Live watch on supported agent traffic
- Optics
- Yes — report only
- Phantom Engine
- Yes
- Enterprise
- Yes
Architecture · Observe · Enforce · Control
Vantio separates the autonomous workload from the authority boundary that governs it. The workload can reason, plan, use tools, and create processes. The organization defines the authority it receives.
Phantom Engine applies that authority across supported application and host paths on enrolled Linux infrastructure. Vantio Enterprise governs who may define, approve, delegate, change, and revoke it.
The Vantio control architecture
Observe, Enforce, and Control operate together as Phantom Engine. They are not separate products.
Topology
Govern
Vantio Enterprise
Ownership, delegated authority, approvals, dual control, exceptions, and durable evidence.
Observe · Enforce · Control
Phantom Engine
One product. Observe, Enforce, and Control on enrolled Linux infrastructure.
Host
Enrolled Linux host
The machines you enroll. Exact coverage is documented for that deployment.
Optics
Optics is Vantio’s free observability product for teams beginning to understand autonomous-agent activity. It shows where supported agents connect and provides process and trace context without storing prompts or completions.
Continuous Assurance
Verifies control state across the chain. Reconciles evidence and keeps known gaps visible. It is a platform capability across the products, not another commercial product.
Vantio’s target architecture distinguishes workload identity from workload integrity. A credential, process name, or familiar network location should not automatically prove that the running workload is still the version the organization approved.
An autonomous workload may combine permitted reads, writes, tool calls, and external actions into a sequence the organization did not authorize.
Vantio’s target architecture includes sequential and aggregate authority so limits can apply across a workload, lineage, tenant, fleet, destination, credential, or time window.
Missing identity, unavailable authorization, stale policy, unsupported coverage, and incomplete evidence must produce explicit states. They must not silently become successful enforcement or verified protection.
For engineers
Data and privacy
Recorded
Never retained
Coverage and limitations
Prices live on Pricing. Path status lives on Compatibility.
| Capability | Optics | Phantom Engine | Enterprise |
|---|---|---|---|
| Live watch on supported agent traffic | Yes — report only | Yes | Yes |
| Action labels | OBSERVED | ALLOWED / BLOCKED / REDACTED + named coverage gap | Same + reviewable evidence |
| Policy as code · preview → enforce | — | Yes | Yes |
| Enforce on the agent path | — | Destination, sensitive-data, and spending policies | Yes |
| Runtime protection on machines you own | — | Yes | Governance on Phantom Engine |
| Bypass indication on enrolled hosts | — | Correlates app-path decisions with host events | Same + durable correlated evidence |
| Durable evidence · audit records · dual-control | — | — | Yes |