01Pharoah Technology · securitylive
GhostCommand
Manage device fleets by applying signed policies, commands, and updates while preventing administrators from accessing user content.
Live · ghostcommand.ghostwire.co.uk/health2 parts · 0 probe-verified
Pharoah Technology Ltd (Craig Attoh and Phil Pereira, 50/50)ghostcommand.ghostwire.co.uk/health
02What it is
The facts, from the register.
| Product | GhostCommand — zero-knowledge device fleet management |
| Register key | ghostcommand |
| Owner | Pharoah Technology Ltd (Craig Attoh and Phil Pereira, 50/50) |
| Live at | ghostcommand.ghostwire.co.uk/health · HTTP 200 on 9 September 2026 |
| Price | priced at launch |
| Built from | 2 register parts, 0 live, 0 probe-verified |
| Listed | 14 August 2026 |
What it does
Manage fleets of privacy-focused devices — signed policy, signed commands, signed updates — without giving administrators access to user content.
Runs on
GhostCommand server-authoritative ownership mode
GhostCommand — zero-knowledge device fleet management
Source: estate register (products, product_parts, builder_blocks) · deploy probe 9 September 2026Evidence live
03The frameWhat this buyer's profession checks
We will measure it against the NCSC Cyber Assessment Framework.
Three checks a buyer in this field applies, whether or not they name the standard. We use them as the frame for everything that follows.
Check 1
Assets and access under control
Check 2
Detection with an evidence trail
Check 3
Response rehearsed, not improvised
Frame chosen by BRG as a summary of the NCSC Cyber Assessment Framework. Verify the wording with the body before external use.No accreditation is claimed
04Why it's better · 1 of 6Check 2 · fit for purpose
The job as the register describes it.
Managing a device fleet normally means giving administrators access to user content — the management tool becomes the exposure.
Who carries it
IT administrators managing privacy-focused device fleets without accessing user content.
Source: register pain_point · audienceThe problem, stated plainly
05Why it's better · 2 of 6Check 2 · fit for purpose
What it does instead.
Manage device fleets by applying signed policies, commands, and updates while preventing administrators from accessing user content.
Manage fleets of privacy-focused devices — signed policy, signed commands, signed updates — without giving administrators access to user content.
The parts doing the work
GhostCommand server-authoritative ownership mode
Closed a proven one-enum bypass: check_privacy_policy trusted the device-asserted report.ownership_mode, so a modified BYOD agent relabelled itself Or
GhostCommand — zero-knowledge device fleet management
Rust workspace: 10 crates, 583 tests, PostgreSQL schema with forced RLS (cross-tenant isolation verified), Helm chart refusing 9 insecure production c
Source: register purpose, public_blurb, product_parts joined to builder_blocks2 of 2 parts shown
06Why it's better · 3 of 6Check 1 · controls
Proof it exists, not a roadmap.
200
HTTP status of ghostcommand.ghostwire.co.uk/health on 9 September 2026 · healthy
0/2
register parts verified by probe
HTTP 200
functional surface probe
Open ghostcommand.ghostwire.co.uk/health during the talk. Anything the deck claims should be visible there.
Source: register deploy_probe_code, deploy_probed_at, product_parts.verified_by_probeProbed, not promised
07Why it's better · 4 of 6Against the market, honestly
Where we lead, and where we don't.
Not in the register yet a competitive assessment. This slide stays blank until the register carries it; nothing here is invented.
Source: register vs_competitionNamed competitors are the register's, not the presenter's
08Why it's better · 5 of 6Check 2 · fit for purpose
Built for one kind of buyer.
IT administrators managing privacy-focused device fleets without accessing user content.
Source: register audience, serves_nichesOne buyer, not everyone
09Why it's better · 6 of 6Price is part of the scope
What it costs, in one line.
Not in the register yet a price. This slide stays blank until the register carries it; nothing here is invented.
Buying route
Payment on enquiry
software
Scope named on the next slides, so the price has a boundary
Source: register price_gbp, billing_interval, pricing_basis, payment_link_activeNo hidden rate card
10What's inside
The parts, with their verification state.
| Part | Category | State | Verified |
|---|
| GhostCommand server-authoritative ownership mode | backend | built | |
| GhostCommand — zero-knowledge device fleet management | backend | built | |
Source: product_parts joined to builder_blocks · 2 of 2 shown probe-verified not yet
11Why packaging matters
Bought as a price.
Delivered as a scope.
What the buyer hears
a price
A number to compare with the last number.
the gap
disputes · churn
unpaid work
What the provider means
A scope
2 parts, some verified, some not, plus everything that is excluded.
Packaging is the instrument that makes the scope as visible as the price.Thesis
12Why packaging matters
Five things a package does that a price cannot.
1Scope becomes visible. The parts are named, so nothing is assumed.
2Boundaries are explicit. What is outside is written down before the first invoice.
3It is auditable. A package is a documented process, which is what the NCSC Cyber Assessment Framework looks for.
4Buyers compare like for like. A referral needs a defined thing to refer.
5Switching fear drops. The move is inside the package, not a project bolted on the front.
Source: BRG packaging doctrine; frame from slide 3Packaging = a compliance instrument
13This packageCut by what each part does
GhostCommand, as a package.
backend
GhostCommand server-authoritative ownership mode
Closed a proven one-enum bypass: check_privacy_policy trusted the device-asserted report.ownership_mode, so a
builtGhostCommand — zero-knowledge device fleet management
Rust workspace: 10 crates, 583 tests, PostgreSQL schema with forced RLS (cross-tenant isolation verified), Hel
built
Source: product_parts grouped by builder_blocks.category1 groups
14Anatomy of the packageOn one page · 4 items of work left, filed
A package reads like a control document.
Inside the scope
- GhostCommand server-authoritative ownership mode
- GhostCommand — zero-knowledge device fleet management
Evidenced, and how
- Live URL probed: HTTP 200 on 9 September 2026
- 0 parts probe-verified
- Functional surface: HTTP 200
- Register row updated with every probe
Outside the scope today · work left
- No build gap recorded in the register
- 2 parts still to verify by probe
- 2 register fields to fill (vs_competition, price_gbp)
Who signs, and where the work sits
- Pharoah Technology Ltd owns the product and the data layer
- 0 build packets proposed · 4 management items pending
- Change log kept in the register
Source: product_parts (inside), deploy and part probes (evidenced), v_deck_work_left (work left; filed to manager_work and build_packets by deck_work_left_sync)One page
15Across the family
Where it hands over.
Anaïs AIgateway.pharoahtechnology.com
Anaïs AI (LLM router / reseller)anaisai.co.uk
Anaïs AI (working app)anaisai.co.uk
Pharoah TechnologyGhostCommandghostcommand.ghostwire.co.uk/health
ATS Résumé Scanner (free)ats.pharoahtechnology.com
Aurora AIauroraai.pharoahtechnology.com
Aurora Guardauroraguard.co.uk
Source: register rows sharing client_key pharoahOne house, many doors
16Close
Three things to take back to your desk.
One
Open the URL on slide 6. Test it before you trust it.
Two
The parts and their verification state are on slide 10.
Three
A package is a compliance instrument, not a price list.
See it live
ghostcommand.ghostwire.co.uk/health
Talk to us
via ghostcommand.ghostwire.co.uk/health
Pharoah Technology Ltd (Craig Attoh and Phil Pereira, 50/50)Pharoah Technology