← Back to all sparks
I

INKY

SUPPORT
Velocity6.3

Email security platform protecting against phishing, malware, and account takeover

INKY is wiring an LLM into email security while binding itself tighter to Kaseya

email-securityllm-analysismsp-integrationstriageoutbound-protection
Current state
INKY ships a dashboard release every one to two weeks, moving from 1.8.5 to 1.9.6 since May. The functional center is the Triage workspace, which pulled detection review, message actions, and account-takeover enforcement into one place and made ATO configurable without a SIEM. July added Smart Insights, an LLM second opinion on any inbound message with a plain-language explanation, gated to INKY Pro with a per-team opt-out. The releases since have returned to widening the rule engine and the integration surface around it.
Where it's heading
Two threads run in parallel. One is analyst experience: consolidate review into Triage, then explain verdicts rather than just issue them. The other is distribution — Autotask ticketing, Gradient billing reconciliation, KaseyaOne role alignment, CyberHoot training recognition — all of which make INKY easier to run inside a Kaseya-provisioned MSP stack and harder to swap out of one. The newest release refines both rather than extending either: a bracketed-subject rule condition, and Autotask ticketing split per report type so a phishing-only configuration is finally saveable.
Prediction
Expect Smart Insights to expand from an on-demand second opinion into something that annotates the Triage queue by default, since that is where its explanations would actually save review time. On the integration side the pattern is one new partner platform per release, so the next addition is more likely another MSP tool than a change to detection itself.

Recent moves

  1. 1mo ago

    v1.9.5: Mesh relay detection and CyberHoot training support

    Recognizing Mesh as an upstream provider lets INKY recover the real sending IP, HELO, and MAIL FROM from the hop where Mesh accepted a message, so authentication runs against the actual sender rather than the relay — including three EU ranges Mesh's own SPF record omits. CyberHoot joins the recognized phishing-training platforms, replacing manual allow-list entries. Both are the same move: absorbing per-customer exceptions into the product.

  2. 1mo ago

    v1.9.3: Smart Insights brings an LLM verdict to every message

    ⚡ SPARK

    Smart Insights is the release the rest of this arc orbits: an LLM verdict, trickiness rating, and written rationale attached to any inbound message, sold on INKY Pro with a per-team switch that keeps a team's mail out of the model entirely. Everything shipped since has refined the surfaces around it rather than extended it.

  3. 1mo ago

    v1.9.2: Autotask PSA ticketing for INKY alerts

    Security events now land in the Autotask queue an MSP already works from, with category and priority pulled live from the customer's own instance and each INKY team mapped to an Autotask company. Gradient MSP arrived in the same release for billing reconciliation. Both are plumbing for partners rather than detection work, and both are scoped to Kaseya-provisioned MSPs.

  4. 2mo ago

    v1.9.1: Tabbed signature editor and redesigned Triage

    Triage gained dedicated Burst Management and Outbound Protection tabs with live counts, and the signature editor became a tabbed workspace with per-field styling and a floatable preview. Splitting Triage into counted queues is the tell that reviewers were scrolling one combined list — the workspace is being tuned for daily use rather than demos.

  5. 2mo ago

    v1.8.8: Email signatures management page

    A dedicated signatures page with per-user review, a floating live preview, and pagination for large teams, alongside standardized CSV exports and resizable audit-log columns. Signature management is adjacent to security rather than part of it, and its arrival marks INKY widening into general mail administration.

  6. 3mo ago

    v1.8.5: Triage page and SIEM-free account-takeover detection

    The release that established the current shape: a Triage page combining detection review, full message content, and approve/reject controls, plus account-takeover detection configurable from the dashboard with no SIEM required. Dropping the SIEM dependency put ATO enforcement within reach of teams without a security operations stack, and every release since has built on this workspace.