01
Protection without conversation retention
Security should not require a chat archive. We record connection and decision facts so you stay in control without storing prompts or completions.
Vantio · Architecture
This page is the map: how visibility, policy on the wrap, and a host stop fit together, plus named workflows, Continuous Assurance, evidence, and where each piece actually deploys. Continuous Assurance keeps Optics, Gate, and Phantom Engine true after install: it detects drift, heals what it can, and exports evidence. It is how the suite stays healthy — not a fourth product you buy.
Where each layer sits
Optics and Gate ride the agent path — Sight Loop, then rules that stick. Phantom Engine protects machines you own: host-level control when the app layer never records the call. Phantom Engine →
Control topology
Agent → Vantio → Destinations
Your stack
Vantio planes
01 · Observe
Optics
Sight Loop
The watch. Destination, process, volume, timing, and trace — reported live. Never steers. Never blocks. Never stores the chat.
02 · Enforce
Gate
Rules that stick
Policy on the same path. When a line is crossed, Gate can block the request, redact PII, or enforce a spend limit. No mandatory proxy hop.
03 · Control
Phantom Engine
Rogue Reconciliation
Host stop on Linux you enroll. Rogue Reconciliation names the gap when the host sees traffic with no app record. Runs on your hosts — on-prem or VPC.
Destinations
Already on the wrap
Optics records egress telemetry to these model APIs without keeping the conversation. Gate can block a destination, redact PII, or enforce a spend limit on the wrap. Phantom Engine is runtime enforcement on Linux you enroll.
Model APIs
Agent runtimes
Hosts you own
Named workflows
Optics
Sight Loop is how Optics works day to day: wrap the agent process, watch outbound connections, report where they went and how much moved, and show you what still sits outside that watch without stopping anything.
Optics →Gate
Gate’s enforce cycle finds where agents connect, writes policy as code (destination allowlists, PII redaction, spend limits), keeps that policy in Git so CI can push it to Gate in one step, previews decisions on live traffic, then turns enforcement on so Gate only acts when a line is crossed — no one has to monitor every session.
Gate →Phantom Engine
Rogue Reconciliation compares what Optics saw, what Gate decided, and what Phantom Engine saw on the host, and names the gap when the host sees traffic with no matching app-layer record.
Phantom Engine →Platform layer
Continuous Assurance keeps Optics, Gate, and Phantom Engine true after install: it detects drift, heals what it can, checks posture, and exports evidence while production agents keep working. Depth grows with what you buy: Optics checks Sight Loop; Gate adds enforce checks and evidence; Phantom Engine adds Rogue Reconciliation and full three-layer assurance.
Design vows
01
Security should not require a chat archive. We record connection and decision facts so you stay in control without storing prompts or completions.
02
Rebuilding the network just to get teeth is a non-starter. Enforcement attaches where agents already run — no forced middlebox to operate or fail.
03
App-layer tools can be skipped. We show where coverage ends, then close those paths under control when rogue agents are unacceptable.
04
Start with Observe, add Enforce, then Control — same shape, more protection. Continuous Assurance deepens with each layer.
Trust boundary
Recorded
Never retained
Why this shape
Common pattern
Chat-logging “governance”
Vantio
Egress telemetry + policy decisions only
You get an audit trail without turning every agent session into a liability archive. The trade: you cannot replay the prompt from Optics.
Common pattern
Mandatory outbound proxy
Vantio
Rules where the agent runs
On Node, fetch, undici, http/https, http2, net/tls, WebSocket, and spawned curl or wget share one wrap — no new hop to certificate-pin. Browser paths stay outside this wrap; Phantom Engine on Linux you enroll closes paths that never load it.
Common pattern
Hope the wrap is always on
Vantio
Independent control on enrolled hosts
When app controls miss a path, Phantom Engine still matches host evidence and names that gap. The trade: that control is customer-hosted Linux on machines you enroll.
Definitions
Capability reference
Optics free, Gate $499, Phantom Engine $799 per node.
| Capability | Optics | Gate | Phantom Engine |
|---|---|---|---|
| Live watch on agent / LLM outbound traffic | Yes — report only | Yes | Yes |
| Prompt & completion capture | Never | Never | Never |
| Action labels | OBSERVED | ALLOWED / BLOCKED / REDACTED | ALLOWED / BLOCKED + named coverage gap |
| Policy as code · preview → enforce | — | Yes | Yes (suite) |
| Enforce on the agent path | — | Block, redact PII, or enforce spend limits | Yes (on-prem Gate) |
| Runtime protection on machines you own | — | — | Yes — $799 / node |
| Rogue Reconciliation | — | Report names gaps Gate cannot see | Gap named + ledger |
| Multi-tenant cloud control plane | — | — | Not offered today |
Next step
Optics is free. Gate when a line must be enforced. Phantom Engine when the wrap never loaded and the Linux host still has to say no.