Design-partner program

Open

Early customers should be product-validation partners, not ordinary prospects.

Every autonomous agent should have an identity, an owner, a policy, an enforceable host boundary, and evidence that proves what happened. The program is published. Apply at /start/design-partner. No design partners are enrolled yet. The program rate is $600 per governed node per month for a limited term: Control on Linux you enroll, with Gate-on-prem for that host, plus Enterprise governance on that same protection. Hosted Gate at $499 per month is not added on top. Public list prices stay on /pricing.

Environments we want to learn from

This is a strategic mix so different failure modes show up. It is not a list of companies we already work with.

AI coding company

Shell access, source control, CI/CD, and credentials in the loop.

Robotics organization

A Linux planner or companion computer. Not physical safety control, motors, or the safety loop.

Regulated workflow

Legal, finance, or healthcare-adjacent work where evidence has to travel.

Agent platform or marketplace

Many agents, shared infrastructure, and policies that differ by tenant or team.

Internal enterprise automation

Long-running agents with SaaS and API access on hosts you own.

What we collect — and what we refuse

The result should become product input, public documentation, and eventually customer-approved case evidence. We do not collect prompts, completions, credentials, or unnecessary customer content.

  • Installation friction
  • Supported and unsupported traffic paths
  • False blocking and missed-path observations
  • Policy-authoring difficulty
  • Evidence usefulness
  • Rollback confidence
  • Operator time
  • Buyer objections
  • Security-review questions
  • Time from installation to first useful proof

How intake works

  1. 1. You apply. Complete the design-partner application. Tell us the environment type, the Linux you control, how many nodes you can enroll, and what new operational data you will return. Vantio does not receive SSH. We do not collect prompts, completions, or credentials.
  2. 2. We review by hand. If your environment type is already covered, the application waits. We may decline when the host, the path, or the data offer is not a fit.
  3. 3. You keep the keys. Install from the public manual and the customer package. Preview policy. Turn enforcement on deliberately. Export evidence you own. Test rollback. Remove cleanly.
  4. 4. Friction comes back as product. Use the collection fields above. Anonymized architecture narrative is enough unless you later approve a named story.