← Back to all sparks
I

INKY

SUPPORT
Velocity6.3

Email security platform protecting against phishing, malware, and account takeover

INKY is wiring an LLM into email security while binding itself tighter to Kaseya.

email-securityphishing-detectionmsp-channelllm-assisted-detectionaccount-takeoverkaseya-ecosystem
Current state
INKY ships a dashboard release every one to two weeks, moving from 1.8.5 to 1.9.5 since May. The functional center is the Triage workspace, which pulled detection review, message actions and account-takeover enforcement into one place and made ATO configurable without a SIEM. July added Smart Insights, an LLM second opinion on inbound mail, plus automatic Autotask ticketing. Running alongside the security work, email-signature management has grown from a single page in June into a tabbed editor with per-field styling.
Where it's heading
Two threads are pulling in the same direction. Detection is becoming AI-assisted and explainable, with Smart Insights returning a verdict, a trickiness rating and a written rationale rather than a score. And the managed-service channel is being deepened at every layer — Autotask billing, Autotask ticketing, Kaseya-provisioned entitlements, a third-party training platform slotted in as an option. INKY is optimizing for the provider reselling it across many tenants, not the employee reading the mail.
Prediction
Smart Insights is gated to Pro with a per-team opt-out, which points to it being extended and monetized further rather than made universal. Mesh was added as a recognized upstream provider under an auto-detect setting, so additional relay providers are the obvious continuation of that work.

Recent moves

  1. 6d ago

    v1.9.5: Mesh relay detection and CyberHoot training support

    INKY now recognizes mail relayed through Mesh and recovers the original sending IP, HELO and MAIL FROM so authentication runs against the real sender rather than the relay. Notably it identifies three EU ranges Mesh's own SPF record omits, which is the kind of detail that separates working detection from silent misses.

  2. 13d ago

    v1.9.3: Smart Insights brings an LLM verdict to every message

    ⚡ SPARK

    The clearest direction change in this release train: detection stops being a score and starts being an argument a human can read. It also introduces the first per-team data-governance switch in the product, which says as much about INKY's customers as the feature does.

  3. 20d ago

    v1.9.2: Autotask PSA ticketing for INKY alerts

    Security events now open tickets directly in Autotask, with category and priority options pulled live from the customer's own instance and each INKY team mapped to an Autotask company. It is another strand tying INKY into the Kaseya stack its resellers already run on.

  4. 26d ago

    v1.9.1: Tabbed signature editor and redesigned Triage

    The signature editor becomes a tabbed workspace with per-field font, weight, size and color overrides, and Triage gains tabs with live counts per queue. Both are the second pass over surfaces introduced a month earlier, which is how this product tends to move: ship the page, then make it workable.

  5. 1mo ago

    v1.8.8: Email signatures management page

    Team and per-user email signatures get a management page with a live previewer and a per-user view explaining how each signature resolves. Signature management sits oddly beside phishing detection, but for the providers INKY sells through it is one more tenant-wide setting they no longer administer elsewhere.

  6. 2mo ago

    v1.8.5: Triage page and SIEM-free account-takeover detection

    Triage arrives as the single place to review detections and act on messages, and account-takeover detection becomes configurable from the dashboard with no SIEM in the loop. Dropping the SIEM dependency widens who can actually turn ATO enforcement on, and every release since has built on this page.