Getting Started
Everything you need to start protecting your team with Blue Lantern Security.
Blue Lantern provides continuous active monitoring for your team's inboxes, browsers, and devices at a flat per-seat price, reporting into the Monitoring Hub. Alongside it, Scan Now offers the same analysis engines on demand, free for 30 runs a day in the web app.
Quick Start - Active Monitoring
Active monitoring is the core of the platform: it continuously watches inboxes, browsers, devices, and the AI tools with access to your data. Everything is managed from the Monitoring Hub: live scan activity, monitor keys, alert rules, and the Security Attestation Report that turns all of it into evidence for insurers and customers.
- Pick your coverage.
- Email, org-wide (recommended): connect Google Workspace or Microsoft 365 once from Integrations. Every monitored mailbox is analyzed automatically, with optional filing of malicious mail to Spam or Junk Email.
- Email, per user: the Outlook Plugin and Google Mail Plugin submit messages to the Email Threat Analyzer in one click.
- Device: Device Agents for macOS and Windows check each machine's security posture about once an hour and score it Healthy, At Risk, or Critical.
- Already running an EDR: connect CrowdStrike Falcon or Microsoft Defender read-only and each protected device gets a daily agent-health run beside your other device data.
- Identity, mail, and AI exposure posture: once an org email integration is connected, enable the daily scans in its settings: MFA and dormant accounts, mail forwarding and inbox rules, DMARC/SPF/DKIM, and the AI exposure inventory of AI tools and unverified apps granted access to mail, files, and calendars.
- Browser: the Chrome Monitor extension checks the URLs you visit through the URL Threat Analyzer.
- Create a monitor key (agents and extensions only). In the Monitoring Hub's Monitors view, create a monitor of the matching type. Monitor keys are scoped to submitting scans only and are shown once, so copy the key when you create it. Org integrations skip this step; the connection wizard handles credentials.
- Install and connect. Install the extension or agent (downloads on the macOS Agent and Windows Agent pages) and give it the key.
- Review activity. Every monitored run appears in the Monitoring Hub's Scan Activity view, with a full report a click away.
- Set up alerts. Create alert rules so Malicious or Critical results reach your inbox, SIEM, or webhook without watching the dashboard.
- Prove it. From the hub's Security Report view, download the Security Attestation Report: a printable, summary-level document of your device, identity, mail, and AI exposure posture over the last 7 days, written to answer insurer and customer security questionnaires.
Billing: Monitoring is covered by a flat Seat License: every integration, agent, extension, and API key requires an active seat plan. Teams seat their members through an organization.
Quick Start - Scan Now
Want to see the analysis in action first, or run one-off scans? Scan Now gives you immediate access to the same engines that power monitoring. It is the fastest way to trial the platform.
- Create an account. Get Started with your email. Every account gets 30 free scans a day, no card required.
- Pick a tool. Visit Scan Now and open any tool.
- Run it. Provide the input (an email file, a URL, a binary) and submit. The verdict lands in your Monitoring Hub in about 30 seconds.
- Need more? A Seat License lifts the limit to 500 runs a day and adds monitoring and API access.
Quick Start - API Access
The REST API exposes the same analysis available in the web UI, for automation and integrations. For each account we allow the user to configure one API key with an expiration up to a year. Please note, this API key will work as a credential for your account and you should store it securely
- Provision an API key - Navigate to Your Acount and go to request an API key.
- Select an Expiration Date - Dates will be acceptable up to a year.
- Test your API key works - Send a request to the /account endpoint to validate the API key is working. Example curl command below
curl --location 'https://api.bluelanternsecurity.io/account' \
--header 'Authorization: [YOUR API KEY]'
Run analysis - Visit individual tool pages for further instructions on how to run analysis
Free Tier and Seat Licenses
Every signed-in personal account is on the Free Tier: 30 Scan Now runs per day across the email, URL, and file analyzers, with full reports. Repeat submissions of the same email are served from cache and do not count. Free accounts can also create alert rules on their own runs.
A Seat License ($15 per seat per month) covers one monitored person and unlocks everything that runs without you clicking: org-wide Gmail and Microsoft 365 integrations, device agents, browser and mail extensions, the forwarding mailbox, and API keys, with fair use up to 500 runs per seat per day. Shared organization accounts run on seats only.
Rate Limits — APIs are limited to 600 requests in a 10 minute period. API access itself requires an active Seat License; keys on accounts without one return a 402 until a seat is added.
Security & Compliance
Blue Lantern Security is SOC 2 Type 1 attested, with the Type 2 audit in progress. Reports, policies, and our full security posture are available in our Trust Center.