I believe the main areas for improvement for Sublime Security are ease of onboarding and learning, as the platform has many powerful capabilities, making it take some time for new analysts to become comfortable with all the features and detection logic. I would also appreciate continued improvements in customization and integration, especially for fitting it smoothly into different SOC workflows. Regarding needed improvements, I think the documentation is generally useful, but I would appreciate more beginner-friendly guidance and practical SOC examples, particularly around setting up detections, tuning rules, and integrating Sublime Security with SIEM and SOAR platforms. The API and integration options are already strong, but clearer step-by-step examples would make it easier for analysts to get started and build more advanced workflows.
Sublime Security could be improved by enabling more integration, better customization of alerts, and more detailed reporting. I would also like more flexibility in detection tuning to reduce false positives and make investigations even more efficient.
Associate Software Engineer at a computer software company with 201-500 employees
Real User
Top 5
Jul 3, 2026
I would say there are very minimal changes needed regarding Sublime Security; for first-time users, it can be difficult knowing how to write the tool. Having some templates available would improve the experience. My advice for others looking into using Sublime Security is that each edition would be helpful for initial users, and users should set templates in, which can be added; right now, I am not trying anything new, as this is cool.
Based on the feedback we receive from our partners and their end-users, there are two main areas for improvement: the learning curve and pricing for smaller organizations. First, while the platform is incredibly powerful, it isn't simply 'plug-and-play.' Security teams need to invest time into learning the product to extract its full value. Second, the cost can feel a bit steep for small-to-medium-sized businesses (SMBs). However, we always caveat this by looking at the ROI: a single breach could put a small company completely out of business. While the upfront cost might seem high to them, preventing just one catastrophic breach means the tool instantly pays for itself.
Security Engineer at a financial services firm with 201-500 employees
Real User
Jan 27, 2026
We are using a traditional security gateway and we have a lot of challenges with that, which is why we are trying to get something based on ML and AI, something that can address our current challenges. That is why we are looking for a new solution that is AI-based. With Sublime Security, so far, I have seen a lot of false positives, and it is something that can bring a lot of administrative overhead.
Manager Security Operations Center at a educational organization with 10,001+ employees
Real User
Top 10
Oct 10, 2025
I know that a lot of time has been invested in improving the efficacy of the platform, and it shows; it performs very well. Moving forward, I think our focus should be on how to achieve better integration with other systems. While they do provide API-level access and web hooks, I believe more out-of-the-box integrations with SOAR platforms and SIEM tools would enhance Sublime's value. This would allow it to be integrated more closely with the workflows of various teams and could potentially increase its market appeal. From my perspective, the tool itself functions exceptionally well, which gives me confidence in the system. I want to see this functionality extend to other tools that I use, enabling faster automation and improved workflows for the team, particularly from a security operations standpoint. I have no critiques regarding the tool itself. They've done an outstanding job and are maintaining high quality throughout their development process. They have a great product, and it's essential that they continue to uphold that standard, even though it requires significant effort.
Head of IT at a manufacturing company with 51-200 employees
Real User
Nov 30, 2023
The ability for users to look at their own quarantine box needs improvement. So at the moment, it doesn't give you the ability to see every email that has been quarantined. No end-user has the ability to see what's being quarantined. It's only people who have access to the back-end platform that can actually see what has been quarantined. The end user doesn't know if they have an email that has been quarantined, only if they're expecting something that didn't come through. In future releases, I would just like to see that ability for users to see what's being quarantined and what's not quarantined but safe. Just those genuine false positives.
Sublime Security provides innovative email security solutions focusing on advanced threat detection and customization, designed to tackle complex security challenges in enterprise environments.
True to its name, Sublime Security delivers a robust platform for email security that empowers professionals with precision tools for threat hunting and detection. It stands out for its focus on customization, allowing users to tailor security protocols to specific threats, enhancing detection...
I believe the main areas for improvement for Sublime Security are ease of onboarding and learning, as the platform has many powerful capabilities, making it take some time for new analysts to become comfortable with all the features and detection logic. I would also appreciate continued improvements in customization and integration, especially for fitting it smoothly into different SOC workflows. Regarding needed improvements, I think the documentation is generally useful, but I would appreciate more beginner-friendly guidance and practical SOC examples, particularly around setting up detections, tuning rules, and integrating Sublime Security with SIEM and SOAR platforms. The API and integration options are already strong, but clearer step-by-step examples would make it easier for analysts to get started and build more advanced workflows.
Sublime Security could be improved by enabling more integration, better customization of alerts, and more detailed reporting. I would also like more flexibility in detection tuning to reduce false positives and make investigations even more efficient.
I would say there are very minimal changes needed regarding Sublime Security; for first-time users, it can be difficult knowing how to write the tool. Having some templates available would improve the experience. My advice for others looking into using Sublime Security is that each edition would be helpful for initial users, and users should set templates in, which can be added; right now, I am not trying anything new, as this is cool.
Based on the feedback we receive from our partners and their end-users, there are two main areas for improvement: the learning curve and pricing for smaller organizations. First, while the platform is incredibly powerful, it isn't simply 'plug-and-play.' Security teams need to invest time into learning the product to extract its full value. Second, the cost can feel a bit steep for small-to-medium-sized businesses (SMBs). However, we always caveat this by looking at the ROI: a single breach could put a small company completely out of business. While the upfront cost might seem high to them, preventing just one catastrophic breach means the tool instantly pays for itself.
We are using a traditional security gateway and we have a lot of challenges with that, which is why we are trying to get something based on ML and AI, something that can address our current challenges. That is why we are looking for a new solution that is AI-based. With Sublime Security, so far, I have seen a lot of false positives, and it is something that can bring a lot of administrative overhead.
I know that a lot of time has been invested in improving the efficacy of the platform, and it shows; it performs very well. Moving forward, I think our focus should be on how to achieve better integration with other systems. While they do provide API-level access and web hooks, I believe more out-of-the-box integrations with SOAR platforms and SIEM tools would enhance Sublime's value. This would allow it to be integrated more closely with the workflows of various teams and could potentially increase its market appeal. From my perspective, the tool itself functions exceptionally well, which gives me confidence in the system. I want to see this functionality extend to other tools that I use, enabling faster automation and improved workflows for the team, particularly from a security operations standpoint. I have no critiques regarding the tool itself. They've done an outstanding job and are maintaining high quality throughout their development process. They have a great product, and it's essential that they continue to uphold that standard, even though it requires significant effort.
The ability for users to look at their own quarantine box needs improvement. So at the moment, it doesn't give you the ability to see every email that has been quarantined. No end-user has the ability to see what's being quarantined. It's only people who have access to the back-end platform that can actually see what has been quarantined. The end user doesn't know if they have an email that has been quarantined, only if they're expecting something that didn't come through. In future releases, I would just like to see that ability for users to see what's being quarantined and what's not quarantined but safe. Just those genuine false positives.