Nine modules, one stack

Nine modules.Three areas.One platform.

Conbool covers the entire mail channel: stop attacks, communicate securely, protect your data. Nine modules in one console, from spam defence through encryption and file exchange to archiving, continuity and recovery from Microsoft 365. One admin portal, one audit log, one contract.

What holds the suite together.

All nine modules access the same platform. One contractual relationship, one audit log under GDPR Art. 30, one central admin, operated in Germany, German company.

EU hosting in GermanyISO 27001 certified data centresMulti-tenant capableGDPR Art. 28 DPA
The nine modules

Every module solves a pain point, all nine work together.

Three areas that build on each other: protection stops attacks, communication makes sending secure and legally sound, data makes sure nothing is lost and the business keeps running. Start with one module and add others later without renegotiating.

Inbound protection

MailGuard

Anti-spam, anti-phishing, BEC and CEO fraud detection with behavioral analysis. DACH DLP detectors for German IBAN, VAT ID DE and Swiss UID, social security number and tax ID.

  • Attachment filter with CDR for Office, PDF, HTML and archives, URL rewriting and reputation in real time
  • QR code phishing filter and display name spoofing detection against BEC
  • DACH DLP library with real checksum validation for German, Austrian and Swiss identifiers
Email encryption

SecureMail

S/MIME, OpenPGP and an integrated message portal as a web reader for recipients without a certificate. Native Outlook add-in for Classic, New and Web.

  • Central key management, automatic certificate distribution via LDAP directories
  • Web reader portal as a fallback for the majority of recipients without PKI
  • Policies per tenant and per business unit, multi-tenant capable
Secure file transfer

SecureFiles

Large attachments straight from Outlook with password or recipient authentication. EU hosting, audit log, expiry policies, retrieval log, deletion proof.

  • Recipient authentication via one time password, password or verified identity
  • Audit log per download with timestamp, IP country and user agent
  • Retention periods configurable per package, deletion proof documentable
Central signatures

Disclaimer

Server-side signatures and statutory details from Entra ID, Active Directory or LDAP, per business unit, subsidiary and site. Consistent across Outlook Classic, New, OWA and mobile. Optionally without changing the mail route, through the Outlook add-in alone.

  • Server-side with nothing to install on devices, or without an MX change through the add-in alone
  • Mandatory disclosures under German Commercial Code (HGB) Section 37a and Section 80 AktG embedded automatically
  • Layered disclaimer for groups with several business units and brands
Outbound identity

DMARC Reports

DMARC aggregate and forensic reports, staged reject policy introduction from p=none to p=quarantine to p=reject. BIMI preparation with a verified brand logo.

  • Automated DMARC analysis with SPF and DKIM correlation
  • Staged policy migration to p=reject without breaking business mail
  • BIMI preparation with brand logo verification and VMC guidance
Audit-proof archive

Archive

Legally compliant email archiving directly in the mail flow. Supports GoBD-compliant archiving with 6, 8 and 10 year retention, cleartext search across encrypted messages and an automated deletion concept.

  • Capture without a connector, Exchange connection via journaling
  • Cleartext archive for S/MIME and PGP messages with full-text search
  • Automated deletion after retention expiry including legal hold
Backup for Microsoft 365

365 Backup

Automated backup of mailboxes and online archives, OneDrive, SharePoint, Teams channels, Teams chats, Planner and Entra ID. Individual messages, files and folders come back on their own, without overwriting whole mailboxes.

  • Eight sources on one schedule: Exchange Online, online archive, OneDrive, SharePoint, Teams channels, Teams chat, Planner, Entra ID
  • Restore individual items from a chosen point in time
  • Operated and stored in German data centres
Training and phishing simulation

Awareness

Realistic phishing simulations, short training right afterwards and reports that carry the NIS2 training obligation. Evaluation happens at group level, never at the individual.

  • Programmes across several months instead of one off campaigns
  • Training on exactly the technique someone reacted to
  • Reports per department and period, exportable for audits
Keep working during an outage

Email continuity

Every incoming message is stored as it passes the gateway. When Microsoft 365 is down, your team carries on through a separate web interface, with nothing to switch over.

  • No manual step in an emergency, the store runs continuously
  • Browser access, nothing to set up on devices
  • Independent of the mailbox system, on premises Exchange included
One platform, nine modules

What connects the nine modules.

Conbool is not a collection of loosely coupled tools. Every module sits on the same multi tenant platform with central administration, a shared audit log and common identity management.

One admin portal

All policies, tenants, roles and logs in the same console. No switching between tools, no duplicate user directories.

One audit log

GDPR Art. 30 met. Every message, every download, every signature application in one audit-proof log.

Multi-tenant native

Groups with subsidiaries, MSPs with end customers. Policies per tenant, separate audit logs, one console.

EU hosting Germany

Data center in Germany, German GmbH as contracting party, DPA under GDPR Art. 28. Sub-processors with Standard Contractual Clauses are listed in the DPA.

Frequently asked questions about the suite

Do we have to use all nine modules.
No. The suite license is billed per mailbox, modules can be added. You can start with one module, for example MailGuard or SecureMail, and add the remaining modules later, without new contracts, a new onboarding phase or an additional admin portal.
How does Conbool differ from a Microsoft 365 add-on.
Conbool sits in front of Microsoft 365 as its own security layer and can run both as a pre-filter and as a full replacement. EU hosting in Germany, German GmbH as contracting party, DPA under GDPR Art. 28. No third-country transfer to US hyperscalers without Standard Contractual Clauses and a Transfer Impact Assessment.
Which module solves which pain point.
MailGuard for inbound protection against spam, phishing and BEC. SecureMail for confidential communication with clients, patients or customers. SecureFiles for large attachments and confidential file handovers. Disclaimer for central mandatory disclosures and consistent signatures. DMARC Reports for outbound identity and domain protection against spoofing.
How does the suite integrate with Microsoft 365.
MX switch technically in under 30 minutes, parallel operation possible. Outlook add-ins rolled out to all mailboxes via the Microsoft 365 Admin Center. SSO via Entra ID, automatic provisioning when an employee joins, immediate revocation when they leave. Existing DMS synchronizations via IMAP, POP3 or MAPI remain functional.
Can a group or MSP manage multiple tenants in one console.
Yes. Conbool is multi-tenant capable with policies per tenant. Groups can manage subsidiaries and business units separately, MSPs can administer end customers separately, all in one console with separate audit logs and separate contractual relationships depending on the setup.

See the suite in 30 minutes in your own setup.

Demo in 30 minutes. Suite stack with MailGuard, SecureMail, SecureFiles, Disclaimer and DMARC. EU hosting in Germany.

MailGuardSecureMailSecureFilesDisclaimerConbool DMARC