Annika Grunewaldt
Annika Grunewaldt Co-Founder & CEO
Kateryna Karnaukh
Kateryna Karnaukh Co-Founder & CMO
Oleksii Antypov
Oleksii Antypov Co-Founder & CTO

The team behind ABOK

Help us build the thing you keep wishing existed.

AI made a convincing fake cheap to produce. The tools that stop it are fragmented, expensive, and built for teams with a security department. We are building the one console that covers it — and we want to hear how the problem actually shows up for you.

"For a world where you always know who you are communicating with."

ABOK Security

Supported by

  • Kofinanziert von der Europäischen Union
  • Land Berlin
  • SIBB

What are the problems we want to solve?

01

AI made impersonation easy and convincing.

What used to take a skilled attacker hours now takes anyone a prompt. AI-generated phishing sees 54% click-through, over four times the rate of human-drafted lures. The barrier to a believable fake is gone.

02

Defences are fragmented and don’t sync.

A CISO needs four to six tools to cover impersonation, none of which coordinate: DMARC tooling, awareness training, brand monitoring, lookalike detection and identity verification. SMBs can’t afford the stack at all, and for enterprises it’s a constant, annoying juggle.

Impersonation stopped being a niche threat. It is cheap to run, hard to spot, and there is not a single tool that covers all attack vectors.
Oleksii Antypov Oleksii Antypov Co-Founder & CTO

03

MSPs carry the risk and the liability.

Live DNS changes across client environments feel like Russian roulette: one misconfiguration downs a client’s mail flow. Spoofing, BEC and a failed NIS2 audit all happen on your watch, and clients want full protection with zero downtime and no extra spend.

04

Tool sprawl eats MSPs margin.

Teams spend half the day toggling client consoles, copy-pasting DNS records and parsing raw XML. High-skilled engineers do low-margin, repetitive work, so every new client means more headcount and thinner profit.

OUR Mission

"Make impersonation defence so simple that every organisation can protect itself."

What we think.

Email security should be something anyone can get right, not just the people with a security team. No business should lose money or standing to a spoofed email. So we take the complicated tools, make them simple, and share what we know, so any organisation can protect its domains with confidence.

We want to see DMARC everywhere, email infrastructure that holds, and every real message landing safely in the inbox. Get that right and businesses can get back to the work that actually matters.

Email security shouldn’t require a cybersecurity degree. My focus is making complex protection clear and approachable for everyone. When people understand it, they can protect their brand and build real trust with every message they send.
Annika Grunewaldt Annika Grunewaldt Co-Founder & CEO

How we plan to do it: one platform, three layers of trust.

ABOK Security establishes who people really are across every channel an attacker can exploit, then keeps that identity enforced as systems change. It runs from one white label console, one account per organisation you protect.

Live first

Human layer training.

Run real AI-assisted phishing, voice and video lures against your own employees, in the context they actually work in, triggered automatically, with reporting HR and compliance can actually use.

Next

Email and brand trust.

Get DMARC, SPF, DKIM and BIMI to enforcement and keep them there. Watch certificate logs, new domain registrations and DNS for lookalikes targeting your client, and run takedowns when something credible appears.

On the roadmap

Verified identity.

Make an S/MIME certificate as simple as turning on MFA, so the person on the email or the call is provably real.

We start where the urgency is highest. Training and verified identity follow on the same platform and the same account.

Why we are the team to build it.

This is not our first look at this market. We have built and run email authentication for service providers and in-house security teams, and we kept seeing the same thing. The people who fixed authentication then wanted training. The ones running training wanted brand monitoring. The ones worried about fraud on calls wanted verified identity. No vendor did all of it, so we are building the one we kept wishing for, EU-native from day one.

Design partners go first.

You get the platform before it is a product everyone has, founder level support, and a direct say in what we build next. Three fields, two minutes.

Get early access