Notes on macOS security architecture, cryptography, and the decisions behind PhantomSecure, written while the suite is still in development.
A practical guide to the difference between deleting a selected file, handling storage copies, and erasing a Mac for a new owner.
Read the guideProgress on PhantomVault’s native FSKit foundation and movie carriers, plus the work preparing PhantomProtect for launch.
Read the updateJamf Threat Labs documented a ClickFix campaign that moved execution from Terminal into Script Editor through an applescript:// URL. Here is how the attack works, what warning signs remain, and how PhantomSecure is being designed to add behavioral and network defenses.
Jamf reports that Trojans represented more than half of the Mac malware in its 2025 dataset. We look at why signatures remain useful but insufficient on their own, and where behavioral and network evidence can help.
The origin story of PhantomSecure, including the move to Apple’s native filtering APIs and the current AES-256-GCM plus optional ML-KEM-1024 Vault design.
A plain-English look at the current PhantomVault encryption design and the decoy-Vault capabilities planned for public launch.