Abnormal Security website screenshot

Abnormal Security

Abnormal Security (operating under the abnormal.ai brand) is an AI-native email and SaaS security platform that uses behavioral AI to model normal communication and identity behavior, then detect socially engineered email attacks, business email compromise, vendor email compromise, and account takeovers across Microsoft 365, Google Workspace, Slack, Zoom, and Microsoft Teams. The Behavior Platform is paired with AI Security Agents (AI Security Mailbox, AI Phishing Coach, AI Data Analyst) and exposes a gated REST API at api.abnormalplatform.com for SOC, SIEM, SOAR, and ticketing integrations. 4,500+ customers including 25% of the Fortune 500; named a 2024 Gartner Magic Quadrant Leader for Email Security Platforms.

Abnormal Security publishes 1 API on the APIs.io network. Tagged areas include Cybersecurity, Email Security, Account Takeover, Behavioral AI, and SaaS Security.

Abnormal Security’s developer surface includes developer portal, documentation, engineering blog, and 10 more developer resources.

25.1/100 emerging ▬ flat Agent 3/100 human only Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFree
1 APIs 11 Features 5 Use Cases
CybersecurityEmail SecurityAccount TakeoverBehavioral AISaaS SecurityPhishingBEC

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 25.1/100 · emerging
Contract Quality 0.0 / 25
Developer Ergonomics 3.9 / 20
Commercial Clarity 11.6 / 20
Operational Transparency 2.7 / 13
Governance 0.0 / 12
Discoverability 6.9 / 10
Agent readiness — 3/100 · human only
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 10
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/abnormal-security: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 1

Individual APIs this provider publishes, each with its own machine-readable definition.

Abnormal Security Platform API

The Abnormal Security Platform REST API at api.abnormalplatform.com gives customers and integration partners programmatic access to detected threats, attack cases, abuse mailbox...

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Abnormal Security Rate Limits

2 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Features 11

Notable capabilities this provider offers.

Behavior Platform

AI-native platform that models normal email and identity behavior to detect socially engineered attacks

Inbound Email Security

Autonomous AI defense against phishing, BEC, vendor email compromise, and other inbound email attacks

Account Takeover Protection

Detection and mitigation of account takeovers across email and identity platforms

Security Posture Management

Detection of Microsoft 365 misconfigurations before attackers can exploit them

Email Productivity

Personalized graymail filtering to reduce inbox noise without compromising security

Misdirected Email Prevention

Detect and prevent emails sent to the wrong recipient before data is exposed

AI Security Mailbox

AI agent that responds to user-reported emails and coaches users at superhuman speed

AI Phishing Coach

Hyper-personalized security training that reduces phishing susceptibility

AI Data Analyst

Natural-language security reporting that produces board-ready insights

SaaS Account Takeover Protection

Account takeover protection for SaaS applications such as Slack and Zoom

Messaging Security

Detection of malicious content inside Microsoft Teams

Scroll for all 11

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Abnormal Security Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Abnormal Security Trust Center

SOC 2, ISO 27001, FedRAMP, GDPR, CSA STAR

SECURITY

Use Cases 5

What developers build with this provider.

BEC and Phishing Defense

Stop business email compromise, phishing, and vendor email compromise on Microsoft 365 and Google Workspace

Account Takeover Response

Detect and respond to compromised email and SaaS accounts in near-real time

SOC Automation

Use AI Security Agents to triage user-reported emails and automate SOC workflows

Security Posture Hardening

Continuously identify and remediate Microsoft 365 misconfigurations

Executive Reporting

Use the AI Data Analyst to deliver board-ready security reporting through natural-language queries

Integrations 8

Pre-built integrations with other platforms and tools.

Microsoft 365

Native API-based integration with Microsoft 365 for email and identity protection

Google Workspace

Native API-based integration with Google Workspace email and identity surfaces

Microsoft Teams

Messaging security integration with Microsoft Teams

Slack

SaaS account takeover protection for Slack workspaces

Zoom

SaaS account takeover protection for Zoom accounts

SIEM

REST API forwarding of detected threats and cases into Splunk, Sentinel, Chronicle, and similar SIEMs

SOAR

Bidirectional integrations with Cortex XSOAR, Splunk SOAR, Tines, and other SOAR platforms

ITSM

Ticketing integrations with ServiceNow, Jira, and other ITSM tools

Scroll for all 8

Resources

Get Started 1

Portal, sign-up, and the first successful call

Documentation 1

Reference material describing how the API behaves

Access & Security 2

Authentication, authorization, and security posture

Operate 1

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 5

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: abnormal-security
url: https://raw.githubusercontent.com/api-evangelist/abnormal-security/refs/heads/main/apis.yml
name: Abnormal Security
type: Index
accessModel:
  pricing: free
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Free
  confidence: medium
  source:
  - plans
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/abnormal-security.png
tags:
- Cybersecurity
- Email Security
- Account Takeover
- Behavioral AI
- SaaS Security
- Phishing
- BEC
description: Abnormal Security (operating under the abnormal.ai brand) is an AI-native email and SaaS security platform that
  uses behavioral AI to model normal communication and identity behavior, then detect socially engineered email attacks, business
  email compromise, vendor email compromise, and account takeovers across Microsoft 365, Google Workspace, Slack, Zoom, and
  Microsoft Teams. The Behavior Platform is paired with AI Security Agents (AI Security Mailbox, AI Phishing Coach, AI Data
  Analyst) and exposes a gated REST API at api.abnormalplatform.com for SOC, SIEM, SOAR, and ticketing integrations. 4,500+
  customers including 25% of the Fortune 500; named a 2024 Gartner Magic Quadrant Leader for Email Security Platforms.
created: '2026-05-23'
modified: '2026-05-23'
specificationVersion: '0.19'
apis:
- aid: abnormal-security:abnormal-security-api
  name: Abnormal Security Platform API
  tags:
  - Threats
  - Cases
  - Abuse Mailbox
  - Account Takeover
  - Behavior Platform
  humanURL: https://portal.abnormalsecurity.com
  baseURL: https://api.abnormalplatform.com
  properties:
  - url: https://portal.abnormalsecurity.com
    type: Portal
    title: Abnormal Security Portal (gated)
  - url: https://abnormal.ai/products
    type: Documentation
    title: Abnormal Security Products Overview
  description: The Abnormal Security Platform REST API at api.abnormalplatform.com gives customers and integration partners
    programmatic access to detected threats, attack cases, abuse mailbox submissions, account takeover events, and security
    posture findings produced by the Abnormal Behavior Platform. The API is commonly used to forward attack data into SIEMs,
    drive SOAR playbooks, and integrate Abnormal into ticketing and incident workflows. Documentation and API credentials
    are provisioned through the Abnormal customer portal.
common:
- type: TrustCenter
  url: security/abnormal-security-trust-center.yml
- type: DomainSecurity
  url: security/abnormal-security-domain-security.yml
- type: LinkedIn
  url: https://www.linkedin.com/company/abnormal-security
- type: Website
  url: https://abnormal.ai/
- type: Portal
  url: https://portal.abnormalsecurity.com
  title: Abnormal Security Customer Portal
- type: Documentation
  url: https://abnormal.ai/products
- type: Blog
  url: https://abnormal.ai/blog
- type: Resources
  url: https://abnormal.ai/resources
- type: ContactSales
  url: https://abnormal.ai/contact
- type: Careers
  url: https://abnormal.ai/careers
- type: Partners
  url: https://abnormal.ai/partners
- type: PrivacyPolicy
  url: https://abnormal.ai/privacy
- type: TermsOfService
  url: https://abnormal.ai/terms
- type: Features
  data:
  - name: Behavior Platform
    description: AI-native platform that models normal email and identity behavior to detect socially engineered attacks
  - name: Inbound Email Security
    description: Autonomous AI defense against phishing, BEC, vendor email compromise, and other inbound email attacks
  - name: Account Takeover Protection
    description: Detection and mitigation of account takeovers across email and identity platforms
  - name: Security Posture Management
    description: Detection of Microsoft 365 misconfigurations before attackers can exploit them
  - name: Email Productivity
    description: Personalized graymail filtering to reduce inbox noise without compromising security
  - name: Misdirected Email Prevention
    description: Detect and prevent emails sent to the wrong recipient before data is exposed
  - name: AI Security Mailbox
    description: AI agent that responds to user-reported emails and coaches users at superhuman speed
  - name: AI Phishing Coach
    description: Hyper-personalized security training that reduces phishing susceptibility
  - name: AI Data Analyst
    description: Natural-language security reporting that produces board-ready insights
  - name: SaaS Account Takeover Protection
    description: Account takeover protection for SaaS applications such as Slack and Zoom
  - name: Messaging Security
    description: Detection of malicious content inside Microsoft Teams
- type: UseCases
  data:
  - name: BEC and Phishing Defense
    description: Stop business email compromise, phishing, and vendor email compromise on Microsoft 365 and Google Workspace
  - name: Account Takeover Response
    description: Detect and respond to compromised email and SaaS accounts in near-real time
  - name: SOC Automation
    description: Use AI Security Agents to triage user-reported emails and automate SOC workflows
  - name: Security Posture Hardening
    description: Continuously identify and remediate Microsoft 365 misconfigurations
  - name: Executive Reporting
    description: Use the AI Data Analyst to deliver board-ready security reporting through natural-language queries
- type: Integrations
  data:
  - name: Microsoft 365
    description: Native API-based integration with Microsoft 365 for email and identity protection
  - name: Google Workspace
    description: Native API-based integration with Google Workspace email and identity surfaces
  - name: Microsoft Teams
    description: Messaging security integration with Microsoft Teams
  - name: Slack
    description: SaaS account takeover protection for Slack workspaces
  - name: Zoom
    description: SaaS account takeover protection for Zoom accounts
  - name: SIEM
    description: REST API forwarding of detected threats and cases into Splunk, Sentinel, Chronicle, and similar SIEMs
  - name: SOAR
    description: Bidirectional integrations with Cortex XSOAR, Splunk SOAR, Tines, and other SOAR platforms
  - name: ITSM
    description: Ticketing integrations with ServiceNow, Jira, and other ITSM tools
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com