Over the past month, we have focused on making PhantomProtect quieter and more dependable before its first release. We reduced sources of false warnings, improved the status shown while protection starts or recovers, and strengthened how threat updates reach the Mac. We also added a new tool that checks files on the Mac.

Artwork for the September PhantomProtect development update.
Development artwork for this update.

PhantomSecure is still in development. These changes have passed focused code checks and automated tests. The complete app still needs to be tested on a Mac.

Quieter alerts built on stronger evidence

Security software needs to notice unusual activity without turning routine work into a stream of warnings. We changed how PhantomProtect evaluates busy file activity. An app update, a cache refresh or a development build should not trigger a warning just because it touches many files. Protect still checks for known harmful files and several related signs of ransomware.

Our own development work exposed several specific false warnings. One imported rule treated nearly any Mac program file as suspicious. Other checks could flag Apple development tools, parts of PhantomSecure and PhantomProtect’s own threat database. We removed the faulty rule from the threat update service, repaired the import process that admitted it and added safeguards for the other cases.

A clearer view of protection status

We improved the way the app reports protection that is starting or recovering. If part of Protect is delayed or misses activity, the app should show that until it can confirm protection is working again. The Home screen and menu bar now follow the same rules in the development build.

We also traced cases where PhantomWatch could briefly appear unavailable or have trouble identifying an app installed in a user’s home folder. We changed how Watch handles repeated reports of the same connection and how it gets an app’s identity from macOS. We will check both fixes in the next installed build.

Automatic threat updates with a safety check

Updates to our list of known threats will continue to run automatically. The service now adds a digital signature to every update. PhantomProtect can use that signature to confirm the update came from us and was not changed on the way to your Mac.

We review and approve changes to file detection rules before they reach Macs. Routine updates to known harmful files, websites and network addresses continue automatically. Reviewing rule changes helps us catch mistakes that could cause false warnings.

We have added signature checking to the development app. The next step is to test it on an installed Mac. We want Protect to reject an altered update and keep using the last trusted copy, then clearly tell you when it cannot get a fresh update.

Testing a new way to check files

We added an early tool that looks for clues in files on the Mac. We are testing how often it gets the answer right and when it makes mistakes. Its results do not yet decide whether PhantomProtect warns about a file or takes action.

We will test it with more files and compare its results with the checks Protect already uses. That work will help us decide whether it is ready to play a larger role.

Continuing Vault work on macOS 27

PhantomVault work continued alongside Protect. We updated the code that lets a vault appear in Finder on macOS 27. Automated tests cover opening and closing a vault, saving changes and handling a failed save. Next, we will check those actions in Finder with the complete app installed.

The current PhantomSecure development build requires macOS 27. We will update the published requirements as release testing establishes the final setup.

What comes next

Our next step is to use the complete app on a Mac as someone would at home or at work. We will restart it, let it recover from interruptions, run common apps and development tools, and create safe test files that should trigger alerts. These checks will show whether PhantomProtect stays quiet during normal work and warns us when it should.

We will also test that PhantomProtect can spot an altered threat update and keep using its last trusted copy. For Vault, we will continue opening, using and closing vaults through Finder.

We will share the results and invite people to help test when the build is ready. Join the launch list below if you would like an update.