What are the core benefits of WithSecure Atlant?
Flexible management – Standalone, Policy Manager console, or container JSON configuration.
Two interfaces – REST API and ICAP connect applications, proxies, gateways.
Broad scanning – Detects malware in files, spam in emails, harmful URLs.
Linux native – Runs on major enterprise distributions or as container.
Isolated networks – Offline content packages supply engines and definition updates.
Important note – No endpoint agent; integration work is required.
Multi-engine scanning service – Several scanning engines plus Security Cloud reputation for files and URLs.
REST scanning API – Scans uploaded files, SHA-1 hashes, emails and URLs over HTTPS.
ICAP scanning service – Connects ICAP-capable proxies and gateways, returns HTML block pages to users.
URL classification – Categorises URLs and blocks forbidden content categories, including embedded links.
Three management options – Atlantctl command line, REST management API, or WithSecure Policy Manager.
Important – No endpoint agent, EDR, patch management or encryption management included.
WithSecure Atlant, formerly F-Secure Atlant, is a self-hosted scanning platform for Linux that your own applications, mail flows and web proxies call via REST API or ICAP to check files, URLs and emails. It runs standalone, centrally managed through WithSecure Policy Manager, or as a container configured with a single JSON file.
Safer upload portals – Scans customer uploads before they reach storage or colleagues.
Hash-only checks – Classifies files by SHA-1 without transferring full file contents.
Existing proxies reused – ICAP lets current web proxies add malware scanning without redesign.
Scale-out friendly – Policy Manager access tokens stay valid across instances behind load balancers.
Controlled product updates – Version pinning freezes the product while engines and definitions stay current.
VDI offload scanning – Replaces the Scanning and Reputation Server for WithSecure Virtual Security.
WithSecure Atlant fits organisations that run their own services where outside parties deliver content, such as customer upload portals, file transfer systems, mail flows or web proxies. The deciding factor is less the number of employees than whether someone can operate a Linux service and connect it to an application via API or ICAP.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | By sector |
| Security questionnaire from large customers | Occasional | Common | Standard |
| Linux and API integration skills | Often missing | Partial | ✓ |
| This product fits | With IT partner | ✓ | ✓ |
The revised Information Security Act obliges operators of critical infrastructure, for example in energy, healthcare, transport, telecommunications and public administration, to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Companies outside these sectors are usually not directly affected, but often receive comparable requirements as suppliers of such operators. WithSecure Atlant supports the detection side of this obligation: each scan returns a result with a named detection, and its logging can record the client IP address and selected request headers, which documents what was blocked, when and from which source. It does not detect attacks outside the content streams routed through it, does not reconstruct an incident timeline and does not create or submit reports to BACS. This information does not constitute legal advice; have your specific obligations checked by a qualified specialist.
No product makes a company compliant with the NIS 2 Directive, because the directive requires organisational risk management measures, not a specific tool. Among others, it names incident handling, business continuity, supply chain security, security in the acquisition, development and maintenance of systems, basic cyber hygiene, cryptography, access control and multi-factor authentication. WithSecure Atlant supports security in system development and operation by adding malware checks to upload and data pipelines, supports supply chain security by scanning files and emails delivered by partners, and provides detection logs as input for incident handling. Backup and business continuity, multi-factor authentication, access control, encryption, staff training and the reporting process itself are not covered and need separate measures.
Partly, and only for the content that flows through it. Atlant answers questions such as whether uploaded or received files are scanned for malware, whether web traffic and emails are filtered for harmful content and URLs, and whether detection definitions are kept up to date automatically, including in isolated networks. It does not answer questions about malware protection on every workstation and server, endpoint detection and response with monitoring, patch management, disk encryption, multi-factor authentication, backups or a documented incident response process. Because Atlant has no higher edition that adds these functions, the practical route is to combine it with WithSecure's endpoint protection and EDR offerings and keep the other controls in your existing tools.
WithSecure Atlant runs only on 64-bit Linux, namely RHEL, Rocky Linux, AlmaLinux, Oracle Linux, Debian, Ubuntu, SUSE Linux Enterprise Server and Amazon Linux, or as a container; there is no Windows installation. It is a building block, not a finished protection product: without an application, proxy or mail gateway that calls its REST API or ICAP interface, it protects nothing, and it provides no protection on workstations. The container variant has no management API and no Policy Manager integration, and its configuration cannot be changed once the container has started. The product needs a regular connection to WithSecure cloud services, and optional ICAP trickling passes parts of a file to the client before the scan is finished, which WithSecure itself advises balancing with additional endpoint protection. No region-limited features were identified.
Not by default for data files: uploading data files to Security Cloud is disabled unless you enable it, while anonymised metadata and, if advanced cloud analysis is requested, application files can be submitted. The use of online services can be switched off entirely in the configuration.
Yes, installation and updates on hosts without internet access are supported through content packages and update archives generated on a connected machine. Because the product still requires a regular connection to WithSecure cloud services, a permanently air-gapped operation is not a suitable use case.
Atlant extracts archives and scans each item individually, by default up to five nested levels. Encrypted or corrupted archives are flagged in the scan result, and the ICAP service can be set to block encrypted archives or archives that exceed the nesting limit.
Self-hosted engine that scans files, URLs and emails via REST API or ICAP. Runs on Linux or as a container. Suits teams able to integrate an API.
WithSecure Atlant, WithSecure, F-Secure Atlant, Atlant for Virtual Environments, malware scanning api, icap scanning server, content scanning, url classification, spam detection
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies