| Node on macOS, Linux, or Windows WSL — vantio run | Optics | Supported | npm i -g @vantio/cli, then vantio run --summary node agent.js | Browser paths stay outside this wrap. Raw sockets that never enter the wrap are not recorded. |
| Python — vantio-agent-sdk | Optics | Supported | pip install vantio-agent-sdk, then follow the current Python SDK example | Do not rely on coverage until a supported outbound event appears. Browser paths stay outside this wrap. |
| Optics MCP — read-only inspect | Optics | Supported | npx -y @vantio/optics-mcp in a local MCP client | Observe-only. Not a tool-call gateway and not enforce-plane policy. |
| Phantom Engine Enforce plane on the same wrap | Phantom Engine | Supported | Contact Vantio at hello@vantio.ai. After you have a key, vantio login, then vantio run. | Application-path enforcement cannot act on traffic that never entered the wrap. Browser and Chromium paths stay outside. Public card checkout is not live. Gate is not a current SKU. Enforce is a technical plane inside Phantom Engine. |
| Enforce plane on a Phantom Engine node | Phantom Engine | Proven in Vantio testing | Customer package on Linux you enroll. Enforce on that node is included in the Phantom Engine purchase. | Proven in Vantio testing on a company-operated host. A completed Stranger Host Standard pass has not been recorded. |
| Phantom Engine Linux daemon — bare metal or VM | Phantom Engine | Proven in Vantio testing | Customer package / Linux daemon on a host you enroll. Contact Vantio. | Linux you enroll only. Not Windows or macOS Control. Proven in Vantio testing — not yet a recorded stranger-host pass. |
| Phantom Engine Kubernetes DaemonSet (Helm) | Phantom Engine | Proven in Vantio testing | Helm 3 on a cluster you operate, Control chart plus on-prem enforce companion. You bring Helm. | Multi-pod auto-attach across every cluster pattern is still open. Stranger-host pass is Open. You bring Helm 3. |
| Enterprise evidence, audit, dual-control | Enterprise | Proven in Vantio testing | Same Phantom Engine install, governance depth on that node. Contact Vantio. | Formal certifications are not held. A completed Stranger Host Standard pass has not been recorded. |
| Browser, Chromium, or headless CDP traffic | Suite | Not supported / not yet tested | Not on the Optics wrap. | Named residual. Do not treat a browser path as application-path enforcement coverage. |
| Windows or macOS Phantom Engine Control | Phantom Engine | Not supported / not yet tested | Not offered. Optics can still wrap on those OSes. | Control is Linux you enroll. |
| Microsoft Entra, Okta, or CyberArk identity consumed by Phantom Engine | Suite | Not supported / not yet tested | Not offered as a product path today. Identity systems say who; Vantio enforces where the agent runs. | Vantio does not replace Entra, Okta, or CyberArk. Mapping, owner, short-lived credentials, and identity-linked evidence are named gaps. |
| Allow / deny / redact on MCP tool calls | Phantom Engine | Not supported / not yet tested | Not offered as a product path today. Optics MCP is read-only inspect. | This is not a standalone MCP gateway product. Host Control remains the backstop. |
| Design-partner validation on a customer-controlled host | Suite | Design-partner validation | Design-partner program at /docs/design-partners. No partners are enrolled yet. | Strategic recommendation only. This row is empty until a partner completes the standard. |