Threat Intelligence Platform
PRIVATE BETA

Intelligence
before impact.

The only email security platform that actually opens the link.

Detect, isolate, and neutralize phishing attacks and malicious files before they reach your team. Every suspicious link and attachment analyzed in a disposable sandbox — in under 8 seconds.

Phantriq Intelligence Dashboard
scroll
HIGH RISKcredential-harvesting · secure-login.paypa1.comjust now
SUSPICIOUSredirect chain · bit.ly/3xR9kzP1m ago
CLEANemail attachment · Q3_Report.pdf2m ago
HIGH RISKbrand impersonation · invoice-portal.net/pay3m ago
HIGH RISKmalicious executable · invoice_final.exe4m ago
SUSPICIOUSnewly registered domain · cloud-verify-login.com6m ago
CLEANshared link · docs.google.com/spreadsheets7m ago
HIGH RISKphishing page · microsoft-365-login.xyz9m ago
HIGH RISKcredential-harvesting · secure-login.paypa1.comjust now
SUSPICIOUSredirect chain · bit.ly/3xR9kzP1m ago
CLEANemail attachment · Q3_Report.pdf2m ago
HIGH RISKbrand impersonation · invoice-portal.net/pay3m ago
HIGH RISKmalicious executable · invoice_final.exe4m ago
SUSPICIOUSnewly registered domain · cloud-verify-login.com6m ago
CLEANshared link · docs.google.com/spreadsheets7m ago
HIGH RISKphishing page · microsoft-365-login.xyz9m ago
Platform Capabilities

Built different
because the threat is different

Four capabilities that don't exist together anywhere else. Watch each one live — then decide if your current stack does any of this.

Threat Hunt · MQL First in the market

Query threats the way
you think about them

Most security teams live between two bad options: a SIEM that costs $150K/year to license, or a dashboard that only shows what someone else decided to show you. Neither gives analysts the freedom to hunt the way their instincts tell them to.

Phantriq MQL is a full query language built directly into the platform. Search across every email, URL session, attachment scan, and IOC in real time. Filter by verdict, threat score, MITRE technique, sender domain, redirect count — anything your analyst needs to reach for.

  • Zero SIEM dependency — MQL runs natively inside Phantriq, no extra license
  • Results in milliseconds across all historical and live detection data
  • Save queries as reusable hunt templates and share across your team
"Splunk Enterprise costs $150K/year. MQL is built in — day one."
— Phantriq platform design
Sandboxed URL Analysis Zero risk to your network

Open any link
touch nothing

When an analyst clicks a suspicious URL to investigate it, they are gambling with their machine, their credentials, and the entire internal network. This is the industry's open secret — and nobody has fixed it. Until now.

Phantriq detonates every URL inside a throwaway container that is completely destroyed after analysis. Your real systems never touch the threat. The page executes, the signals are captured, the evidence is stored — and you get a verdict in under 12 seconds.

  • 6-layer scoring: reputation, behavior, redirect chain, credential forms, domain age, brand impersonation
  • Full DOM snapshot, network traffic capture, and screenshot evidence attached to every analysis
  • Verdict in under 12 seconds — industry average for manual review is 40+ minutes
"Traditional scanners tell you what 90 AV engines think. Phantriq shows you what the page actually does."
— Phantriq platform design
Incident Response Full lifecycle management

Every alert becomes a case
every case becomes closure

Alerts that don't become structured cases get lost. They sit in a queue, age out, and become the incidents you read about in breach reports six months later. Most teams accept this as normal. It is not normal. It is a tooling failure.

Phantriq turns every threat into a full case automatically — with evidence chain, SLA timer, analyst assignment, audit log, and a PDF-ready report. No $80K case management add-on. No switching between four tools. The platform that found the threat also manages the response.

  • Full evidence chain: emails, URLs, attachments, IOCs — all linked in one timeline
  • Built-in SLA tracking with severity-based deadlines and breach warnings
  • IOC correlation: same domain across multiple cases is surfaced automatically
"ServiceNow and Jira are not built for SOC analysts. This was."
— Phantriq platform design
AI-Powered Triage Signal over noise

Your analysts should be
hunting — not sorting

The average SOC analyst spends 40% of their day triaging alerts they'll eventually mark as false positives. That's not a people problem. It's a tooling problem. And it gets worse every quarter as attack volume scales and teams don't.

Phantriq's triage queue is AI-scored, pre-assessed, and ranked by threat severity before your analyst ever opens it. Every item comes pre-loaded with AI assessment, IOC data, MITRE technique mapping, and a suggested verdict. Your analyst walks in knowing what they're dealing with — not discovering it from scratch.

  • Priority scoring 0–100 with CRITICAL / HIGH / MEDIUM / LOW auto-classification
  • One-click verdict override with analyst notes and full audit trail
  • Auto-archive after configurable retention window — GDPR compliant by design
"Most platforms deliver raw alerts. Phantriq delivers decisions."
— Phantriq platform design
Why now

AI made phishing
cheap and scalable

Traditional secure email gateways were built for signature-based threats. They scan headers, filter keywords, check reputation lists. But they never actually open the link. In 2024, that gap became critical.

+202%
Increase in phishing attacks in 2024 vs 2023 — driven by AI-generated lures at scale.
SlashNext Annual State of Phishing Report, 2024
4,151%
Rise in malicious emails since the public release of ChatGPT — phishing now requires zero technical skill.
SlashNext Threat Intelligence, 2023
56%
Of modern phishing attacks bypass traditional secure email gateways — static analysis cannot keep up.
Avanan / Check Point Research, 2024
Market opportunity
$5.3B
Global email security market in 2024 — growing at 14.8% CAGR.
Projected by 2030
$12.1B
Runtime behavior analysis — Phantriq's core — is the fastest growing segment. MarketsandMarkets, 2024.
Regulatory tailwind
NIS2 Directive
EU-wide enforcement from October 2024. Critical infrastructure operators must implement active behavioral threat detection. Legacy scan-and-filter approaches no longer comply.
DORA
EU Digital Operational Resilience Act — in force January 2025. Financial entities must demonstrate documented email threat response with full evidence chains. Phantriq is built for this.
BDDK / SPK (Turkey)
Turkish banking and capital markets regulators now mandate documented threat detection workflows for all financial institutions. Deadline: Q4 2026.
The Real Gap

94% of breaches
start with an email

This isn't new data. Every CISO has seen it. The question is why the market keeps spending billions on tools that activate after the email has already been opened.

Existing tools — Reaction

Splunk, CrowdStrike,
Microsoft Defender, Proofpoint

These are world-class tools. But they are built for a different job: detecting and managing threats that have already entered your environment. An EDR fires when malware executes on an endpoint. A SIEM correlates events after the intrusion. A Secure Email Gateway scans metadata before delivery.

None of them open the link. None of them watch the page execute in real time. By the time they alert, the credential has already been harvested.

  • Alert fires after the user has clicked — breach has started
  • Signature-based — misses zero-day phishing pages entirely
  • Enterprise pricing: $80K–$500K/year for coverage that still has gaps
VS
Phantriq — Prevention

Stop the threat
before it can act

Phantriq intercepts every suspicious email before it reaches the inbox. The link is detonated inside a disposable container. The page executes. The credential form is detected. The verdict is rendered — before any human ever sees the email.

The goal isn't to manage the breach better. It's to prevent the breach from starting. That's a fundamentally different architecture — and it's why the detection rate matters more than the incident response time.

  • Threat intercepted and verdicted before inbox delivery — zero user exposure
  • Behavioral analysis in a live isolated container — catches pages no AV engine has seen
  • Deploys via API in under 30 minutes — no agents, no MX record changes
Expansion roadmap

Email is where we start.
It's not where we stop.

Live now Email & Phishing
2026 Endpoint & Browser
2026 Cloud Storage
2027 Messaging (Teams, Slack)
How it works

From threat
to verdict
in seconds

Every suspicious email, link, or file goes through a 5-stage automated pipeline — fully isolated, complete evidence trail.

01Threat Detected
02Sandbox Isolation
03Deep Analysis
04Verdict Issued
05Auto Response
Step 01
Threat Detected

An incoming email or manually submitted URL instantly triggers the analysis pipeline. Phantriq intercepts threats at the source — before any user interaction occurs.

Gmail & M365 integration Manual URL submission Real-time API endpoint Header & sender analysis
⏱ < 0.1 sec
Step 02
Sandbox Isolation

A disposable Docker container spins up in milliseconds. The threat is executed in total isolation — no network access, no host filesystem, no persistence. The container is destroyed the moment analysis ends.

--network=none, --read-only --cap-drop ALL, non-root user 256 MB RAM, 0.5 CPU cap Auto-destroyed after analysis
⏱ < 0.8 sec
Step 03
Deep Analysis

Six detection layers run simultaneously inside the sandbox — behavioral and static. Each layer produces a weighted signal that feeds into the final confidence score.

Reputation lookup (VT, GSB) Domain intelligence Redirect chain tracing Credential form detection Brand impersonation check IOC correlation engine
⏱ 3 – 7 sec
Step 04
Verdict Issued

A confidence-scored verdict is produced with a complete evidence trail — signal breakdown, redirect chain, extracted IOCs, and an analyst-ready PDF report. No black-box decisions.

Score 0–100, 3-tier verdict Configurable thresholds Full signal breakdown Exportable PDF report IOC extraction
⏱ < 0.5 sec
Step 05
Auto Response

Verdict triggers instant multi-channel alerting and automated playbook execution. Cases are auto-created in the SOC, analysts are notified, and SIEM is updated — all before a human ever sees the email.

Slack, Teams, SMTP alerts Case auto-created in SOC Playbook triggers Syslog / SIEM forwarding
⏱ Instant
Platform features

Everything your security
team needs

From first detection to case closure — one platform handles the entire threat lifecycle.

Disposable Browser Isolation

Every suspicious URL is opened in a sandboxed container that is completely destroyed after analysis. Zero exposure to your real systems.

Attachment Sandbox

PDFs, Office files, executables and archives analyzed in isolation. Macro detection, PE analysis, and string IOC extraction included.

Multi-Layer Threat Scoring

Six detection layers combine reputation, behavior, redirect chains, credential form detection, and domain intelligence into a single confidence score.

Case Management

Every threat becomes a case with evidence, timeline, analyst assignment, SLA tracking, @mention notifications, and a full audit trail.

Automated Playbooks

Define response workflows that trigger automatically on verdict. Block, notify, escalate, or quarantine — without human delay.

Compliance Ready

Full audit logs, GDPR data retention, MFA enforcement, role-based access, and multi-tenant isolation. Enterprise deployable from day one.

SIEM / SOAR Integration

Native Syslog forwarding in CEF and JSON format. Webhook output to any endpoint. MITRE ATT&CK technique codes included in every event. Built for Splunk, Elastic, and CrowdStrike from day one.

MITRE ATT&CK Intelligence

Every verdict is automatically mapped to MITRE ATT&CK Enterprise v15 techniques. Export full ATT&CK Navigator layers. AI correlation agent generates technique-linked analyst briefings for every high-risk threat.

Live Platform

The platform your team
opens every morning

Not a mockup. Not a demo environment. This is Phantriq running live — SOC dashboard and threat intelligence in a single pane of glass.

Phantriq SOC Dashboard Phantriq Threat Intelligence
MITRE ATT&CK mapped on dashboard Real-time verdict split 8 threat category intelligence feed Top malicious domains & IPs live
Detection Engine

Six layers.
One verdict.

Every threat passes through six independent detection layers simultaneously. Each layer contributes a weighted signal to the final confidence score — no single layer can produce a false decision alone.

LIVE
LAYER 01
Reputation Analysis
Cross-references every URL and domain against VirusTotal (90+ AV engines) and URLScan.io in real time. Known blacklists, threat feeds, and historical scan data fused into a single reputation score.
VirusTotal URLScan.io 90+ engines score 0–100
LIVE
LAYER 02
Behavioral Analysis
Live DOM execution inside the sandbox captures credential form detection, redirect chain tracking (multi-hop), JS obfuscation, hidden fields, SSL certificate age, and domain registration recency.
credential forms redirect chains JS obfuscation domain age
LIVE
LAYER 03
NLP Tone Analysis
Detects social engineering tactics in email subject and body using weighted NLP pattern matching. Scores urgency, authority impersonation, fear induction, and financial pressure — in Turkish, English, and Arabic.
urgency fear authority financial TR · EN · AR
MITRE
LAYER 04
MITRE ATT&CK Mapping
Every verdict is automatically tagged with the corresponding MITRE ATT&CK technique (T1566.002, T1598, T1189 and more). The AI triage agent generates a correlation summary linking detected signals to the attack taxonomy.
T1566.002 T1598 T1189 ATT&CK v15 Navigator export
LIVE
LAYER 05
Brand Impersonation
Entity extraction engine identifies 40+ targeted brands (PayPal, Microsoft, Amazon, banking institutions) in email subject, body, and sender domain. Flags domain-brand mismatches and visual logo similarity.
40+ brands domain mismatch spaCy NER visual similarity
AI
LAYER 06
AI Triage Explanation
For every HIGH RISK or SUSPICIOUS verdict, an LLM agent (Claude / GPT-4o) generates a natural language analyst briefing. Privacy-first: raw email content never leaves your infrastructure — only structured signals are sent.
Claude · GPT-4o privacy-first TR · EN analyst briefing
Automated Response

Verdict fires.
Playbook executes.

Define once. Run automatically on every matching verdict. Your analysts stop triaging alerts manually — they start managing exceptions.

STEP 01
Threat Detected
Engine scores verdict HIGH RISK with confidence 87%
STEP 02
Playbook Triggers
Matching rule fires: severity CRITICAL, channel EMAIL
STEP 03
Actions Execute
Block sender — Quarantine email — Alert Slack — Create case
STEP 04
Case Closed
Full evidence chain, audit trail, PDF report — zero human delay
EXAMPLE PLAYBOOK RULE
If verdict HIGH RISK Block Sender Quarantine Email Alert Slack #soc Create Case
Real-world scenarios

Threats Phantriq stops
every day

From credential phishing to QR code attacks — three scenarios your team faces, and exactly how Phantriq handles each one.

Credential Phishing

Fake PayPal login page

An employee receives an urgent email: "Your account is suspended." The link points to secure-paypa1.com — a pixel-perfect PayPal clone with a live credential harvesting form.

Credential form detected — POST to attacker server
Brand spoof: PayPal logo + CSS similarity 94%
Domain registered 3 days ago, not in VirusTotal
PHISHING ⏱ 5.8 sec
QR Code Attack

QR code hidden in PDF

A PDF invoice contains a QR code labeled "Scan to confirm payment." Traditional SEGs see only a clean PDF. Phantriq extracts, decodes, and detonates the embedded URL in the sandbox.

QR code extracted from attachment page 2
Destination: 3-hop redirect → credential page
SEG bypass confirmed — PDF itself was clean
MALICIOUS ⏱ 7.1 sec
Malicious Attachment

Excel macro dropper

An "invoice_final.xlsx" from a spoofed supplier domain contains a VBA macro. On open, it executes silently — calling out to a C2 server and dropping a payload binary to the temp folder.

Macro execution detected in isolated sandbox
Outbound C2 call blocked — 185.220.x.x
Payload dropped to %TEMP% — zero host exposure
HIGH RISK ⏱ 12.4 sec
< 8 sec
Average analysis time
6
Detection layers per threat
99%+
Phishing detection accuracy
0
Host execution — fully sandboxed
Works with your existing security stack
Microsoft 365
Gmail
Slack
Teams
Splunk
CrowdStrike
VT
VirusTotal
Elastic SIEM
Syslog / CEF
REST API
More
Measured performance

Real numbers — no estimates

Every metric below is from benchmark v5 — 467 unique URLs across 7 benchmark iterations — 100 live sandbox executions + 6,300 mathematical simulation runs. Real signals, real execution, independently reproducible.

0%
Detection Rate
94 out of 100 malicious / suspicious URLs correctly flagged
0%
Precision
Of URLs flagged as threats, 85.5% were confirmed true positives
0
F1 Score
Harmonic mean of precision and recall — balanced accuracy measure
0%
False Positive Rate ↓
Inflated by tech/infosec domains (Azure, Ubuntu, NIST) atypical in corporate email*
Internal Benchmark v5 · 100 URLs · Live sandbox execution · April 27, 2026  ·  *FP context: all 8 false positives were legitimate security/infosec domains (DigitalOcean, Vercel, censys.io, NIST, etc.) — rarely seen in real enterprise email flows, so real-world FPR is expected to be lower.
Unique capabilities

What Phantriq does that
traditional SEGs don't

These are features we've built and ship today. No roadmap items. No vague checkboxes.

Phantriq
Traditional SEG
Disposable Browser IsolationEach URL opens in a real, ephemeral browser — destroyed after analysis
Dynamic Behavioral AnalysisDetects redirects, JS execution, form rendering, and credential harvesting at runtime
Screenshot Evidence CaptureFull-page screenshot stored per analysis for analyst review and audit trail
QR Code URL ExtractionDecodes QR codes embedded in email bodies and attachments before analysis
Redirect Chain TrackingFollows multi-hop redirects and records every domain in the chain
Partial
Multi-signal Fusion ScoringReputation + behavior + domain + form signals fused into a single explainable verdict
Verdict ExplainabilityEvery verdict includes per-signal score breakdown — no black-box decisions
Built-in Case ManagementAnalysts open, assign, and resolve cases without leaving the platform
Playbook AutomationDefine response playbooks triggered automatically by verdict and severity
IOC Auto-CorrelationExtracted IOCs cross-referenced across open and internal threat intel feeds
Partial
API-First ArchitectureEvery action available via REST API — built for SIEM/SOAR/XDR integration from day one
Varies
Live platform

Real-time verdict
full evidence trail

Analysts get a complete picture — not just a score, but the full behavioral breakdown that led to the verdict.

  • Redirect chain visualization
  • Credential form & phishing page detection
  • IOC extraction (IP, domain, URL, hash)
  • VirusTotal & Google Safe Browsing integration
  • Exportable PDF report per analysis
  • Cross-case IOC correlation engine
  • Multi-tenant SOC portal with role-based access
  • Full interface in English, Turkish & Arabic — built for global SOC teams
PHANTRIQ Intelligence Dashboard
LIVE
Threat Queue
Cases
IOC Map
Reports
ANALYZING 2s ago
https://secure-login.paypa1.com/verify
REPUTATION
HIGH
BRAND SPOOF
87%
CRED FORM
✓ POST
phishing credential-harvesting PayPal impersonation
91/100
https://invoice-portal.net/payHIGH RISK87
https://docs.google.com/spreadsheets/d/1A…CLEAN4
https://bit.ly/3xR9kzPSUSPICIOUS52
attachment: invoice_final.exeHIGH RISK95
IOCs EXTRACTED 185.220.101.47 paypa1.com 3 prior cases Case auto-created ✓
How isolation works

Zero-touch execution
zero host exposure

Every URL is detonated inside an ephemeral container that is completely isolated from your network — and permanently destroyed after analysis.

Suspicious Email / URL
Gmail · M365
REST API
Disposable Sandbox
Ephemeral container
Network isolated
ISOLATED
6-Layer Analysis
Reputation · Behavior
IOC · Brand · Cred
Verdict + Evidence
Score · IOCs
PDF report · Case
VERDICT
Container Destroyed
No trace remains
on host
DESTROYED
Container lifetime: < 800ms spin-up, destroyed immediately after
No malware ever executes on your infrastructure
Full network isolation — outbound calls blocked
Developer API

Integrate in
minutes

Full REST API with OpenAPI docs. One endpoint, one key, one verdict. Embed Phantriq's detection engine into any product or security workflow.

  • Verdict in <8 sec via single POST request
  • Webhook callbacks on verdict completion
  • Full OpenAPI 3.0 documentation
  • SDKs for Python, Node.js and Go
Request API Access
import requests

response = requests.post(
    "https://api.phantriq.com/v1/analyze",
    headers={"Authorization": "Bearer sk-live-..."},
    json={"url": "https://suspicious-site.com"}
)

result = response.json()
# result["verdict"]     →  "PHISHING"
# result["confidence"]  →  91
# result["signals"]     →  [...]
# result["report_pdf"]  →  "https://..."
FAQ

Common questions

Still have questions? Reach out to our team and we'll walk you through a live demo.

The only email security platform that actually opens the link.
How is Phantriq different from a Secure Email Gateway?
Traditional SEGs rely on static signatures and reputation databases. Phantriq actively opens and executes every suspicious link inside a disposable container, observing real-time behavior. This means we catch zero-day phishing pages, newly registered domains, and QR-code redirects that SEGs completely miss.
Does it require endpoint installation or agents?
No. Phantriq is fully agentless. It integrates via email API (Gmail / M365) or a REST endpoint. There is nothing to install on employee machines, and no changes to your mail routing are required beyond a simple forwarding rule or API key.
How long does a full analysis take?
Under 8 seconds for a complete URL analysis — from URL submission to verdict with full evidence trail. Attachment analysis varies by file type but averages 10–20 seconds. The sandbox container is spun up in under 800ms and destroyed immediately after.
What happens when a URL is flagged as malicious?
Phantriq triggers an automated response: multi-channel alerts (Slack, Teams, email), a SOC case is automatically created with full evidence attached, and any configured playbooks execute immediately — blocking the sender, quarantining the email, or escalating to a senior analyst based on your rules.
Is Phantriq GDPR compliant?
Yes. Phantriq includes configurable data retention policies, automated GDPR deletion workflows, full audit logs for every action, and role-based access control. Analysis data is scoped to each tenant with strict multi-tenant isolation. We can deploy on-premises or in your preferred cloud region.
Can it integrate with our SIEM or EDR?
Yes. Phantriq supports Syslog forwarding (CEF/JSON), webhook output to any endpoint, and native integration with Slack and Microsoft Teams. A REST API with full OpenAPI documentation is available. Custom integrations with Splunk, Elastic, and CrowdStrike are on the roadmap for Q3 2026.
Pricing

Built for security teams
of every size

No per-click fees. No hidden costs. Full platform access from day one.

SOC Team
Starter
For growing security teams that need fast, reliable phishing detection without the enterprise overhead.
  • Up to 5 analyst seats
  • 5,000 URL analyses / month
  • Email API integration (Gmail / M365)
  • 6-layer behavioral detection
  • PDF report export per analysis
  • Case management + IOC correlation
  • Slack & Teams alerting
  • Standard SLA (24h support)
Contact for Pricing
MOST POPULAR
Enterprise
Professional
For SOC teams and enterprises that need full automation, multi-tenancy, and custom detection tuning.
  • Unlimited analyst seats
  • Unlimited URL + attachment analysis
  • Multi-tenant portal with RBAC
  • Custom detection profiles + thresholds
  • Playbook automation engine
  • SIEM forwarding (Syslog / CEF / JSON)
  • CrowdStrike & Splunk integration
  • Country risk scoring (configurable)
  • MFA enforcement + audit logs
  • Priority SLA (4h response)
Contact for Pricing
API / OEM
Platform
Embed Phantriq's analysis engine directly into your own product or security platform via REST API.
  • Full REST API access
  • High-throughput analysis endpoint
  • Webhook verdict callbacks
  • Custom verdict schema
  • White-label ready
  • On-premises or cloud deployment
  • Dedicated sandbox infrastructure
  • 99.9% uptime SLA
  • Engineering onboarding support
Contact for Pricing

All plans include a 14-day proof-of-concept. On-premises deployment available for all tiers.

Deployment

Deploy your way
no compromise

Phantriq is built for enterprise environments where data sovereignty and infrastructure control are non-negotiable. Choose the deployment model that fits your security policy.

Cloud
Fully managed infrastructure. Automatic updates, built-in redundancy, and 99.9% uptime SLA. Up and running in hours, not weeks.
Managed updates Auto-scaling 99.9% SLA
On-Premises
Deploy entirely within your data center. No data leaves your network perimeter. Full control over infrastructure, storage, and retention. Air-gapped environments supported.
Data sovereignty Air-gap ready Full control
Hybrid
Cloud management plane with on-premises data processing. Centralized visibility, distributed execution. Ideal for multi-site enterprises and regulated industries.
Flexible architecture Multi-site Regulated industries
ROI Calculator

What does a phishing
attack cost you?

Adjust to match your environment. See your estimated monthly exposure and what early detection saves.

5,000
5
$150,000
94
Threats blocked / month
188 hrs
Analyst hours saved / month
$4.3M
Estimated exposure prevented
$0
Annual savings estimate

* Verizon DBIR 2024 · Proofpoint Email Security Report 2024 · SANS SOC Survey · IBM Cost of a Data Breach 2024

Our journey

From idea to platform
17 months

Phantriq started as a question: why do security teams still open suspicious links manually? Every milestone below is a direct answer to that question.

Nov 2024
Concept & Architecture
Identified the core gap: traditional SEGs never actually execute suspicious content. Architectural decision: disposable browser isolation as the foundation.
Jan 2025
First Working Engine
URL analysis engine operational. FastAPI backend, Playwright-based disposable browser, Docker container isolation. First end-to-end analysis running in under 12 seconds.
Mar 2025
6-Layer Detection System
Multi-signal scoring launched: reputation, behavioral analysis, credential harvesting detection, redirect chain tracking, visual brand similarity, TLS validation. Detection rate crosses 85%.
May 2025
Full SOC Platform
Case management, triage queue, IOC correlation, playbook automation, analyst assignment, SLA tracking. Phantriq becomes a complete SOC workflow, not just a scanner.
Jul 2025
Enterprise Integrations
Gmail, Microsoft 365, Slack, Teams, Splunk, CrowdStrike, VirusTotal connectors. Multi-tenant architecture, RBAC, MFA, full audit logging. Built for enterprise from day one.
Oct 2025
Attachment Scanning & Hardening
PDF, Office, Excel sandbox detonation. VBA macro detection. Security hardening: brute-force protection, HTTP security headers, stack trace sanitization, CORS hardening.
Jan 2026
Detection Optimization
Configurable detection profiles, per-client scoring weights, country risk engine. False positive rate reduced. Multi-language platform (TR / EN / DE / FR / AR).
Apr 2026
Private Beta — Platform Ready
Benchmark v5: 100 live sandbox executions, 94% detection rate, F1 score 0.895. 467 unique URLs tested across 7 benchmark iterations, 6,300+ simulation runs. Full vendor & admin portal. Platform ready for first enterprise customers. Currently onboarding select security teams.
BUILT WITH BATTLE-TESTED TECHNOLOGY
Python 3.12
FastAPI
Docker
Playwright
PostgreSQL
Redis
VirusTotal API
Google Safe Browsing
React + TypeScript
Celery + Beat
THE BUILDER

Melik Öztürk

Founder & Lead Engineer

Built Phantriq after observing how traditional email security tools consistently miss sophisticated phishing attempts. Every line of the detection engine, the isolated browser sandbox, and the SOC dashboard was designed and written by me — with enterprise security teams in mind from day one.

Cybersecurity Backend Engineering Threat Detection Docker & Sandboxing SOC Tooling
Melih Genç — Co-Founder & Head of Business Development
THE CONNECTOR

Melih Genç

Co-Founder & Head of Business Development

Drives enterprise partnerships and go-to-market across the Turkish and regional market. Economics background with a focus on turning technical capability into real-world customer relationships.

Business Development Enterprise Sales Turkey & MENA
Seed Stage

We're building something
the market needs now

Phantriq is an early-stage company with a working platform, a real benchmark, and a clear path to enterprise deployment. We're currently exploring strategic partnerships and seed investment to accelerate go-to-market.

Get in touch →
Stage
Working product · Private beta · Seeking seed
Market
$5.3B email security · 14.8% CAGR · Enterprise focus
Traction
94% detection rate · F1: 0.895 · 17 months to platform
Security & compliance

Enterprise-ready
by design

Phantriq is built from day one with enterprise procurement requirements in mind. Here's where we are and where we're going on the compliance roadmap.

01
Live · April 2026
Platform security baseline
  • Full audit logging on every action
  • MFA enforced across all roles
  • RBAC with multi-tenant isolation
  • Encrypted data at rest and in transit
  • HTTP security headers + CORS hardening
02
Q3 2026
SOC2 Type I preparation
  • Independent penetration test
  • Formal security policies documentation
  • Vendor risk assessment process
  • Incident response playbook
  • GDPR data processing records
03
Q4 2026
SOC2 Type I + ISO 27001
  • SOC2 Type I audit targeted
  • ISO 27001 gap analysis planned
  • NIS2 compliance documentation
  • BDDK/SPK readiness report
  • Enterprise procurement package targeted

Security documentation available to enterprise prospects under NDA. Contact us for the full security posture report.

Currently in Private Beta

Get early access
to Phantriq

We're onboarding a limited number of security teams for our private beta. Join the waitlist and we'll reach out to set up a hands-on proof of concept.

No spam. We reach out personally within 48 hours.

You're on the list!

We'll be in touch within 48 hours — check your inbox.