Compliance
Evidence your security, risk, and compliance teams can review.
Enterprise adds durable, correlated evidence, audit records, and dual-control workflows on top of Phantom Engine. It helps teams show how agent controls were configured, applied, and reviewed. Formal certifications and authorizations remain separate programs. Framework-by-framework status lives below.
Where we stand on frameworks
We keep our framework status simple. When you see ready_for_assessment, it means our product evidence is ready for your auditor to review. If you see blocked_on, it means we are still working through an open program or authorization step.
- ready_for_assessment
- We have the product evidence and mapping you need for an auditor gap assessment. We do not hold the certificate yet.
- blocked_on
- We are still working through an open program or verification step. We do not hold this credential today.
| Framework | Status | What that means |
|---|---|---|
| ISO/IEC 42001 | ready_for_assessment | We map AI management themes directly to live evidence. We do not hold the certificate yet. |
| EU AI Act | ready_for_assessment | We provide the oversight and transparency evidence you need for a gap assessment. We do not hold conformity yet. |
| GDPR | ready_for_assessment | Optics never stores prompts or completions. This helps your data minimization goals, though we do not provide legal counsel. |
| SOC 2 | ready_for_assessment | We have the Trust Services control evidence you need to start an assessment. We do not have a Type II report yet. |
| NIST AI RMF | ready_for_assessment | We map product controls directly to the core NIST functions. Formal conformity is still an open program. |
| SLSA | blocked_on | Our supply-chain provenance program is still open. We are not SLSA verified. |
| FedRAMP | blocked_on | We have not started this sponsored authorization program. We are not FedRAMP Authorized. |
| StateRAMP | blocked_on | We are tracking the FedRAMP path for this. We are not authorized today. |
| CMMC | blocked_on | We will enter this defense-contractor path when the market opens. We are not certified. |
Frequently asked
- Does Vantio hold any certifications today?
- Not yet. We built our product controls to map perfectly to common assessment frameworks. Being ready for an assessment is different from holding the actual certificate. We will let you know as soon as we finish these programs.
- Is Vantio SOC 2 certified?
- Not yet. We generate the exact control evidence you need to start a SOC 2 assessment. Securing the Type II report requires a CPA engagement, which we are still working through.
- Is Vantio ISO/IEC 42001 certified?
- Not yet. We give you live evidence mapped to AI management themes so you can run a gap assessment. Getting the formal ISO/IEC 42001 certification is still on our roadmap.
- Is Vantio FedRAMP Authorized or StateRAMP Authorized?
- No. We have not entered these sponsored authorization programs yet.
- Does Vantio store AI agent prompts or completions?
- No. Vantio Optics only records connection facts like where the agent went, which process it used, and how much data it sent. We never store prompts or completions.
- Can I buy Phantom Engine as a multi-tenant cloud SaaS?
- No. You run Phantom Engine directly on your own on-prem machines or inside your VPC. We do not offer it as a multi-tenant cloud service.
Let's talk about your compliance goals
Enterprise is optional governance on Phantom Engine — talk to sales. If you want to know exactly how our evidence maps to the framework you care about, just reach out. If you only need a quick answer, our Support page is the best place to start.