Ghost Security
Also known as: Ghost Labs
Enterprise security agents for incident response, phishing, business email compromise, identity and cloud key compromise that run on premises, in a private cloud or air gapped, with per agent Notify, In the Loop or Above the Loop autonomy and every reasoning step logged.
Ghost Security, founded in Austin by Greg Martin and Josh Larsen and backed by investors including Munich Re Ventures, now sells enterprise security agents that "investigate, contain, and resolve" inside the customer's own perimeter, on what it calls a trusted operating system for security agents.
Purpose built agents cover incident response, vulnerability management, supply chain security, phishing response, business email compromise, identity threat response, MFA fatigue response, privileged account misuse, over permissioned user audits and cloud access key compromise, running around the clock and reporting in Slack or Teams.
Each agent runs in one of three modes: Notify, where it investigates and reports; In the Loop, where it acts within a defined scope only with approval and then reports what it did; and Above the Loop, where it runs the workflow end to end.
The platform deploys on premises, in a private cloud or air gapped, with a published Terraform module for AWS and a Docker deployment. Agents hold no credentials and reach systems through a credential brokering proxy, sandboxed with least privilege, every reasoning step is logged and every action auditable, and customers connect their existing tools and preferred models. Ghost engineers learn the customer's stack, tune agents to its runbooks and build custom agents.
Ghost also maintains open source security tools under Apache 2.0, including the Reaper validation proxy, the Wraith dependency scanner, the Poltergeist secret scanner and AppSec skills for coding agents, and an MCP server for the Ghost Security API. Its trust center refuses automated reading. It fits security teams that want response agents for identity, email and cloud incidents running inside their own environment with a per agent choice of autonomy; the model providers and connected tools are not listed publicly.
Vendor details
Canonical URL
https://ghostsecurity.ai
Category
Security / SOC agent
Funding status
Venture backed; investors include Munich Re Ventures. Austin, Texas. Founded by Greg Martin (CEO) and Josh Larsen (CTO). Specific round sizes not disclosed in retrieved sources.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Agents reach the customer's systems through a credential brokering proxy and report in Slack or Microsoft Teams; customers connect their existing tools and preferred models (not listed publicly). An MCP server exposes the Ghost Security API (findings and repositories), and open source tools on GitHub include Reaper, Wraith, Poltergeist and AppSec skills for coding agents. Deployment through a Terraform module for AWS or Docker.
Sources & related URLs
Research sources
Agentic Index coverage score
10.0 / 14 capabilities · 71%
| Integrations & Tool Calling | Full |
|---|---|
|
Ghost's agents "investigate, contain, and resolve" incidents such as business email compromise, MFA fatigue, privileged account misuse and cloud access key compromise, reaching the customer's systems "through a secure proxy" with brokered credentials, reporting in Slack or Teams (3.3M+ actions stated); the connected systems are not listed by name. Sourceghostsecurity.airead 2026-09-28 |
|
| Workflow Orchestration | Full |
|
Ten purpose built agent workflows run end to end under a chosen autonomy mode, and a Ghost engineer "tunes agents to your runbooks", flows configured to the buyer's own procedures across multiple agents. Sourceghostsecurity.airead 2026-09-28 |
|
| Knowledge Grounding & RAG | Partial |
|
Agents gather context from the customer's systems and keep "your security context" inside the perimeter, and are tuned to the customer's runbooks, but no maintained knowledge structure the agents retrieve from is documented. Sourceghostsecurity.airead 2026-09-28 |
|
| Human Oversight & Guardrails | Full |
|
Buyers pick from three autonomy modes: Notify (the agent investigates and reports in Slack or Teams), In the Loop ("With approval the agent takes action within its defined scope, then tells you what it did") and Above the Loop (end to end), so an approval can come before the agent action commits. Sourceghostsecurity.airead 2026-09-28 |
|
| Security, Identity & Governance | Partial |
|
Agents hold no credentials and reach systems through a credential brokering proxy, sandboxed with least privilege by default. No attestation is published on the open site, and the trust center at trust.ghostsecurity.com is not publicly readable. Sourceghostsecurity.airead 2026-09-28 |
|
| Observability & Auditability | Full |
|
"Every reasoning step logged. Every action auditable." and "Every reasoning step visible", a step level record of the agents' own runs. Sourceghostsecurity.airead 2026-09-28 |
|
| Memory & State Persistence | Not documented |
|
"Self-learning" agents that adapt to real conditions is a learning claim; no memory with a stated scope and lifetime is documented. The open source Reaper tool keeps a local traffic database, which belongs to that tool rather than the agent platform. Sourceghostsecurity.airead 2026-09-28 |
|
| Deployment & Data Residency | Full |
|
"Deploy on-prem, private cloud, or air-gapped. Your security context stays in your perimeter", and Ghost publishes a Terraform module (AWS) and a Docker deployment for the Ghost Agent Platform, named customer environment options. Sourceghostsecurity.airead 2026-09-28 |
|
| Prebuilt Agents / Templates / Packs | Full |
|
Purpose built agents for incident response, vulnerability management, supply chain security, phishing response, business email compromise, identity threat response, MFA fatigue response, privileged account misuse, over permissioned user audits and cloud access key compromise, plus custom agents on request and open source AppSec skills for coding agents. Sourceghostsecurity.airead 2026-09-28 |
|
| Triggers & Channel Coverage | Full |
|
Response agents run 24/7 on incidents such as phishing reports, MFA fatigue and cloud access key compromise, with a stated 22 second average time to respond, so security events wake the agents on their own; the alert sources are not named. Sourceghostsecurity.airead 2026-09-28 |
|
| Model Flexibility & Routing | Full |
|
The platform page says to "Connect to your existing tools and preferred models", a customer choice of model, though no provider list is published. The open source Reaper tool takes an OpenAI key. Sourceghostsecurity.ai/platformread 2026-09-28 |
|
| APIs / SDKs / MCP Extensibility | Full |
|
Ghost's own MCP server for the Ghost Security API publishes its endpoint (https://api.ghostsecurity.ai/v2), API key auth (GHOST_SECURITY_API_KEY) and six enumerated tools, including ghostsecurity_update_finding_status, which changes the platform's own objects; the npm package is described as not yet published, so installation is from source. Sourcegithub.com/ghostsecurity/ghost-mcp-serverread 2026-09-28 |
|
| Testing, Debugging & Optimization | Not documented |
|
No harness, scored test cases or quality gate for the agents is offered to customers; the Ghostbank challenge is Ghost's own research practice for the experimental ReaperBot, a vendor release practice rather than a customer tool. Sourceghostsecurity.airead 2026-09-28 |
|
| Browser / Computer-use | Not documented |
|
Agents reach systems through a credential brokering proxy; no agent operating a browser or desktop is documented. Sourceghostsecurity.airead 2026-09-28 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Not public; the Ghost Agent Platform is sold through sales with forward deployed engineers
not disclosed
Cost watchouts
Inference, not stated by the vendor: self hosted deployment (Terraform on AWS or Docker) adds your own infrastructure cost, and connecting your preferred models may add model usage on your own provider bill.
Variable cost rationale
Inference, not stated by the vendor: with self hosting and customer chosen models, infrastructure and model usage costs sit partly on the customer's own bills; the platform price is not disclosed.
Sales call required
Yes, required for paid access
Free / trial
No free tier for the agent platform; open source tools free under Apache 2.0
Lowest paid plan
Not published; commercial Ghost Platform via sales
Key ambiguities
The agent platform's pricing basis is not published, and whether the older Reaper autonomy modes with a Ghost API key are still offered is not stated.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Ghost Security
The closest documented capability profiles to Ghost Security among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Palo Alto Networks10.5 / 14Fuller documented coverage on Security, Identity & Governance
- Swimlane10.5 / 14Fuller documented coverage on Security, Identity & Governance
- D3 Security (Morpheus)10.5 / 14Adds documented Memory & State Persistence
- SentinelOne10.5 / 14Fuller documented coverage on Knowledge Grounding & RAG and Security, Identity & Governance
- Tines11.5 / 14Adds documented Memory & State Persistence and Testing, Debugging & Optimization
- Andesite9.0 / 14Fuller documented coverage on Security, Identity & Governance
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded