Fairfield, NJ · Metro New York(888) 711-4521 · Toll-FreeBuilt & operated by Intelligent Automation
Anti-Ransomware · Argos Defense

The anti-ransomware engine is Halcyon’s. We’re telling you that on the first line.

Argos Defense is Halcyon — a platform built to do one thing rather than everything — deployed, tuned and watched by us, and wired into the Argos Kernel so a detection becomes a triaged alert, a ticket and a co-signed containment decision instead of an email nobody opens. We could have left the vendor name off this page. Most of the industry does, and calls the result “our proprietary engine.” A platform whose entire argument is check us does not get to be vague about whose code is stopping the ransomware.

Attribution

Whose is what.

The question an MSP owner should ask any vendor selling security is which parts they wrote and which parts they resell. Here is our answer before you ask it, in the order it matters.

Ransomware detection, prevention and behavioral engine Halcyon
Encryption-key capture and file recovery Halcyon
Ransomware warranty, and every term in it Halcyon
Deployment, tuning, policy and the 24/7 watch on your environment Intelligent Automation
Kernel integration, one triage queue, automatic PSA ticket, co-signed containment Argos

If the only thing we added were a login screen and a markup, you should buy Halcyon directly and we would tell you so. The last row is the reason not to.

The capability

What the engine actually does.

Most endpoint tools treat ransomware as one alert class among thousands and are graded on the average case. Ransomware has no average case — it is the one attack where the difference between catching it and nearly catching it is the whole business. The right-hand column says which layer each capability belongs to.

Built for one attack, not bolted onto twelve. An AI engine trained on ransomware behavior, backed by a behavioral layer that sees through evasion and anti-detonation tricks. A specialist, not a generalist with a ransomware checkbox. Halcyon engine
Caught at multiple stages, not just at encryption. Coverage spans initial access, privilege escalation, credential theft, lateral movement and the encryption event itself. An attacker has to beat several layers in sequence, not one door. Halcyon engine
Recovery through captured keys. The engine captures the encryption keys as the ransomware deploys them. If files are encrypted, they can be decrypted and restored — recovery that does not depend on a backup surviving the attack that came for it. Halcyon engine
Your recovery points, shielded. Modern ransomware deletes shadow copies and backup data first, hours before anything visibly breaks. Defense guards them against tampering, so the thing you would rely on is still there when you reach for it. Halcyon engine
It resists being switched off. Real-time anti-tamper, a last-gasp guard if something tries to disable detection, and kernel-level defense against attacks that abuse signed vulnerable drivers — because killing the security tool is step one of a competent intrusion. Halcyon engine
Watched around the clock, by people. Halcyon operates a dedicated ransomware operations center. We watch your tenant on top of it, tune the policy, and own the conversation with you — you are not filing a ticket into a vendor you have no relationship with. Halcyon · IA
capability as described by Halcyon · deployment and watch by us
What Argos adds

A detection is not an outcome. The gap between them is the product.

Standalone anti-ransomware protects a machine and then hands you a notification. What happens in the next four minutes — who is that user, what else do they touch, who is on call, does anyone open a ticket, does the account get pulled — is work, and in most stacks it is human work performed across four consoles at 2am. Defense is an Argos citizen, so that work is data movement inside one system instead of copy-paste between vendors.

  • One identity, not a name to match. The endpoint that fired resolves against the same client graph your tickets, contracts and compliance evidence already use. Nothing has to be reconciled, because nothing is a copy.
  • One triage queue. The alert lands in the same queue as everything else your analysts look at — not in a twelfth portal with its own password and its own idea of severity.
  • The PSA ticket opens itself. Detection to alert to a ticket in Argos Service, assigned, with the timeline attached. This path is live today.
  • Containment takes two human approvals. Nothing isolates a host because a model felt strongly about it. Two distinct people sign, and isolation is reversible network containment — nothing is deleted, ever.
  • The audit spine records it. Every step is written to a hash-chained, append-only log the database itself refuses to alter — which is what an incident report is made of when the insurer, the auditor or the client asks what happened.

Roadmap Automated containment is built and verified end to end in dry-run, and has not yet been used to lock down a production endpoint. The detection, alert and ticket path is live. The lockdown is not proven, so we are not going to imply that it is — you would find out during someone’s worst afternoon, and that is the worst possible moment to discover a marketing page was optimistic.

The warranty

There is a warranty. It is Halcyon’s, and so are its conditions.

Halcyon offers a ransomware warranty behind its protection. It is worth understanding precisely, because a warranty stated loosely is worse than no warranty at all — it is a thing you believe you have.

Who provides it Halcyon — not Intelligent Automation
What it goes toward Halcyon’s expert incident-response and recovery services, following a covered incident
What it is conditioned on Active blocking-mode protection · anti-tamper enabled · a supported version · prompt notice
Who sets eligibility and terms Halcyon — confirmed at onboarding

Notice what is missing from that table: a number. We are not publishing an amount here. The amount, and everything that qualifies it, is set by Halcyon and confirmed for your environment during onboarding — and a figure printed on a marketing page, stripped of the four conditions sitting above it, is the exact shape of a promise that fails in the one week it matters. Halcyon publishes its own terms at halcyon.ai/warranty ↗. Read them there, from the company that has to honor them.

A warranty is not insurance, and Intelligent Automation is neither an insurer nor a broker. What we are is the party that keeps the conditions true: blocking mode on, anti-tamper on, versions current, and someone watching — because every one of those is a way a warranty quietly stops applying while everyone assumes it still does.

partner-provided · terms set by Halcyon
Scope

What we can and cannot say about this yet.

We have zero Argos OS customers today — the platform soft-launches in September 2026. So there is no fleet, no ransomware-incidents-stopped counter, and no case study, and you should be suspicious of anyone at our stage who has one. What exists is the engine, which is Halcyon’s and has its own record you can research independently; the integration, which is ours and which we run against our own 26 clients every day; and this page, which will be updated the moment either of those statements changes.

our own environment · not customer scale

Don’t trust us. Check us.

Ransomware defense, with the vendor named.

We deploy Halcyon across your environment, tune it, watch it, wire it into your tickets and your audit trail, and tell you plainly which parts are ours. Start with a conversation, not a contract.

Secured by IA