005 Material Security Email Security Upgrade | Pager Duty | Material Security
SU006 Material Security How Stake Secures Its Cloud Workspace | Stake | Material Security
SU007 Material Security Accelerate Search and Investigations Across Multiple Cloud Workspaces | Material Security
SU008 Material Security Cloud Workspace Security Platform | Material Security
SU009 Material Security Google Partnership | Material Security
SU010 Material Security Material Security Material Trust Center | Powered by SafeBase
SU011 Business Wire Material Security Reaches $1.1 Billion Valuation for ‘Zero Trust’ Security on Microsoft and Google Email
SU012 Help Net Security Material Security raises $100 million on a $1.1 billion valuation
SU013 citybiz Material Security Closes $100 Million Series C
SU014 First Round Review Material Security’s Path to Product-Market Fit
SU015 Hacker Valley Episode 110 - Becoming Material Security with Ryan Noon and Abhishek Agrawal
SU016 Software Engineering Daily Material Security with Ryan Noon
SU017 Sagetap Material Security
SU018 Craft Material Security company profile
SU019 TrustRadius Material Security Overview, Reviews, Pricing 2026 | TrustRadius
SU020 PeerSpot Material Security Reviews, Competitors and Pricing
SU021 Material Security Material Security for Google Workspace
SU022 Material Security Material Security for Microsoft 365
SU023 Material Security The Material Advantage for Google Workspace
SU024 Material Security Beyond Basic Google DLP: Smart Tricks for Bulletproof Data Security
SU025 Material Security Material Security vs. SEGs
SU026 Panther Security Integrations for Modern SOC Operations | Panther
SU027 Panther Docs Material Security Logs | Panther Docs
SU028 Material Security How Cabinetworks Secured Its Workspace | Cabinetworks | Material Security
SU029 Material Security How Color Protects Sensitive Health Data | color | Material Security
SU030 Material Security Faster Phishing Response | Lyft | Material Security
SU031 Material Security MARS Gets Visibility and Faster Response | Mars | Material Security
SU032 Material Security 91% Phishing Triage Reduction | Gusto | Material Security
SU033 Material Security Email Security for Google & M365 | Material Security
SU034 Material Security Automate User-Reported Phishing | Material Security
SU035 Material Security Distribute the Security Burden | Material Security
SU036 Material Security What AI Adoption Actually Requires | Material Security
SU037 Material Security Automating Phishing Reports at Scale | Material Security
SU038 Material Security How MARS Protected Sensitive Data | Material Security
SU039 Material Security Automate Phishing Triage with Tines | Material Security
SR001 Material Security Information we collect | Material Security Privacy Policy
SR002 Material Security Material Security Material Trust Center | Powered by SafeBase
SR003 Material Security Building Trustworthy ML at Material Security
SR004 Material Security Material Security for Google Workspace
SR005 Material Security Material Security for Microsoft 365
SR006 Material Security Material Security vs. SEGs
SR007 Material Security Email Security for Google & M365 | Material Security
SR008 Material Security How Headway Protects Mental Health Data | Headway | Material Security
SR009 Material Security How Stake Secures Its Cloud Workspace | Stake | Material Security
SR010 Material Security Email Security Upgrade | Pager Duty | Material Security
SR011 Material Security MARS Gets Visibility and Faster Response | Mars | Material Security
SR012 Material Security How Cabinetworks Secured Its Workspace | Cabinetworks | Material Security
SR013 Business Wire Material Security Reaches $1.1 Billion Valuation for ‘Zero Trust’ Security on Microsoft and Google Email
SR014 FBI IC3 2025 Internet Crime Report
SR015 Microsoft Microsoft Digital Defense Email Threats Report Q2 2026
SR016 Verizon 2026 Data Breach Investigations Report
SR017 Proofpoint 2024 State of the Phish
SR018 CISA Cybersecurity Advisories
SR019 Morgan Lewis Cybersecurity & Privacy 2026: Enforcement & Regulatory Trends
SR020 Debevoise Data Blog Cybersecurity Incident Disclosure Form 8-K Tracker: Two-Year Update
SR021 DFIN SEC Cybersecurity Incident Disclosure Rules
SR022 Google Cloud Google Cloud Trust Center
SR023 Google Workspace Help Google Workspace legal and compliance
SR024 Microsoft Microsoft Trust Center product overview
SR025 Microsoft Learn Why do I need Microsoft Defender for Office 365?
SR026 Google Workspace Help Advanced phishing and malware protection | Gmail | Google Workspace Help
SR027 Panther Docs Material Security Logs | Panther Docs
SR028 Panther Security Integrations for Modern SOC Operations | Panther
SR029 Material Security Introducing the OAuth Remediation Agent | Material Security
SR030 Material Security What AI Adoption Actually Requires | Material Security
SR031 Material Security Automating Phishing Reports at Scale | Material Security
SR032 Material Security How Color Protects Sensitive Health Data | color | Material Security
SR033 Material Security Third Party Subprocessors of Personal Data | Material Security
SR034 CISA Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) | CISA
SR035 CISA CIRCIA FAQs | CISA
SR036 NIST Cybersecurity Framework
SR037 NIST NIST Special Publication 800-61 Rev. 3
SR038 Google Cloud Cloud Data Processing Addendum | Google Cloud
SR039 Microsoft Microsoft Products and Services Data Protection Addendum
SV001 Business Wire Material Security Reaches $1.1 Billion Valuation for ‘Zero Trust’ Security on Microsoft and Google Email
SV002 Business Wire Material Security Raises $40 Million Series B To Protect the World’s Email From the Next SolarWinds Attack
SV003 Material Security Cloud Workspace Security Platform | Material Security
SV004 Material Security Helping Secure Our Customers | Material Security
SV005 Material Security How Headway Protects Mental Health Data | Headway | Material Security
SV006 Material Security How Stake Secures Its Cloud Workspace | Stake | Material Security
SV007 Material Security MARS Gets Visibility and Faster Response | Mars | Material Security
SV008 Material Security Material Security vs. SEGs
SV009 Windsor Drake Cybersecurity Valuation Report 2026
SV010 Windsor Drake Cybersecurity Valuations: Q2 2026
SV011 CompaniesMarketCap CrowdStrike (CRWD) - Market capitalization
SV012 CompaniesMarketCap Zscaler (ZS) - Market capitalization
SV013 CompaniesMarketCap Palo Alto Networks (PANW) - Market capitalization
SV014 CompaniesMarketCap Microsoft (MSFT) - Market capitalization
SV015 CompaniesMarketCap Okta (OKTA) - Market capitalization
SV016 CrowdStrike Investor Relations SEC Filings | CrowdStrike Holdings, Inc.
SV017 Zscaler Investor Relations SEC Filings | Zscaler, Inc.
SV018 Microsoft Investor Relations Microsoft Investor Relations - SEC Filings
SV019 Palo Alto Networks Annual Reports | Palo Alto Networks
SV020 Zscaler Annual Reports | Zscaler, Inc.
SV021 Okta Okta Inc. - Financials - Annual Reports
SV022 Microsoft Corporation SEC Filings | Microsoft Corporation
SV023 Palo Alto Networks SEC Filings | Palo Alto Networks
SV024 Proofpoint Thoma Bravo Completes Acquisition of Proofpoint
SV025 Permira Permira Completes Acquisition of Mimecast
SV026 Material Security Material Security for Google Workspace
SV027 Material Security Material Security for Microsoft 365
SV028 Material Security Introducing the OAuth Remediation Agent | Material Security
SV029 Material Security Automated Remediation + Deeper Context | Material Security
SV030 Material Security What AI Adoption Actually Requires | Material Security
SV031 Proofpoint State of the Phish
SV032 Material Security Email Security for Google & M365 | Material Security