The anti-ransomware engine is Halcyon’s. We’re telling you that on the first line.
Argos Defense is Halcyon — a platform built to do one thing rather than everything — deployed, tuned and watched by us, and wired into the Argos Kernel so a detection becomes a triaged alert, a ticket and a co-signed containment decision instead of an email nobody opens. We could have left the vendor name off this page. Most of the industry does, and calls the result “our proprietary engine.” A platform whose entire argument is check us does not get to be vague about whose code is stopping the ransomware.
Whose is what.
The question an MSP owner should ask any vendor selling security is which parts they wrote and which parts they resell. Here is our answer before you ask it, in the order it matters.
If the only thing we added were a login screen and a markup, you should buy Halcyon directly and we would tell you so. The last row is the reason not to.
What the engine actually does.
Most endpoint tools treat ransomware as one alert class among thousands and are graded on the average case. Ransomware has no average case — it is the one attack where the difference between catching it and nearly catching it is the whole business. The right-hand column says which layer each capability belongs to.
A detection is not an outcome. The gap between them is the product.
Standalone anti-ransomware protects a machine and then hands you a notification. What happens in the next four minutes — who is that user, what else do they touch, who is on call, does anyone open a ticket, does the account get pulled — is work, and in most stacks it is human work performed across four consoles at 2am. Defense is an Argos citizen, so that work is data movement inside one system instead of copy-paste between vendors.
- One identity, not a name to match. The endpoint that fired resolves against the same client graph your tickets, contracts and compliance evidence already use. Nothing has to be reconciled, because nothing is a copy.
- One triage queue. The alert lands in the same queue as everything else your analysts look at — not in a twelfth portal with its own password and its own idea of severity.
- The PSA ticket opens itself. Detection to alert to a ticket in Argos Service, assigned, with the timeline attached. This path is live today.
- Containment takes two human approvals•. Nothing isolates a host because a model felt strongly about it. Two distinct people sign, and isolation is reversible network containment — nothing is deleted, ever.
- The audit spine records it. Every step is written to a hash-chained, append-only• log the database itself refuses to alter — which is what an incident report is made of when the insurer, the auditor or the client asks what happened.
Roadmap Automated containment is built and verified end to end in dry-run, and has not yet been used to lock down a production endpoint.• The detection, alert and ticket path is live. The lockdown is not proven, so we are not going to imply that it is — you would find out during someone’s worst afternoon, and that is the worst possible moment to discover a marketing page was optimistic.
There is a warranty. It is Halcyon’s, and so are its conditions.
Halcyon offers a ransomware warranty• behind its protection. It is worth understanding precisely, because a warranty stated loosely is worse than no warranty at all — it is a thing you believe you have.
Notice what is missing from that table: a number. We are not publishing an amount here. The amount, and everything that qualifies it, is set by Halcyon and confirmed for your environment during onboarding — and a figure printed on a marketing page, stripped of the four conditions sitting above it, is the exact shape of a promise that fails in the one week it matters. Halcyon publishes its own terms at halcyon.ai/warranty ↗. Read them there, from the company that has to honor them.
A warranty is not insurance, and Intelligent Automation is neither an insurer nor a broker. What we are is the party that keeps the conditions true: blocking mode on, anti-tamper on, versions current, and someone watching — because every one of those is a way a warranty quietly stops applying while everyone assumes it still does.
partner-provided · terms set by HalcyonWhat we can and cannot say about this yet.
We have zero• Argos OS customers today — the platform soft-launches in September 2026. So there is no fleet, no ransomware-incidents-stopped counter, and no case study, and you should be suspicious of anyone at our stage who has one. What exists is the engine, which is Halcyon’s and has its own record you can research independently; the integration, which is ours and which we run against our own 26• clients every day; and this page, which will be updated the moment either of those statements changes.
our own environment · not customer scaleDon’t trust us. Check us.
Ransomware defense, with the vendor named.
We deploy Halcyon across your environment, tune it, watch it, wire it into your tickets and your audit trail, and tell you plainly which parts are ours. Start with a conversation, not a contract.