THE LATEST
JUL 2026 / Fraudulent ads join the platformMAY 2026 / Marketplace enforcement launchesMAR 2026 / Akamai + Bolster: Brand Guardian

Company / Cybersecurity · The removal business

Bolster AI and the 32-day head start

A fake website can be spotted in seconds and survive for weeks. Bolster AI built a business around the awkward interval between knowing a scam exists and making it disappear.

Thirty-two days is a generous opening offer. In a November 2025 account published by Bolster AI, a U.S. financial institution discovered how long a phishing takedown could take when handled internally. The fake site had already been identified. What remained was coordination: legal teams, hosting providers, competing priorities. An impostor could keep its doors open while the real institution worked out how to close them.

Bolster says that institution subsequently brought removal time down to 36 hours. Treat those numbers as a customer account, rather than a promise for every deployment. They introduce the company’s proposition neatly: the time after discovery deserves as much attention as the discovery itself.

The useful version
  • The job: find online impersonation, assemble evidence, and pursue removal.
  • The customer: businesses whose names help strangers decide whom to trust.
  • The entry point: CheckPhish, a free suspicious-URL scanner.
  • The buying question: how much work remains for your team after an alert?

Thirty-two days is a generous opening offer

The institution began with CheckPhish, added domain and app protection in 2022, and expanded its modules in 2025. This is a sensible sequence for software with a large remit: start with an observable task, then widen the contract once the task works. The embarrassment of a slow takedown supplied the incentive. A free tool supplied somewhere to begin.

One institution’s reported removal time
Internal process32 days / 768 hours
With Bolster AI36 hours
A shorter lease for the impostor. Figures from Bolster’s November 2025 customer account; elapsed time, not analyst labor. Bars share a scale.

A separate bank case study describes another tempting response: buy the lookalike domains before anybody else does. That bank found the possibilities too numerous and costly. Its threat intelligence manager’s verdict was admirably brief: “We just have to monitor.” Even then, the team needed to separate dormant lookalikes from active abuse and give legal colleagues sufficient proof. The bottleneck was the work needed to make a discovery actionable.

The impostor has a landlord

Bolster’s domain product looks for suspicious registrations and websites, sorts them by threat lifecycle, and brings investigation and removal into one dashboard. Its expertise combines machine learning with the practical mechanics of enforcement. A hostname is useful evidence; so is what the page says, what it looks like, and what it asks a visitor to do. The company uses text and visual analysis to assess that wider picture.

A takedown still operates in a world of registrars, hosting companies, content platforms, and their rules. Someone must connect the abusive asset to the right provider and present a case that provider can act on. Bolster’s emphasis is on automating that sequence, with security analysts handling difficult cases. An accurate alert is an ingredient in the service, rather than the finished meal.

That places Bolster in external threat protection and digital risk protection, alongside alternatives such as ZeroFox, Netcraft, and Doppel. Monitoring, AI, and takedowns appear elsewhere in this market, too. Bolster’s useful distinction is the combination of those jobs in a workflow customers can actually delegate. Whether it performs that combination better for a particular brand is a question for a trial with real threats.

A security company needs security, too

McAfee is a revealing customer. Its published case describes abuse mailboxes receiving reports from around the world, while analysis was not specifically looking for infringement of McAfee’s own brand. The firm evaluated replacements before its existing vendor renewed. Bolster’s identification capabilities and the working relationship between the two security operations teams helped make the decision.

McAfee’s account reports a 50% reduction in phishing triage workload. In one invoicing campaign, attackers shifted providers after enforcement; the net reduction was approximately 70%. Those two numbers describe different things: staff effort and campaign activity. Both are more useful than assuming that a successful removal makes an adversary retire.

SoFi’s case supplies a different lesson. An impersonation campaign used a plausible domain that was not even a misspelling. Logo detection and optical character recognition helped identify abuse that a spelling-led search could miss. Its published account reports roughly 24 hours to remove a Hong Kong-targeted site and about 20% less analyst workload across the program. That is the appeal for a busy team: fewer investigations consuming the same afternoon.

Bolster’s public customer material also names Uber, Dropbox, Canva, and AIA. Their shared problem is the value of a recognizable identity. Borrow the name of a bank, a software company, or a consumer platform, and a stranger may lend you attention before asking who you are.

“Their automation is a game changer.”

Bill Harmon · VP Intellectual Property, Uber
On Bolster’s customer page

The invoice is more interesting than the accuracy claim

Bolster began in 2017 as RedMarlin, founded by Abhishek Dubey and Shashi Prakash. Dubey’s background includes Cisco’s Talos security organization; Prakash worked at the intersection of machine learning and security research. Dubey led Bolster until 2024. Rod Schultz became CEO that November.

Bolster co-founder and former CEO Abhishek Dubey
The founder before the handoff. Abhishek Dubey led Bolster from 2017 to 2024. Portrait from his public website. The unglamorous paperwork became a software business.

The company announced a $10 million Series A in November 2019, a $15 million financing in October 2022, and a $14 million Series B led by Microsoft’s M12 in May 2024. At the last of those announcements, it described total funding above $40 million. Funding buys development and distribution; customers buy licenses and an operating capability.

Enterprise pricing is quoted for the deployment. A partner brief describes tiers tied to modules and customer website traffic. The platform can expand across domains, social accounts, apps, dark web intelligence, customer abuse reports, and newer commerce channels. CheckPhish gives people a smaller starting point, while its API and Microsoft Security Copilot plugin bring URL analysis into existing tools.

A historical cost example$579,000

Three-year, risk-adjusted present value of software licensing in a 2022 commissioned Forrester model. A further $209,000 covered domain management. One customer-derived scenario, not today’s price list.

That study modeled 278% ROI using an interview with one customer representative. The scale matters: a large organization and substantial recurring enforcement work. A buyer can borrow the calculation method, then substitute its own workload and costs. An impressive return on somebody else’s spreadsheet is a poor substitute for arithmetic on your own.

Follow the customer into the trap

Signals, launched in October 2025, adds another audience: the executive asking what the alerts amount to. It offers threat correlation, peer comparisons, plain-language questions through Ask Bolster, and reports that can leave the analyst’s dashboard. Its usefulness depends on connecting a collection of cases to a decision about priorities, exposure, or staffing.

In 2026 the product perimeter expanded again. Marketplace Monitoring & Takedowns, announced in May, addresses counterfeit listings, unauthorized sellers, and repeat listings. July brought Fraudulent Ads Monitoring & Takedowns. A company investigation blog explains the change in perspective: trace how the customer arrived at the malicious page. A paid search result can be the first contact; the fake storefront is farther down the journey.

The March Akamai collaboration tackles a particularly awkward observation problem. Attackers can show different pages according to location or other conditions, so a scanner may see something harmless while a victim sees fraud. Bolster’s joint perspective describes work on global, adaptive capture and measuring potential exposure. Several capabilities are framed as exploration, which matters when assessing what is available today.

Borrow the stopwatch

The lesson travels beyond this particular vendor. Map the handoffs between detection, evidence, provider contact, and confirmation. Give each stage an owner. Test a service against abuse your organization really encounters, including cases where a provider is slow or the offender returns. Count time saved for staff separately from elapsed time saved for customers.

The conditions matter. A scanner needs to see the malicious experience; a provider needs evidence it accepts; a removal process needs somewhere to apply pressure. Dark web monitoring can reveal leaked information without making every copy disappear. A brand with little recurring abuse may have less to gain from a broad enterprise contract. Customer cases demonstrate possibilities, while the buyer’s own cases establish fit.

Bolster’s promise is appealing because it gives a familiar nuisance an accountable endpoint. The fake business is exploiting a real name. Someone should be responsible for closing it - and for checking whether it has reopened around the corner.