
Material Security
Unified email, file, identity and app security for Google Workspace and Microsoft 365
By Material Security · 4.0/5 Value-Position score (estimate)
Positioning guardrails
Best for
- Security teams standardized on Google Workspace or Microsoft 365 that need defense beyond native filters.
- Organizations that must govern OAuth grants and third-party AI agents with access to mail and files.
- Teams that need to find and remediate sensitive data such as PHI or PII shared too broadly in Drive and email.
- Incident response teams that want to contain account takeovers without blocking legitimate users.
- Security leaders consolidating several workspace point tools into one API-deployed platform.
Ideal size: 300–10,000 employees people · Mid-market to enterprise with a dedicated security or IT team
Not for
- Companies running email and file workloads outside Google Workspace and Microsoft 365.
- Buyers looking for endpoint, network, or cloud-infrastructure security rather than workspace protection.
- Very small businesses without a dedicated security or IT admin function.
- Organizations that require fully self-hosted, on-premises deployment.
- Teams seeking a free tier, since list pricing starts at $4 per user per month plus storage fees.
Value metrics scorecard
Time-to-Value
Same day; API deployment in minutes
~1 days to first production value
Total Cost of Ownership
$36,000/yr
Starts at $48 · Per user per month billed annually: $4 Essentials, $6 Advanced, plus a Shared Drive storage fee with a minimum annual cost covering up to 1TB.
Implementation Friction
2/5
Engineering + admin effort required
Value-Position score
out of 5 · model estimate
Full cost breakdown
Mandatory implementation fee
None
Seat tiers
No published seat minimum; volume discounts available at scale.
Add-on costs
- ATO Resilience add-on: +$3 per user/month, or $5 per user/month as a stand-alone module.
- Shared Drive fee based on storage size; minimum annual cost covers up to 1TB.
Company & support
Who is behind Material Security, and how your team gets help once it is live.
Company
- Founded
- 2017 · 9 yrs in business
- Headquarters
- Not recorded
How you get support
We haven’t recorded support channels for Material Security yet. Nothing here means unverified — not absent.
Market position
Where Material Security sits against its closest alternatives. Pick any two of cost, speed, friction and buyer score, and up to 9 companies to compare.
Quadrant view
Typical annual cost × Time-to-value
The lines cross at the median of the solutions shown, so about half sit on each side of each line.
Companies on the chart 6 / 10
- Material Security
- Oyster
- Gatekeeper
- NordLayer
- G-P
- CrashPlan
Add or change companies
Up to 10 companies including Material Security. Listed closest first.
Stack fit signal
Compatibility with standard B2B ecosystems.
No supported MCP path today, so it cannot be driven from an AI client.
AI & MCP readiness
What Material Security ships in AI, and what it asks of your ecosystem.
AI features shipped
Material's pricing table lists agentic investigation and remediation of OAuth grants, an automated agent for user-reported phishing, and detection of anomalous sensitive-content sharing. The vendor does not name the underlying models, describe training-data practices, or document AI action logging on the pages reviewed.
Your data & models
- Trains on your data
- Not recorded — ask the vendor
- Runs on
- Not recorded
- AI pricing
- Not recorded
In your ecosystem
- AI connection
- Not supported
- Model key
- Not recorded
- AI usage audit
- Not recorded
Compliance attestations
* IAPP AIGP certifies individuals, not products. It means named staff hold the credential — not that the platform does.
Bottom line
Material Security is a cloud workspace security platform for Google Workspace and Microsoft 365. It combines inbound email threat detection, automated user-reported phishing triage, OAuth and AI-agent access governance, sensitive file and email data protection, account-takeover containment, and workspace posture management in one product that deploys via API. List pricing is $4 per user/month for Essentials or $6 for Advanced, billed annually, plus a Shared Drive storage fee.
Frequently asked questions
What does Material Security cost?
List pricing is $4 per user/month for Essentials and $6 per user/month for Advanced, billed annually, plus a fee based on Shared Drive size with a minimum annual cost covering up to 1TB. The ATO Resilience module adds $3 per user/month, or $5 per user/month as a stand-alone. Volume discounts are available at scale.
How long does deployment take?
Material says it deploys entirely via API in minutes, and one published customer reported a six-minute integration. No mandatory implementation fee is published. Buyers can choose shared multi-tenant or dedicated single-tenant deployment; dedicated single-tenant is aimed at organizations with very strict regulatory requirements.
Does Material replace Google or Microsoft native security?
No. Material positions itself as catching email attacks that Google, Microsoft and legacy SEG providers miss, and it adds controls native tooling does not provide, such as OAuth grant investigation and remediation, bulk file access remediation, and message-level access controls during an account takeover.
What integrations and API access does Material offer?
Material lists integrations across cloud office, SIEM and logging, SOAR and automation, IT ticketing, cloud platforms, team notifications and identity, with flexible webhooks for other tools. Essentials and Advanced plans both list RBAC, Event Subscriptions and API, and an MCP Server as platform capabilities.
What support is available?
The pricing FAQ states that Material offers multiple support options and directs buyers to contact sales for details on available plans. Specific channels, hours of coverage and response-time SLAs are not published on the pages reviewed, so they should be confirmed during procurement.
Are SOC 2 or ISO 27001 certifications confirmed?
The pages reviewed do not include a trust, security or compliance page, so certifications could not be verified from these sources. Buyers should request current attestations and reports directly from the vendor during due diligence.