Now with Shadow IT Detection

Control your browsers.
Protect your org.

Fantomo deploys silently in the background and lets you block sites, deliver contextual policy messages, and detect unauthorized SaaS signups — without touching user productivity.

2 Million Domains Pre-Categorized
<50ms Rule Matching Latency
Zero End-User Configuration

Built for enterprise IT teams managing Chrome & Edge

Manifest V3 Automated Deployment Shadow DOM Isolation Row-Level Security SOC 2 Architecture

Everything you need to manage
browser-level policy

From blocking unauthorized tools to detecting Shadow IT, Fantomo gives your IT team complete visibility and control.

Business View Take a Deeper Look

Intelligent Rule Engine

Keep your team safe on the web by directing traffic to approved tools. Block unproductive sites and guide users to corporate-sanctioned alternatives instantly.

Intelligent Rule Engine

Match by exact domain, URL fragment, domain pack, or AI-powered classification. Priority-sorted, frequency-controlled, with group, OU, and user-level exclusions.

Explore the Engine →

Silent Deployment

Deploy across all company computers automatically without interrupting your staff. No user sign-in or manual setup required.

Silent MDM Deployment

Deploy via Microsoft Intune, Jamf Pro, or any MDM. Auto-provisions users from active browser profile data. Fully invisible to the end user.

View MDM Configs →

Shadow IT Detection

Discover SaaS applications in use. Monitor signup behaviors, manage software compliance, and aggregate usage scoped by Google Workspace OUs and Groups.

Shadow IT Detection

Automatically detect SaaS account creation. Segment telemetry and SaaS usage by Google Workspace Organizational Units, Google Groups, and O365 equivalents.

Discover SaaS →

Real-Time Guidance

Guide employee behavior with custom alerts that pop up in the browser, helping them use corporate tools correctly.

Real-Time Guidance

Show policy messages right where users need them. Dismissable, non-dismissable, or full block — with custom styling and translated messages.

See Warning Flow →

Privacy-First Analytics

Monitor company-wide software adoption and security compliance while protecting individual user privacy.

Privacy-First Analytics

Our agent-based architecture ensures that SaaS usage is monitored, not the staff. No full URLs, document titles, or screenshots are ever logged.

Compliance Reports →

Automated Response Playbooks

Orchestrate multi-step response workflows automatically. Set triggers for new signups, breaches, or anomalies, and execute custom Slack alerts, emails, or access revocation.

SOAR Response Engine

Define sequences of checks and actions. Automatically request user justifications, set cooldown periods, escalate non-responses to admins, and synchronize default policies across all tenants.

Read Playbooks Guide →

Three steps to full
browser governance

Simple Steps Take a Deeper Look
01

Define Policies

Set guidelines for what websites and software tools your organization should use, directing employees away from risky sites.

Define actions (block, redirect, warn, or inform) by exact domain, URL patterns, or categories. Set rule priority and display frequency control.

02

Automate Installation

Install the software instantly on all employee computers in the background, with zero interruption or setup required from them.

Push the extension silently via Intune, Jamf, or GPO. Auto-configures using browser managed storage policies and immediately pulls active rules.

03

Gain Visibility

View which software is being adopted across your team, discover shadow IT, and protect company and staff data privacy.

Track SaaS signup forms, trigger real-time alerts (including Slack integration), and review compliance logs isolated with Postgres Row-Level Security.

Simple, usage-based pricing —
start free

15 seats always free. Only pay for users who were active last month. No contracts, no surprises.

Volume Discounts
16–50 users $4/user/mo
51–100 users $3/user/mo
101–200 users $2/user/mo
200+ users Contact us

Are you a non-profit? Learn about our non-profit program →

Frequently asked questions

How does the extension get deployed?

The extension is deployed silently via your MDM (Intune, Jamf, etc.) using managed storage policies. End users never see a login prompt or configuration step.

Can users disable or remove the extension?

When deployed via MDM with force-install policies, users cannot disable, remove, or modify the extension. This is a standard Chrome/Edge enterprise capability.

What browsers are supported?

Fantomo supports Chrome and Edge (Chromium-based). Both browsers support Manifest V3 extensions with managed storage for enterprise deployment.

How does Shadow IT detection work?

The extension uses multilingual URL pattern matching to detect when users visit signup, registration, or account creation pages at SaaS providers. Detections are logged and can trigger Slack alerts.

Can I use domain packs without creating individual rules?

Yes. Domain packs (e.g., "Social Media", "AI Tools") contain curated lists of 20-30+ domains. Create one rule targeting a pack to apply policy to all domains in that category.

Is my data secure?

All data is encrypted in transit (TLS 1.3) and at rest. We use PostgreSQL Row-Level Security to ensure strict tenant isolation. Audit data retention is configurable per organization.

What is the Tenant Security Tune-up add-on?

The M365 & GWS Security Tune-up add-on ($49/month) allows you to audit and remediate cloud tenant security settings. Automated remediation runs using Just-in-Time (JIT) memory-only credentials that self-destruct 15 minutes after completion, and daily compliance scans audit settings for configuration drift, raising Slack alerts and ITSM tickets if settings are modified outside of Fantomo.

What is included in the Full Browsing & Analytics add-on?

Available for $119/month, the Full Browsing & Analytics add-on provides complete browsing analytics with domain categorization, visit frequency tracking, and daily metric rollups. It includes Shadow IT & SaaS Management. Data retention is configurable.

When does billing start?

Billing only activates when more than 15 users are active in a calendar month. If your team never exceeds 15 active users in a given month, that month is free. We recommend adding a payment method before you hit 15 so there's no interruption as you grow.

What counts as an active user?

A user is counted as active if their extension synced with Fantomo at least once during the prior calendar month. Users who are enrolled but haven't opened their browser that month don't count.

What if our team shrinks?

Billing adjusts automatically every month based on who was actually active. If headcount drops, your bill drops too — you never pay for inactive users.

Are there contracts or commitments?

No contracts. Fantomo is month-to-month and you can cancel at any time. For teams over 200 users, we offer negotiated annual pricing — contact us to discuss.

Ready to take control of your browsers?

Start with a free account. No credit card required. Deploy in under 10 minutes.