# Abnormal Inbound Email Security privacy rating

Cloud email security from Abnormal AI that connects to Microsoft 365 and Google Workspace through their APIs and uses behavioral AI to detect phishing, business email compromise and account takeover. It does not need MX record changes.

## Summary

Abnormal Inbound Email Security scores 36 out of 100 (grade F) on the spam and virus filtering criteria. It meets 2 of 7 criteria: tells users about requests and security headers. It partly meets no ads or data sales, independent audit and transparency report. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: Mozilla HTTP Observatory grade A+.

- Website: https://abnormal.ai/platform/inbound-email-security
- Jurisdiction: United States. Five Eyes member. Subject to the US CLOUD Act.
- Platforms: Web
- Home page trackers: Google Tag Manager
- Category: [Spam and virus filtering](https://privacyratings.com/spam-filters/)
- Grade: F (36/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | No | Closed source. |  |
| No trackers or telemetry | No | The website loads Google Tag Manager, and the privacy policy allows third-party cookies, web beacons and pixels for advertising and analytics. | https://abnormal.ai/legal/privacy |
| No ads or data sales | Partial | Paid business service with no ads, but the privacy policy allows sharing data with advertising providers for interest-based ads and using it to show ads on other websites. | https://abnormal.ai/legal/privacy |
| Independent audit | Partial | Abnormal holds ISO/IEC 27001, 27701 and 42001 certification and has an annual SOC 2 audit, but reports are only shared under a non-disclosure agreement. | https://abnormal.ai/trust-center |
| Transparency report | Partial | The data processing addendum describes legal review of government requests and challenges to unlawful ones, but no request counts are published. | https://legal.abnormalsecurity.com/legal-hub/abnormal-security-data-processing-addendum-91eb5b0b |
| Tells users about requests | Yes | The data processing addendum promises to notify customers of legally binding government requests for their data where permitted by law, and to seek a waiver when notice is prohibited. | https://legal.abnormalsecurity.com/legal-hub/abnormal-security-data-processing-addendum-91eb5b0b |
| TLS configuration | Not tested yet | Not tested yet. |  |
| Security headers | Yes | Grade A+ (110/100+) | https://developer.mozilla.org/en-US/observatory/analyze?host=portal.abnormalsecurity.com |
| Modern web standards | Not tested yet | Not tested yet. |  |

Source: https://privacyratings.com/spam-filters/abnormal-inbound-email-security/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/spam-filters/abnormal-inbound-email-security.md
