Skip to content

Architecture · Observe · Enforce · Control

Authority below the agent.

Vantio separates the autonomous workload from the authority boundary that governs it. The workload can reason, plan, use tools, and create processes. The organization defines the authority it receives.

Phantom Engine applies that authority across supported application and host paths on enrolled Linux infrastructure. Vantio Enterprise governs who may define, approve, delegate, change, and revoke it.

Where each layer sits

The Vantio control architecture

Observe, Enforce, and Control operate together as Phantom Engine. They are not separate products.

Topology

  1. Govern

    Vantio Enterprise

    Ownership, delegated authority, approvals, dual control, exceptions, and durable evidence.

  2. Observe · Enforce · Control

    Phantom Engine

    One product. Observe, Enforce, and Control on enrolled Linux infrastructure.

  3. Host

    Enrolled Linux host

    The machines you enroll. Exact coverage is documented for that deployment.

Optics

Optics is Vantio’s free observability product for teams beginning to understand autonomous-agent activity. It shows where supported agents connect and provides process and trace context without storing prompts or completions.

Continuous Assurance

Verifies control state across the chain. Reconciles evidence and keeps known gaps visible. It is a platform capability across the products, not another commercial product.

A valid credential is not always a valid workload.

Vantio’s target architecture distinguishes workload identity from workload integrity. A credential, process name, or familiar network location should not automatically prove that the running workload is still the version the organization approved.

Individually allowed actions can still create an unauthorized outcome.

An autonomous workload may combine permitted reads, writes, tool calls, and external actions into a sequence the organization did not authorize.

Vantio’s target architecture includes sequential and aggregate authority so limits can apply across a workload, lineage, tenant, fleet, destination, credential, or time window.

Unknown must not become allowed by accident.

Missing identity, unavailable authorization, stale policy, unsupported coverage, and incomplete evidence must produce explicit states. They must not silently become successful enforcement or verified protection.

For engineers

The mechanisms behind it

eBPF
Extended Berkeley Packet Filter: a Linux kernel mechanism Phantom Engine uses to observe and constrain process, filesystem, and network activity on enrolled hosts.
LSM
Linux Security Module: kernel hooks that can allow or refuse operations according to policy on the enrolled host.
Enforcement daemon
The Phantom Engine process that runs on each enrolled Linux host and applies host-level authority.
Process inheritance
Child processes keep the parent’s enforcement identity, so creating a subprocess is not a way around the boundary.
Trace correlation
Matching application-path records with host events so an unrecorded path can be named.
Explicit unknown
The state emitted when host activity has no matching application-path record. Unknown is reported as unknown.

Data and privacy

What Vantio records — and what it refuses to keep.

Recorded

  • DestinationWhere the workload tried to connect
  • Process contextWhat ran, under what identity
  • Volume and timingHow much moved, and when
  • DecisionObserved, allowed, denied, or an explicitly named gap
  • TraceEnough to match events across layers

Never retained

  • PromptsUser and system instructions stay out
  • CompletionsModel output is not stored in Vantio’s records
  • Tool payloads as chatThere is no conversation warehouse to breach
  • Customer secrets by designRedaction is an enforcement action, not a retention strategy

Coverage and limitations

What each product provides

Prices live on Pricing. Path status lives on Compatibility.

Live watch on supported agent traffic

Optics
Yes — report only
Phantom Engine
Yes
Enterprise
Yes

Action labels

Optics
OBSERVED
Phantom Engine
ALLOWED / BLOCKED / REDACTED + named coverage gap
Enterprise
Same + reviewable evidence

Policy as code · preview → enforce

Optics
—
Phantom Engine
Yes
Enterprise
Yes

Enforce on the agent path

Optics
—
Phantom Engine
Destination, sensitive-data, and spending policies
Enterprise
Yes

Runtime protection on machines you own

Optics
—
Phantom Engine
Yes
Enterprise
Governance on Phantom Engine

Bypass indication on enrolled hosts

Optics
—
Phantom Engine
Correlates app-path decisions with host events
Enterprise
Same + durable correlated evidence

Durable evidence · audit records · dual-control

Optics
—
Phantom Engine
—
Enterprise
Yes