Value-blind managed path
Managed dotenv files contain phantom placeholders. On an exact configured route, the authenticated loopback proxy injects the route's vault value into its fixed authentication header.
Phantom addresses one hard problem: letting a supported agent workflow use configured API credentials without placing provider values in the managed dotenv context. The security case is open to inspection, and its limits are part of the product contract.
What the shipped local path does
Managed dotenv files contain phantom placeholders. On an exact configured route, the authenticated loopback proxy injects the route's vault value into its fixed authentication header.
The shipped path stores credentials through an OS keychain or encrypted-file backend. Cloud and team source does not prove a commissioned hosted service.
Phantom reduces accidental credential exposure in its managed workflow. It is not a sandbox, endpoint-security suite, identity provider, or regulatory certification.
These summaries do not replace the versioned threat model. Review the exact installed artifact, configuration, endpoint, and client before adoption.
Evidence, not badges
Trust boundaries, abuse cases, known gaps, and non-mitigations.
Supported versions, disclosure expectations, scope, and safe harbor.
Canonical map for technical, release, platform, and security review.
Phantom has no paid bug bounty and claims no certification or independent security audit. Report suspected vulnerabilities privately; do not include real credentials or personal data.