Public-sector evaluation

Evidence first. Claims only as strong as the proof.

Public-sector teams can use the MIT-licensed local core or discuss a bounded, written-scope evaluation with Ashlr AI. The evaluation starts with a named non-production environment and ends with an auditable decision—not a blanket authorization.

Evaluation boundary

Start local. Keep authority explicit.

Phantom is designed to keep provider values out of the managed agent dotenv path. That narrow control does not make the agent, endpoint, network, or organization compliant. Reviewers should evaluate the complete operating environment and the documented same-user authority limitation.

Review the threat model

Minimum evidence packet

  • Exact source, version, platform, and installation method
  • Named workflow, data boundary, owners, and prohibited actions
  • Test commands, results, skipped gates, and unresolved findings
  • Separate records for deployment, provider, and user acceptance

Diligence starts here

No implied authorization, certification, or contract vehicle.

Phantom is not represented as FedRAMP authorized or FIPS validated.
No SOC 2, ISO 27001, CMMC, HIPAA, PCI DSS, or agency authorization is claimed.
No government contract vehicle or procurement schedule is represented on this site.
No generally available hosted service, SSO/SAML, SCIM, or self-hosted enterprise control plane is offered.
No uptime, response, residency, or support commitment exists outside a signed agreement.

Requested controls may be discussed as proposed engineering work. A proposal is not implementation; implementation is not deployment; deployment is not agency authorization or acceptance.