Skip to content
BastionCyber
Bastion Cyber presents GhostShield V3.0 — Endpoint Detection & Response for Linux

Inside the host, your network defenses are blind. Drop the hammer
before the payload
executes.

Once an attacker is executing on the host, your perimeter is behind the fight. GhostShield decides inside the kernel, at the moment the action is attempted: a move that violates policy is refused before it lands, not written up after it has. It is Surgical Defense — the offending operation is denied or the process tree is frozen in place, while the rest of the host keeps serving. What it contains stays inspectable, and every decision lands in a local audit trail where a later edit is detectable.

And it answers the question that actually decides the purchase: what happens when the agent is wrong? The fear is not the malware — it is the endpoint agent killing PID 1’s database at 3 a.m. over a false positive. GhostShield is built the other way round: containment is scoped to the offending process tree, the services you declare are exempt from lethal enforcement, and every defence that cannot classify an action lets it through rather than guessing. A Zero-Outage posture is the design goal of the engine, not a slogan bolted onto it.

  • 0.0–0.5%CPU, day to day
  • ChainedTamper-evident logs
  • 0Cloud dependencies†
  • 1Command to operate

† Forensics, detection and logs stay on the host. The agent opens no outbound connection of its own: it has no HTTP client compiled into it, and it verifies your licence offline, against a public key built into the binary. The one exchange with us happens off the agent — you collect your signed licence key here, on this site, once, before you install.

Requires Linux kernel 5.8 or newer. Guided two-step install: kernel preparation first, then the agent. Runs on modern Linux distributions that provide BPF LSM — cloud, bare metal or VM. Nothing is sent off the host.

Server requirements. Linux kernel 5.8 or newer — the engine's event channel is the BPF ring buffer, introduced in that version. The kernel also needs BTF (CONFIG_DEBUG_INFO_BTF) and BPF LSM (CONFIG_BPF_LSM), which is the default in the generic cloud images of Ubuntu, Debian, RHEL and derivatives, plus unified cgroup v2 for the process-freeze containment. The installer checks all four before writing anything and stops with the reason, leaving no files behind.

Measured, not claimed — Zero-Overhead engineering

Corporate defence should not eat the infrastructure it protects

Security software earns its place by what it costs you when nothing is happening. GhostShield decides inside the kernel, on the syscall path: there is no scanning pass, no agent polling loop and no queue to drain, so the machine's capacity goes back to the workload you bought it for. The figures below were measured in production on AWS, under load and not at idle. Your hardware and workload will move them, which is what the free trial is for.

0.0–0.5% CPU, day to day

The range observed on an AWS production instance in ordinary operation. Decisions are taken in microseconds inside the kernel, on the syscall path — there is no periodic scanning pass and no backlog queue to drain.

<50MB Engine memory

Resident size of the Ring 0 engine — about 2.0% of a 2 GB instance. Bounded by design: the footprint does not grow with the size of an incident.

*<50 MB applies strictly to the Ring-0 Enforcement Engine. The complete EDR suite — including Argos telemetry and the Tarpit — operates at <120 MB total footprint.

Chained log Tamper-evident audit

Every event is cryptographically chained to the one before it, so an edit or a deletion — including one made with root privileges — breaks the chain and is surfaced by verification.

Zero Outbound telemetry

No cloud console, no phone-home, no telemetry upload. The agent opens no outbound connection of its own, and incident data stays on the server you own.

Forensics, detection and logs are entirely local. The only exchange with us is the one-time issue of your signed licence key, done here on the website before installation — the installed engine then verifies it offline, against a public key compiled into the binary.

Where the budget goes back. Corporate-grade protection does not have to devour your infrastructure. GhostShield runs invisibly at Ring 0 — no user-space scanner walking the filesystem, no agent waking on a timer, no telemetry upload competing with your traffic — and gives the machine’s resources back to what actually matters: your operation. The cost is paid per governed syscall, in microseconds, and only when one is attempted.

Contain the attack without destroying the evidence

Killing a malicious process ends the incident and your investigation at the same time. GhostShield freezes the process tree instead of terminating it: execution stops, while the process, its memory and its open file descriptors are preserved for forensics or for your insurer. The outbound connections it opened are already on the record, attributed to it.

Enforce at the syscall layer

A governed action that violates policy is denied as it is attempted, in milliseconds.

Contain evidence intact

The process tree is frozen in place and stays inspectable, instead of being destroyed.

Prove tamper-evident

Each event is sealed to the previous one, so an edit or a deletion is detectable.

Capabilities

What GhostShield does for your business

Six outcomes, each answering a way modern attacks actually end in a loss — lateral movement, in-memory payloads, an alert queue nobody reads, a disk filled by the tool itself, and an audit trail nobody can trust afterwards.

Deterministic Threat Containment Lateral movement

A process that trips containment is frozen where it stands, together with the tree it spawned, halting its progress on that host. It is held intact rather than killed, so you keep the evidence your investigation, your insurer and your regulator will ask for.

evidence preserved

Fileless Attack Defense In-memory payloads

The attacks that defeat file-scanning products never write a file: they run straight from memory. GhostShield acts on the operation rather than the artefact — a cross-process memory write that violates policy is denied at the syscall boundary, and the attempt is written to the audit trail.

denied in the kernel

Automated Attack Defense Bots and scanners

Most attempts on an internet-facing server come from automation that never sleeps. Reconnaissance is scored as it happens, and every program that starts — reverse shells, droppers, crypto miners included — is recorded at launch with its caller and its origin. When the score crosses the line, the process and everything it spawned are frozen where they stand.

scored as it happens

Deception Tarpit Bots and scanners

A decoy service greets the scanners that sweep every internet-facing host. Once a bot or a brute-force script connects, the socket is held open and answered one byte at a time, on a long delay — a pit of tar that stalls the attacker’s tooling on a dead end while it learns nothing. The trap runs unprivileged, capped so it can never load the host it protects.

the attacker pays the time

Invisible Decoy Seeder Lateral movement

Honeytoken files are planted across the system directories an intruder searches first — credentials, keys, backups that look real and exist only to be touched. The decoy paths never appear in any script or config an attacker could read; the moment one is opened, the process is flagged at Ring 0. Reconnaissance becomes the signal.

bait that only an intruder finds

Trip-Wire Anti-Tamper Sabotage of the agent

Disabling the guard is the attacker’s first move, so the guard defends itself in the kernel. A forced kill of the engine or its decoys from outside the protected set is refused at Ring 0 and raised as a tamper event; the binaries cannot be deleted or overwritten; and if the process is stopped it is brought back. The shield is not a soft target.

the guard guards itself

Tamper-Evident Forensics Contested incidents

When an incident becomes a claim, a filing or a dispute, the question stops being what happened and becomes whether you can prove it. Every event is sealed to the one before it, so a rewrite or a quiet deletion — including one made with root privileges — leaves a break in the chain. One command verifies the whole record.

evidence that holds up

Low-Noise Alerting Alert fatigue

A dashboard that lists everything is a dashboard nobody reads — and the row that mattered was on screen the whole time. GhostShield shows decisions, not chatter: routine activity is recorded to the trail but kept off the screen, and the alarms your own installation raises are held back so day one is not a wall of false urgency. The counters still show everything, and the panel always states how much it is holding back.

only what needs a decision

Predictable Storage Footprint The agent filling the disk

Security software that fills a production disk becomes the outage it was bought to prevent. The audit trail is capped: past the limit the older half is compressed into a single rolling archive and the recent history stays instantly readable. Log growth is bounded by design, and retention cannot be configured back into “keep everything”.

bounded by design

Behavioral Risk Engine Memory-borne payloads

A constant-time (O(1)) behavioral layer built for ISP-scale hosts: writable-executable memory is treated as a signal, not a verdict. Legitimate JIT runtimes — Node.js, Nginx/OpenResty and other SaaS engines — keep running, because that analysis is silent and never blocks memory on its own. Dynamic JIT Tolerance and Layered Defense mean Ring 0 enforcement engages only when a flagged process then attempts a suspicious outbound connection or an unauthorized execution — stability for legitimate operations without giving up kernel-level blocking.

O(1) per event
Coverage

4 Core Protections, one agent

Every protection below appears by name on your dashboard — three as live counters, Immunity Matrix as a live state. Nothing here is an add-on, an upsell or a separate product: one licence per server turns on all four.

Zero-Trust Execution Malicious payloads 01

Every program that starts on the server is evaluated against policy before execution completes. Executions that match an enforcement rule — droppers, miners and reverse shells among them — are denied at launch, and what tried to run, from where and on whose behalf is written to the trail.

processes stopped

Memory Shield Fileless attacks 02

Guards a process’s memory from another process reaching into it — both reading it (credential dumping: stolen keys, tokens, passwords) and writing it (in-memory implants that never touch disk). Routine metadata reads by the OS pass untouched; the memory itself is where the line is drawn.

dumping & injection

Behavioral Network Defense C2 & exfiltration 03

Every outbound connection is attributed to the process that opened it and written to the trail — caller, destination, time. And the engine reads the shape of the traffic: a process reaching out at rigidly regular intervals — the heartbeat signature of command-and-control and autonomous agents — is flagged and its process tree contained, by behavior alone. Zero configuration: no allowlists to build, no threat-IP feed to maintain — the pattern is the tell.

Bulk egress goes through the Ancestry Funnel, and this is where surgical beats blunt. When a transfer crosses the volume and ratio thresholds, the engine asks the kernel whose descendant the sender is: a process under an interactive login session — the shape of a stolen credential moving data out — has the socket denied while the process itself stays alive and inspectable; a declared service daemon is recorded and left to work. An action the funnel cannot classify is recorded, never cut.

C2 beacon detection Ancestry Funnel

Immunity Matrix False-positive lockout 04

You name the workloads that matter — the database and its telemetry workers, the web tier, your observability and SIEM agents, the container runtime — by cgroup, and immunity follows the whole process tree beneath them, not just the process you named. Those workloads stay exempt from the engine's lethal defenses, so a legitimate tool doing legitimate work is not frozen or blocked by the security layer itself. The agent is fail-open by design: where policy cannot reach a verdict it lets the work through, so a degraded security layer is not turned into a degraded service.

fail-open, immunity by cgroup subtree

And a threat sensor watching across all four. Beyond the individual protections, the agent scores behaviour across the whole server rather than judging each action alone — so a slow, patient intrusion that looks harmless step by step still surfaces as one incident, with the sequence that led to it attached. When the score crosses the line, the process and everything it spawned are frozen where they stand.

Lineage intelligence, not blind density. Volume alone is a poor verdict: a package upgrade rewrites files in bursts, and so does ransomware. GhostShield weighs where the activity came from and whether it is still behaving like the thing it claims to be — so a known workload doing known work is not treated as an intruder, and it loses that benefit the moment it stops behaving like itself. Fewer interrupted maintenance jobs; no softening of the verdict on something nobody recognises.

Immunity Matrix — the continuity framework

This is the answer to the question every SysAdmin asks before installing an endpoint agent on a production box: what protects Nginx, the database and my legitimate daemons from the security tool itself? It is a surgical continuity posture: a declared boundary you control, not a promise we make about outcomes. High-throughput services behave, on the wire, a lot like the threats the agent looks for: a database replicating, a proxy fanning out, a backup job streaming off-box, an NTP client polling on a fixed cadence. VIP Isolation is how you tell GhostShield which workloads you trust to run known code — so their normal work is never mistaken for an incident, and a false positive cannot reach the units your revenue runs on. It is a deliberate trust boundary, and it is meant to stay small.

What it exempts

Naming a unit exempts it and its whole cgroup subtree from the agent's lethal enforcement — both the network volume and frequency heuristics (beaconing, bulk exfiltration) and the Ring 0 behavioural defences (memory W^X, execution, ptrace, file tampering, decoy access, induced freeze). A trusted database, proxy, backup job or JIT runtime often does exactly what those defences watch for — writing then executing memory, moving data in bulk — and VIP is what stops that legitimate work from being contained.

Why it stays small

Because the exemption is complete within the subtree, a VIP workload is a workload you have decided to trust: if it is later compromised, the agent treats its actions as that trusted service's. So name only services whose code you control. VIP is keyed by the systemd unit, not by process name — a renamed or forked binary cannot inherit immunity it was not granted — and the EDR's own binaries are protected by inode-level self-defence that is independent of any VIP entry. Everything you do not name keeps the full set of protections.

Who to name

Name the services whose job is high or repetitive traffic: databases and their replication, reverse proxies and API gateways, backup and sync jobs, container and orchestration runtimes, and monitoring or metrics agents. Immunity follows the whole cgroup subtree beneath the unit you name — every child process inherits it, resolved once at start.

How you add one. VIP is keyed by the systemd unit (its cgroup), not by process name — a renamed or forked binary cannot inherit immunity it was not granted. You declare the units at install time or add them later from the operator console; the agent resolves each to its cgroup subtree on the next start. The list is small and stable by design: a handful of named services, not a wildcard.

Platform — for your engineers

Where the decision is made

Most tools observe an action and raise a ticket after it has completed. GhostShield answers while the action is still a request, so for the operations it governs the word is “denied” rather than “detected”.

  • Enforcement, not notification. A governed operation is refused while it is still being attempted — not written up once the implant is already resident.
  • No out-of-tree kernel module. Everything the agent runs in the kernel is checked by the kernel itself before it is allowed to run. That is a materially different risk profile from a third-party kernel driver, which the kernel accepts on trust.
  • Your CPU bill is not set by the attacker. The agent measures the behaviour of whoever is already inside the host. Flooding it from outside does not raise your costs.
  • Evidence you can hand to an auditor. Every event is one timestamped line on your own disk, sealed to the line before it. Deleting or editing history is detectable.
  • Fail-open under fault, immune where you declare it. When the engine is degraded or unavailable, policy lets the work through instead of blocking it: a fault in the security layer should not turn into downtime for the service it protects. The units you declare — sshd, the web tier, your container runtime — keep that immunity across everything running beneath them, so you keep a way into the host while you work an incident.
  • The dashboard does not weaken the engine. It is read-only by construction: it exposes no write path to the agent or to policy, so reviewing an incident does not change it.
Decide and enforce in the kernel

Execution, memory, file activity and outbound traffic are judged at the moment they are attempted.

Correlate and contain the agent

Scores behaviour across signals, freezes the threat and writes the forensic trail.

Report read-only

A local dashboard with no write path: it shows the incident, it does not change it.

Licensing & privacy

Licensed offline. No outbound calls.

Your servers do not need to reach us to stay protected, and we do not reach them. Licensing is verified on the host itself, which removes an outbound dependency from your security stack and keeps your incident data where it belongs — with you.

  • Works with no internet access. Licence checks are done entirely on the server, so an agent in an air-gapped or egress-restricted network is fully licensed and fully functional. There is no licence server that can go down and take your protection with it.
  • One licence, one server. Each licence is bound to the HWID it was issued for and will not activate on another machine. Your entitlement is exact, and so is your invoice.
  • Cryptographically signed, verify-only on the host. The agent ships with the public verification key and no signing key, so licence material recovered from a compromised server does not let an attacker issue entitlements — yours or anyone else’s.
  • No telemetry. We receive no infrastructure data, no file contents and no event stream. Every detection is a line on a disk you own.
  • Clean licensing: nothing renews by itself. There is no auto-renewal, no recurring charge and no card stored on our side. A term ends when it ends, and you buy the next one when you decide to — so there is nothing to cancel and no subscription that outlives your intention to use it.
  • Uninstall is yours to run. One command removes the agent, and it works after a subscription has lapsed. Removal does not depend on an active licence or on reaching us.
Signed by us verify-only agent

The agent verifies a licence. It holds no signing key and cannot issue one.

Bound to the server one per host

A licence issued for one machine will not activate on another.

Stored locally nothing about you

Plan and expiry sit on your disk. No personal or infrastructure data is kept.

Outbound calls none

No phone-home, no licence round-trip, no data leaving the host.

Visibility

Your own console, on your own server

Every decision the agent makes shows up where the incident happened — on the machine itself. No console to log into, no logs to ship, no third party holding your incident data. Each line answers what an incident review actually asks: who did it, what they touched, why it was stopped. We would rather show it to you than describe it.

Ask for a walkthrough

Why GhostShield?

Why choose GhostShield EDR?

Two numbers decide an EDR purchase: what it costs you every day it is installed, and what it saves you on the one day it matters.

Performance

A security agent sized for production hosts

File-scanning agents inspect artefacts after they land, can consume gigabytes of RAM and still miss anything that never writes to disk. GhostShield evaluates the operation instead of the file, so there is no scanning pass — and the capacity you bought stays with the workload you bought it for. Measured in production on AWS: the Ring 0 engine holds under 50 MB resident, roughly 2% of a 2 GB instance, at 0.0–0.5% CPU in ordinary operation.

Memory footprint of the whole service set — engine, console and licence services together — under normal operation on our reference host. The Ring 0 engine alone holds under 50 MB.

Cost & visibility

What one bad night costs

A single ransomware incident is measured in days of downtime, a recovery project, a disclosure obligation and, increasingly, a fine. For a small team it can be an existential event. GhostShield costs less per server than the bandwidth that server already uses.

  • Stay online: the contained process tree is frozen in place and stays inspectable, while your critical units keep their share of the machine.
  • Answer the auditor: a tamper-evident trail of what happened, in order, where a quiet edit does not go unnoticed.
  • Predictable billing: one flat rate per server. No tiers, no per-event charges, no surprises.
From $249/year per server →
Validation

Proven not to break the systems it protects

Every release passes an automated gate before it is ever packaged, and the engine is exercised on a live production host running real web services. The design principle is simple: judge what attackers do, without fighting the operating system. Routine OS activity passes untouched; enforcement is reserved for the real vectors — cross-process memory access, unauthorized execution, suspicious egress. And the record is honest: the trail states only what the kernel actually did. Below is what we measure on our reference host — resilience, not magic.

GhostShield’s network engines and I/O thresholds underwent exhaustive cloud calibration testing under real traffic, across different Kernel architectures (5.8+). This rigorous mathematical foundation delivers lethal threat containment with zero false-positives measured in production environments.

Automated release gate Regression

Hundreds of automated tests — 425, zero failures on the current release — must pass before a package is produced. The build and the tests run clean, or the release does not ship. Each package ships with a diagnostic report attesting its pillars and the eleven in-kernel programs it attached.

0 failures

Kernel-verified Ring 0 Unsafe code

Every in-kernel program is loaded and accepted by the operating system’s own safety verifier on the target kernel before a build is published. If a single program is refused, the release is blocked — the engine never ships partially attached or blind.

verifier-gated

Runs beside your stack Crash loops

Validated live next to Nginx and production web services: the host stayed online through arming and testing — no restarts, no crash loops, no legitimate service denied. The downloaded package is verified end-to-end by SHA-256.

no crash loops

JIT workloads keep serving False positives

Node.js, Nginx/OpenResty and other JIT-heavy engines allocate executable memory constantly. Under the behavioral engine they keep running: memory analysis is silent, and enforcement acts only on a suspicious outbound connection or an unauthorized execution — not on normal internal traffic.

JIT tolerant

Doesn’t fight the OS OS friction

The operating system reads process metadata constantly — a log daemon, a service manager, a status tool. That routine activity passes untouched. Judgment is reserved for actual cross-process memory access — the vector behind credential theft and code injection — and the line is drawn at the kernel’s own permission model, not a brittle binary allow-list.

low false-positive

Credential-dumping guard Memory theft

Reading another process’s memory — the classic path to stolen keys, tokens and passwords — is detected and, once armed, blocked, while ordinary tools that only read metadata keep working. Detection escalates on repetition, so a single stray access is contained without punishing a one-off.

memory-access aware

Signal over noise Alert fatigue

Routine execution telemetry is coalesced so real security events are never buried under it — the audit view surfaces actionable events first and accounts for the rest as a count. The complete record still lives on the tamper-evident trail on disk.

actionable first

Measures before it enforces Day-one outage

Installs in a 24-hour calibration window that observes without blocking, then arms automatically — no manual tuning. A false positive from your own stack surfaces during calibration, where it can be reviewed, before enforcement can take a process down.

calibration-first

Figures are measured on our reference host under our test conditions and describe engineering resilience, not a guarantee of outcome. No security control removes all risk; GhostShield is defense-in-depth, not a promise of invulnerability.

Not sure it fits your stack? When in doubt, talk to us before you deploy. Email our operations team for a pre-deployment review of your specific workload — and to request a supervised trial or a white-label evaluation build to test first, on your terms, before anything goes live.

Request an operations review
Plans & Pricing

One license per protected server

Prices in US dollars (USD), per server. Activate in minutes, with no lock-in contract and no deployment fee.

  1. 1 One command prints the server's HWID
  2. 2 You choose the plan
  3. 3 The license is issued and installation is unlocked

Before you buy, check your kernel 30 seconds

GhostShield needs Linux kernel 5.8 or newer. That is not a product setting: the engine's event channel is the BPF ring buffer, which was introduced in Linux 5.8. On an older kernel the agent does not run, and the installer stops before writing anything.

Run this on the server you want to protect:

uname -r; stat -fc %T /sys/fs/cgroup; ls /sys/kernel/btf/vmlinux

You want a kernel of 5.8 or higher, the word cgroup2fs, and the BTF file listed. That is the default on the generic cloud images of Ubuntu, Debian, RHEL and derivatives. Servers still on cgroup v1 can run the agent, but process-freeze containment is not available there — it depends on a control-group feature that exists only in cgroup v2.

First, get your Server HWID no download needed

Every GhostShield licence — free or paid — is bound to one machine, and the HWID is that machine's fingerprint. Run this on the Linux server you want to protect. It prints one line and changes nothing:

curl -sL https://bastioncyber.online/get-hwid.sh | sudo bash

→ 50a644b7d38340e1a5caab476cce7513

That is your HWID. Paste it into the plan you pick below. You do not need to download the package yet — the script installs nothing, contacts nothing and writes nothing. Read the script first if you would rather see it before running it. We would.

Start here

Free

$0/15 days

No credit card. No sales call.

The full engine, not a reduced demo build. One server, 15 days.

  • One Linux server per licence
  • 15 days, full engine — not a reduced build
  • No credit card required
  • Upgrade to any paid plan without reinstalling

Licence issued instantly from your HWID. Upgrade later without reinstalling.

Monthly

$29/month

Billed monthly

Ideal for stress testing and on-demand protection.

  • One Linux server per licence
  • Billed $29 every month, in USD
  • Does not auto-renew — buy a new licence when the term ends
  • 14-day compatibility guarantee — refunded if the engine cannot run on your kernel

Licence generated instantly from your HWID. Guided deployment: prepare the kernel, then install.

Subscribe Now
Save 9%

Quarterly

$79/quarter

Equals $26.33/month

Continuous protection for teams past the evaluation stage.

  • One Linux server per licence
  • Billed $79 every 3 months, in USD
  • Does not auto-renew — buy a new licence when the term ends
  • 14-day compatibility guarantee — refunded if the engine cannot run on your kernel

Licence generated instantly from your HWID. Guided deployment: prepare the kernel, then install.

Subscribe Now
Save 14%

Semi-Annual

$149/6 months

Equals $24.83/month

The balance point between commitment and savings.

  • One Linux server per licence
  • Billed $149 every 6 months, in USD
  • Does not auto-renew — buy a new licence when the term ends
  • 14-day compatibility guarantee — refunded if the engine cannot run on your kernel

Licence generated instantly from your HWID. Guided deployment: prepare the kernel, then install.

Subscribe Now
Best Value Save 28%

Annual

$249/year

Equals $20.75/month

The lowest per-server cost, billed once a year.

  • One Linux server per licence
  • Billed $249 every 12 months, in USD
  • Does not auto-renew — buy a new licence when the term ends
  • 14-day compatibility guarantee — refunded if the engine cannot run on your kernel

Licence generated instantly from your HWID. Guided deployment: prepare the kernel, then install.

Subscribe Now

Every plan, including the free trial, runs the full engine

Paid plans buy time, not features. There is no reduced tier, no per-event quota and no capability locked behind a higher plan.

Billing terms

  • Currency and scope. All prices are in US dollars (USD) and cover one server. A licence is bound to one machine’s HWID and will not activate on another.
  • Renewal. Licences do not renew automatically. There is no recurring charge and no stored payment mandate. When a term ends the licence simply expires; to continue, you buy a new licence here at the then-current price and generate the renewal JWT in the system with ghostshield renew, which extends the licence on that server for the new term.
  • Nothing to cancel. Because nothing renews on its own, letting a term end IS the cancellation. The term you already paid for runs to its end.
  • Refunds — read this before you buy. There is no change-of-mind refund: the licence is issued instantly and bound to your HWID, and the 15-day free trial exists so you can prove compatibility before paying. What we do offer is the 14-Day Compatibility Guarantee — if the eBPF engine cannot load, verify or attach on your kernel, distribution or infrastructure and we cannot make it work, you get your money back, provided you report it within 14 calendar days of the original purchase. It applies once, to the first purchase for a given server; a renewal purchase is a new term for a server you have already proven compatible, so it is not covered. Full conditions in the Refund Policy.
  • Global distribution. Orders are sold and processed by our authorized global distribution partner, which handles payment and is responsible for global tax collection and remittance. Applicable VAT or sales tax is calculated and shown at checkout, and your card statement will show the distribution partner rather than Bastion Cyber.
  • No lock-in. No deployment fee, no minimum term beyond the plan you pick, and no contract to sign. Full terms in the Terms of Service.

Transparency & Scope

GhostShield is deliberately one thing done properly: a behavioural endpoint agent for Linux servers. Here is what it is not, stated plainly, so it can sit correctly alongside what you already run.

  • Not a network firewall. We do not handle DDoS or volumetric floods — keep the edge protection you have. Our coverage begins the moment a threat reaches the operating system, which is precisely where edge protection stops.
  • Not a traditional antivirus. There is no scheduled disk scan and no signature database to fall behind. GhostShield evaluates what a program does, so behaviour first seen today is judged by the same rules as behaviour seen last year.
  • Not a promise of absolute security. GhostShield raises a Linux server to an enterprise level of protection and mitigates attacks while they are happening. It is not, and nothing on the market is, a guarantee of “100% security” against a dedicated, well-resourced attacker. What we sell is resilience, not magic: fewer ways in, far less room to move once inside, containment that buys your team the hours it needs, and an evidence trail that survives the incident. Anyone offering you certainty is selling you something else.
  • Not zero-touch: system preparation is required. GhostShield attaches through BPF LSM, which is enabled on the kernel command line, so the guided first step edits the boot configuration and reboots the server once, at a time you choose. On a kernel where it is already enabled, nothing is changed and no reboot happens. After that, upgrades and day-to-day operation need no restart. We say so here rather than after you have bought.