Back to vendors
G

Ghost Security

Also known as: Ghost Labs

Visit site
Entry priceNot public; the Ghost Agent Platform is sold through sales with forward deployed engineersFull pricing detail

Enterprise security agents for incident response, phishing, business email compromise, identity and cloud key compromise that run on premises, in a private cloud or air gapped, with per agent Notify, In the Loop or Above the Loop autonomy and every reasoning step logged.

Ghost Security, founded in Austin by Greg Martin and Josh Larsen and backed by investors including Munich Re Ventures, now sells enterprise security agents that "investigate, contain, and resolve" inside the customer's own perimeter, on what it calls a trusted operating system for security agents.

Purpose built agents cover incident response, vulnerability management, supply chain security, phishing response, business email compromise, identity threat response, MFA fatigue response, privileged account misuse, over permissioned user audits and cloud access key compromise, running around the clock and reporting in Slack or Teams.

Each agent runs in one of three modes: Notify, where it investigates and reports; In the Loop, where it acts within a defined scope only with approval and then reports what it did; and Above the Loop, where it runs the workflow end to end.

The platform deploys on premises, in a private cloud or air gapped, with a published Terraform module for AWS and a Docker deployment. Agents hold no credentials and reach systems through a credential brokering proxy, sandboxed with least privilege, every reasoning step is logged and every action auditable, and customers connect their existing tools and preferred models. Ghost engineers learn the customer's stack, tune agents to its runbooks and build custom agents.

Ghost also maintains open source security tools under Apache 2.0, including the Reaper validation proxy, the Wraith dependency scanner, the Poltergeist secret scanner and AppSec skills for coding agents, and an MCP server for the Ghost Security API. Its trust center refuses automated reading. It fits security teams that want response agents for identity, email and cloud incidents running inside their own environment with a per agent choice of autonomy; the model providers and connected tools are not listed publicly.

Vendor details

Canonical URL

https://ghostsecurity.ai

Category

Security / SOC agent

Funding status

Venture backed; investors include Munich Re Ventures. Austin, Texas. Founded by Greg Martin (CEO) and Josh Larsen (CTO). Specific round sizes not disclosed in retrieved sources.

Company status

independent

Use cases & customers

Primary use cases

Autonomous application and API security testingBusiness logic and BOLA fuzzing of live apps and APIsContinuous application discovery, monitoring and risk contextAI agent driven offensive security testing

Target customers

Application security teams and AppSec analystsPenetration testers, red teams and bug bounty huntersEnterprises securing cloud native apps and APIs

Deployment options

On premisesPrivate cloudAir gapped

Integrations

Agents reach the customer's systems through a credential brokering proxy and report in Slack or Microsoft Teams; customers connect their existing tools and preferred models (not listed publicly). An MCP server exposes the Ghost Security API (findings and repositories), and open source tools on GitHub include Reaper, Wraith, Poltergeist and AppSec skills for coding agents. Deployment through a Terraform module for AWS or Docker.

Agentic Index coverage score

10.0 / 14 capabilities · 71%

Integrations & Tool Calling Full

Ghost's agents "investigate, contain, and resolve" incidents such as business email compromise, MFA fatigue, privileged account misuse and cloud access key compromise, reaching the customer's systems "through a secure proxy" with brokered credentials, reporting in Slack or Teams (3.3M+ actions stated); the connected systems are not listed by name.

Sourceghostsecurity.airead 2026-09-28

Workflow Orchestration Full

Ten purpose built agent workflows run end to end under a chosen autonomy mode, and a Ghost engineer "tunes agents to your runbooks", flows configured to the buyer's own procedures across multiple agents.

Sourceghostsecurity.airead 2026-09-28

Knowledge Grounding & RAG Partial

Agents gather context from the customer's systems and keep "your security context" inside the perimeter, and are tuned to the customer's runbooks, but no maintained knowledge structure the agents retrieve from is documented.

Sourceghostsecurity.airead 2026-09-28

Human Oversight & Guardrails Full

Buyers pick from three autonomy modes: Notify (the agent investigates and reports in Slack or Teams), In the Loop ("With approval the agent takes action within its defined scope, then tells you what it did") and Above the Loop (end to end), so an approval can come before the agent action commits.

Sourceghostsecurity.airead 2026-09-28

Security, Identity & Governance Partial

Agents hold no credentials and reach systems through a credential brokering proxy, sandboxed with least privilege by default. No attestation is published on the open site, and the trust center at trust.ghostsecurity.com is not publicly readable.

Sourceghostsecurity.airead 2026-09-28

Observability & Auditability Full

"Every reasoning step logged. Every action auditable." and "Every reasoning step visible", a step level record of the agents' own runs.

Sourceghostsecurity.airead 2026-09-28

Memory & State Persistence Not documented

"Self-learning" agents that adapt to real conditions is a learning claim; no memory with a stated scope and lifetime is documented. The open source Reaper tool keeps a local traffic database, which belongs to that tool rather than the agent platform.

Sourceghostsecurity.airead 2026-09-28

Deployment & Data Residency Full

"Deploy on-prem, private cloud, or air-gapped. Your security context stays in your perimeter", and Ghost publishes a Terraform module (AWS) and a Docker deployment for the Ghost Agent Platform, named customer environment options.

Sourceghostsecurity.airead 2026-09-28

Prebuilt Agents / Templates / Packs Full

Purpose built agents for incident response, vulnerability management, supply chain security, phishing response, business email compromise, identity threat response, MFA fatigue response, privileged account misuse, over permissioned user audits and cloud access key compromise, plus custom agents on request and open source AppSec skills for coding agents.

Sourceghostsecurity.airead 2026-09-28

Triggers & Channel Coverage Full

Response agents run 24/7 on incidents such as phishing reports, MFA fatigue and cloud access key compromise, with a stated 22 second average time to respond, so security events wake the agents on their own; the alert sources are not named.

Sourceghostsecurity.airead 2026-09-28

Model Flexibility & Routing Full

The platform page says to "Connect to your existing tools and preferred models", a customer choice of model, though no provider list is published. The open source Reaper tool takes an OpenAI key.

Sourceghostsecurity.ai/platformread 2026-09-28

APIs / SDKs / MCP Extensibility Full

Ghost's own MCP server for the Ghost Security API publishes its endpoint (https://api.ghostsecurity.ai/v2), API key auth (GHOST_SECURITY_API_KEY) and six enumerated tools, including ghostsecurity_update_finding_status, which changes the platform's own objects; the npm package is described as not yet published, so installation is from source.

Sourcegithub.com/ghostsecurity/ghost-mcp-serverread 2026-09-28

Testing, Debugging & Optimization Not documented

No harness, scored test cases or quality gate for the agents is offered to customers; the Ghostbank challenge is Ghost's own research practice for the experimental ReaperBot, a vendor release practice rather than a customer tool.

Sourceghostsecurity.airead 2026-09-28

Browser / Computer-use Not documented

Agents reach systems through a credential brokering proxy; no agent operating a browser or desktop is documented.

Sourceghostsecurity.airead 2026-09-28

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Pricing

Not public; the Ghost Agent Platform is sold through sales with forward deployed engineers

not disclosed

Trial available

Cost watchouts

Inference, not stated by the vendor: self hosted deployment (Terraform on AWS or Docker) adds your own infrastructure cost, and connecting your preferred models may add model usage on your own provider bill.

Variable cost rationale

Inference, not stated by the vendor: with self hosting and customer chosen models, infrastructure and model usage costs sit partly on the customer's own bills; the platform price is not disclosed.

Sales call required

Yes, required for paid access

Free / trial

No free tier for the agent platform; open source tools free under Apache 2.0

Lowest paid plan

Not published; commercial Ghost Platform via sales

Key ambiguities

The agent platform's pricing basis is not published, and whether the older Reaper autonomy modes with a Ghost API key are still offered is not stated.

Agentic Index verified 2026-09-28

Alternatives to Ghost Security

The closest documented capability profiles to Ghost Security among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Palo Alto Networks10.5 / 14Fuller documented coverage on Security, Identity & Governance
  • Swimlane10.5 / 14Fuller documented coverage on Security, Identity & Governance
  • D3 Security (Morpheus)10.5 / 14Adds documented Memory & State Persistence
  • SentinelOne10.5 / 14Fuller documented coverage on Knowledge Grounding & RAG and Security, Identity & Governance
  • Tines11.5 / 14Adds documented Memory & State Persistence and Testing, Debugging & Optimization
  • Andesite9.0 / 14Fuller documented coverage on Security, Identity & Governance

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.