We’re building PhantomProtect to analyze threats on your Mac because security software handles sensitive information. Local analysis can reduce the need to send file contents to a remote service when deciding whether something is dangerous.

The product is still in development. Our work combines local rules, models and downloaded threat information, with testing to establish what each part can detect and how it affects everyday use.

What cloud threat analysis can involve

A cloud service can compare information from many devices and return an assessment of a suspicious file. The information sent may be a file identifier, other metadata about the file or activity, or a sample of the file itself. Each gives the service a different view of what happened on the computer.

Bitdefender Antivirus for Mac, for example, describes using cloud technology for threat detection. Microsoft Defender for Endpoint, an enterprise product, documents metadata transmission and optional file sample submission. Microsoft’s Mac configuration guide explains the available controls. The information shared depends on the product, situation and settings.

For PhantomProtect, we want the Mac to do the analysis of file contents. Downloading current threat information can help local checks recognize known threats while the contents being evaluated stay on the device.

Give local AI a defined role

We’re developing models that run on the Mac as part of PhantomProtect’s threat analysis. They can work alongside rules and known threat information to assess the clues around a file or an activity.

PhantomGuardian has a related role: explain a security event in ordinary language using a model on a supported Mac. A useful explanation tells you what was observed, why it matters and what you can do next. The decision that something is dangerous still needs evidence from the protection system.

As attackers adopt AI tools, we expect to keep developing and testing these methods. Their value needs to show up in detection results, fewer false alarms and acceptable performance during normal use. A model’s label alone tells you little about those outcomes.

Explain the connections the product needs

Local analysis is one part of the privacy picture. Software updates, accounts, threat information downloads and the planned private URL lookup service involve network connections. Optional contributions to improve threat analysis require their own consent and explanation.

Our product and privacy guide describes these areas as the product develops. It gives us a place to explain what information is involved, the reason for each connection and the choices available to you.

Show what the development work establishes

PhantomProtect comes first in our release plan. These development notes will explain the decisions behind the product and share test results when they are ready. That includes the conditions of the tests and the cases the product missed, so you can assess the results in context.

If this approach matters to you, the launch list below is where we’ll share development milestones, testing opportunities and availability.