How to Buy Lookout
Start with the protection your mobile fleet needs today. Add specialized capabilities as your requirements evolve.
A platform built around how you actually buy security.
Most enterprise security platforms force a choice: buy a limited point product that leaves gaps, or pay for an expensive bundle loaded with capabilities you don't need yet.
Lookout is structured differently. The platform is modular by design — built around a mandatory security foundation with optional, specialized modules that extend coverage to address your most pressing operational risks.
You pay for what you deploy. You scale to what you need.
Every Lookout deployment starts with the MES Base Platform. From there, you can add one, two, or all three solution modules — in any order, at any time — based on your organization's immediate priorities and budget.
Platform structure at a glance.
Governance
Protection
(Mobile EDR)
The foundation: MES base platform.
App Security
Stops malicious apps, malware, trojans, and spyware before compromise occurs.
Device & OS Integrity
Detects rooting, jailbreaking, OS tampering, and exploit techniques that bypass MDM controls.
Mobile Vulnerability Management
Identifies vulnerable OS versions and apps, prioritized by real-world exploitability — not just CVE presence.
Mobile App Risk Reputation
Dynamic behavioral risk scoring across 420+ million apps, enabling confident allow, restrict, or block decisions.
Network Security
Detects rogue Wi-Fi, man-in-the-middle attacks, and insecure network conditions on any network, including public and cellular.
Phishing & Content Protection
Blocks malicious links and harmful content across browsers, apps, SMS, and social channels — in real time, before users can interact.
Secure DNS
Encrypts and secures DNS traffic across cellular, Wi-Fi, and roaming networks to block DNS-based attacks, data exfiltration, and C2 communication.
Mobile Software Exposure Center (MSEC)
Extracts a complete Software Bill of Materials from Android and iOS app binaries, continuously correlating components against vulnerability databases and real-world threat intelligence.
Privacy-first by design
The MES Base Platform enforces strong security and compliance policies across both corporate-owned and employee-owned (BYOD) devices without collecting personal content, monitoring private activity, or degrading device performance. Privacy is not a configuration option — it is foundational.
Extend coverage where you need it.
AI Visibility & Governance
52% of generative AI activity happens on mobile devices. Most organizations have no visibility into it.
Employees are already using AI tools on their phones to draft emails, summarize documents, query internal data, and interact with agentic systems that can take actions on their behalf. Without visibility into what AI tools are running on mobile, security teams cannot assess data exposure, enforce policy, or demonstrate compliance with AI governance regulations.
The AI Visibility & Governance module gives security teams a complete, continuously updated inventory of every AI application touching corporate data across both managed and unmanaged devices — and the enforcement controls to act on what they find.
CISO, Chief AI Officer, Risk and Compliance leadership, CFO/COO. Frequently unlocks budget outside traditional IT security lines.
What this module delivers:
- Shadow AI discovery and usage visibility across the full mobile fleet, including apps and AI-related network activity
- Classification of sanctioned versus unsanctioned AI tools, with the ability to investigate new AI apps as they emerge
- Detection of agentic AI behavior — identifying tools capable of taking actions on behalf of employees
- Policy enforcement: block, redirect, warn, quarantine, or monitor AI usage based on risk classification
- Prevention of sensitive data leakage to unsanctioned AI services and LLMs
- Alignment to ISO/IEC 42001, the EU AI Act, and NIST AI RMF — the only mobile-native solution mapped to these frameworks
Social Engineering Protection
SMS phishing click rates run 6–10x higher than email. Smishing attacks grew more than 300% between 2022 and 2025. Voice deepfake fraud has increased 550% since 2021.
Mobile users are the primary target for AI-powered social engineering precisely because most security tools do not see what happens inside personal messaging apps, SMS, or voice calls. The Social Engineering Protection module closes that gap — delivering comprehensive defense across every channel where mobile users are targeted.
CISO, SOC leadership, Identity and Access Management teams focused on stopping credential theft upstream from the identity layer.
What this module delivers:
- Targeted phishing protection: detects and blocks malicious links and domains in browsers and embedded in apps, including short-lived and brand-spoofing URLs
- Messaging protection: scans and blocks malicious content across SMS, RCS, MMS, WhatsApp, iMessage, Signal, and other third-party messaging platforms
- Executive impersonation detection: identifies socially engineered messages that spoof company leadership
- Voice security: protects against deepfake calls, fraudulent caller ID, and real-time voice fraud — including voicemail and live call analysis
- Content filtering: enforces acceptable-use and risk-based browsing policies across the mobile fleet
- Enterprise visibility and campaign detection: identifies targeted attack trends and active smishing campaigns across the organization
Advanced SOC — Mobile EDR
Mobile devices are entry points into your broader enterprise environment. Without mobile telemetry feeding into SOC workflows, analysts are investigating incidents with a structural blind spot.
The Advanced SOC module brings true endpoint detection and response capabilities to mobile — enabling security operations teams to proactively hunt for threats, perform forensic analysis on historical events, and respond to mobile incidents with the same speed and precision they apply to desktops and servers.
SOC Directors, Security Architects building out XDR coverage, and CISO organizations seeking to close the mobile telemetry gap.
What this module delivers:
- Access to raw mobile telemetry for proactive threat hunting across the fleet
- Forensic analysis of historical mobile security events for lookback investigations
- Instant device quarantine upon anomaly detection, integrated with existing MDM and UEM workflows
- Detailed mobile app analysis and intelligence — understanding what applications are doing at a code and behavioral level
- Bidirectional integration with SIEM, SOAR, and XDR platforms, feeding mobile risk signals into the tools your SOC already operates
How to get started.
Step 1
Assess your environment
Work with your Lookout account team to map your current mobile fleet — device types, MDM/UEM platforms, BYOD policies, and compliance obligations. This shapes which modules are most relevant to your immediate risk profile.
Step 2
Start with the MES Base Platform
Every deployment begins with the MES Base Platform. Deployment is lightweight — no VPN backhaul required, minimal user friction — and integrates directly with Microsoft Intune, Jamf, Okta, IBM MaaS360, Ivanti, BlackBerry, and other platforms already in your stack.
Step 3
Layer in the modules that match your priorities
Add AI Visibility & Governance if your organization needs to address shadow AI risk, comply with AI governance regulations, or establish visibility into how employees use generative AI on mobile. Add Social Engineering Protection to harden your employees against phishing, smishing, vishing, and executive impersonation. Add Advanced SOC to extend your threat detection and response program to mobile endpoints.
Step 4
Scale as your needs evolve
Modules are designed to be added at any point in the contract lifecycle. Your net pricing adjusts automatically as additional modules are deployed, with volume discounts applied at renewal or mid-term expansion.
Businesses and organizations around the world trust Lookout to safeguard their data.
