# Olyteck Guard > EU-hosted email threat protection for Microsoft 365 — catches the impersonation, > invoice/CEO fraud and advanced phishing (lookalike & homoglyph domains, QR-code > "quishing", callback/TOAD scams, reply-chain/thread hijacking, malicious links) > that the Microsoft baseline lets through. A layer on top of M365: live in > minutes, no mail rerouting, nothing to rip out. Operated by Olyteck (France). Principle: "counts findings, never files" — Guard stores signals, scores and verdicts, never message bodies or attachments (analysed transiently, never stored). EU-hosted (Scaleway PAR, France), GDPR-aligned, no third-party AI. Read-only first; every action (warning banner, move-to-junk, block) is reversible and logged. Detection is signal- and technique-based (authentication, domains, links, QR, patterns), not semantic reading of your mail. ## What Guard catches (40+ detection models) - **Spoofing & authentication** — DMARC/SPF/DKIM failures, exact-domain spoofing, return-path / reply-to mismatch, freemail reply-to. - **Impersonation** — CEO/VIP and IT display-name impersonation (executives detected automatically), lookalike + homoglyph/cousin domains (punycode, Cyrillic/Greek confusables), brand impersonation, reply-chain / thread hijacking. - **BEC & financial fraud** — invoice and bank-details (IBAN) fraud with pressure cues — the scam behind most six-figure wire losses. - **Malicious links & attachments** — credential-harvesting / fake Microsoft sign-in pages, hidden redirects, shorteners, risky/macro/double-extension files; dangerous links rewritten to a safe click, blocked when confirmed malicious. - **QR-code phishing (quishing)** — decodes QR codes hidden in image attachments, inline parts and SVGs, then re-checks where they really lead. - **Callback phishing (TOAD)** — emails with no link, just a fake support number designed to get staff on the phone. ## How it works 1. **Connect Microsoft 365** — sign in, one admin approval. Read-only via Graph; no rerouting, no settings changed, switch off anytime (~2 minutes). 2. **Choose who to protect** — VIPs and IT detected for you; pay only for the mailboxes you choose. Shared, disabled and guest mailboxes are free. 3. **Protected from that moment** — incoming mail watched in real time; threats get a plain-language warning banner or move-to-junk, all reversible. A public "why was this flagged?" page and one-click company-wide takedown teach and protect staff. ## Pricing Per protected mailbox / month: **Essentials €2.50**, **Business €4.50** (+ custom rules & model tuning, client reporting PDF/CSV/XLSX, 1-year retention, priority support). **14-day free trial, no card** — see real threats land in your own mail before you pay. MSP and Enterprise (dedicated single-tenant, SSO, custom DPA) are sales-led. No minimum contract; cancel anytime, prorated. ## Who it's for SMB IT / Microsoft 365 admins, CEOs and owners worried about wire fraud, and CISOs / security leads who need documented, EU-hosted, layered email controls for cyber-insurance and audit. ## Company & links - Product: Olyteck Guard · Parent: Olyteck (France, EU-hosted — Scaleway PAR) - Contact: contact@olyteck.com - Website: https://guard.olyteck.com/ - Trust Center: https://olyteck.com/trust/guard - Olyteck family (Cyber, Ask, Studio, Guard): https://olyteck.com/ - Product briefs: https://cyber.olyteck.com/llms.txt · https://ask.olyteck.com/llms.txt · https://studio.olyteck.com/llms.txt