Skip to content

Customer install manual

Install, watch, preview, prove, roll back, and leave — on Linux you enroll.

Optics gives teams a free view of supported AI-agent activity. Phantom Engine adds enforceable policy and host-level authority as one product. Vantio Enterprise adds organizational governance and evidence.

This path has passed internal rehearsal. External Stranger Host validation remains Open. A company-operated rehearsal is not a pass of the Standard. Phantom-Box is company-operated and ineligible. A host Vantio operates cannot close that walk.

Vantio does not need SSH on your host. If a step is missing from this page or the customer package, that is a product gap — not a reason for an undocumented login. To pick Optics, Phantom Engine, Enterprise, or the design-partner application, start at /start.

What you are installing

Supported paths only. Phantom Engine Control is enrolled Linux. Named gaps stay named. Do not generate fake traffic to look live. Honest idle is valid. Phantom Engine: Contact Vantio. Vantio Enterprise: Contact Vantio. Details live on Pricing.

What you need

  • Linux with sudo for the loader. Windows and macOS Control are not offered.
  • Helm 3 if you use Kubernetes. You bring Helm. Chart default is observe-only (`enforce: false`).
  • Optics CLI on PATH (`npm i -g @vantio/cli`). Python agents: Python support requires vantio-agent-sdk. Follow the current Python SDK example and verify that a supported outbound event appears before relying on the coverage state.
  • A policy key on this host (`VANTIO_API_KEY`) when you turn Enforce on. Contact Vantio for a key.

Optics — observe, free

Install the CLI, wrap the process you already run, and confirm an OBSERVED record — or honest idle if the agent never called a supported host. Attached, idle, outside the wrap, and degraded observation are named. No account required. Prompts and completions stay out. Optics does not invent traffic.

npm i -g @vantio/cli
vantio run --summary node agent.js
vantio prove --list
vantio prove
vantio discover --local

Python support requires vantio-agent-sdk. Follow the current Python SDK example and verify that a supported outbound event appears before relying on the coverage state.

pip install vantio-agent-sdk
vantio run python agent.py

Optics — leave

Stop wrapping the process, then uninstall the CLI or SDK. Honest idle while Optics is installed is valid — a wrap with no OBSERVED line means the agent never called a supported host, not that the product failed. After uninstall, the wrap is gone. Local ~/.vantio/runs is metadata you own, not a prompt warehouse.

# Stop the wrap — run the agent the way you did before vantio run.
node agent.js

# Optional: delete local wrap logs (hosts and sizes, not prompts)
rm -rf ~/.vantio/runs

npm uninstall -g @vantio/cli
pip uninstall vantio-agent-sdk

Phantom Engine — Enforce plane

Gate is not a current SKU. Enforce is a technical plane inside Phantom Engine. Contact Vantio at hello@vantio.ai. After you have a key, vantio login, preview policy on live traffic, then turn enforcement on for one path you marked.

vantio login <key>
# Preview first, then enforce on a path you chose.
vantio run --summary node agent.js

Path A — Helm (Kubernetes)

Observe-only first. Pin image.tag in your values. Do not ship latest as a surprise. Annotate a workload with vantio.ai/enroll: "true" when you are ready. Nothing else is watched unless you opt it in.

# Observe-only first. Pin image.tag in your values. Do not ship latest as a surprise.
helm upgrade --install vantio-phantom-engine ./vantio-phantom-engine/deploy/helm \
  -f your-values.yaml

# Enforce-plane on-prem is included in the Phantom Engine purchase.
bash scripts/pe_customer_pack_gate_onprem.sh
bash scripts/pe_customer_pack_healthcheck.sh

Path B — Phantom Engine (protect a host you own)

Optics is the free way to see what your agents do. Phantom Engine is the paid step: it enforces and controls agent activity on a Linux host you own, as one node subscription.

Phantom Engine is not an unattended download today. You get a guided install: a short onboarding with our team, the pinned Phantom Engine customer pack (Optics + Phantom Engine only), and a fail-closed health check before enforcement is turned on. You watch first in observe mode, then a person on your side flips enforcement on. Rollback and clean removal are included and documented. Enterprise Governance is an add-on when you need proof and process on top. To start, request access at hello@vantio.ai and we'll provision your pack.

See what is attached

No attached agents is honest idle. Agents running — not on Optics / Phantom Engine is a named gap (outside the wrap). Unknown does not become green. Incomplete observation is named degraded.

python3 scripts/vantio_assure.py attach-health
python3 scripts/vantio_assure.py planes
vantio discover --local

Preview policy, then enforce on purpose

Set dry_run: false and enforce: true only after you have watched preview decisions on a path you marked. Helm Control stays enforce: false until you flip it with a values change you own. A misspelled field is not a live rule.

# No write:
python3 scripts/policy_push.py --check policies/policy.preview.example.yaml

# Preview on the live enforce plane (dry_run true). You choose when to write:
python3 scripts/policy_push.py --strict policies/policy.preview.example.yaml

# Confirm:
curl -sS -H "x-vantio-identity: $VANTIO_API_KEY" http://127.0.0.1:5001/api/v1/config
curl -sS -H "x-vantio-identity: $VANTIO_API_KEY" \
  "http://127.0.0.1:5001/api/v1/residual-risk?demo=false"
python3 scripts/policy_push.py --check --strict policies/policy.malformed.example.yaml
# expect POLICY_PUSH_STRICT_FAIL
  • Stale policy: if the control plane you poll is unreachable, do not assume the last good rule is still protecting you. Healthcheck must fail closed.
  • Malformed policy: ignored field names come back on the write. `--strict` refuses a green CI on a typo.
  • Network loss: do not invent ledger rows. Named degraded evidence is valid.

Evidence you keep

Packaged evidence can be older than the live enforce ledger. That is a named gap, not a reason to generate traffic. Customer copy says Control.

python3 scripts/vantio_assure.py production-check
python3 scripts/vantio_assure.py drill absolute    # Control prove; customer copy says Control
python3 scripts/vantio_assure.py compliance-export
python3 scripts/vantio_assure.py stranger-host     # SH-01..SH-20; does not mark the Standard passed by itself

Rollback

Saves current enforce-plane config, returns it to dry_run=true / enforce=false, and sets Helm enforce=false if that release exists. Phantom Engine protection stays on. The script refuses to run on company-operated Vantio hosts.

bash scripts/customer_pack_rollback.sh

Uninstall

Helm uninstall, stop the on-prem enforce daemon, stop vantio-loader if you installed the unit. Evidence folders stay. The script refuses company-operated Vantio hosts. After removal, confirm the enforce /health is gone and pgrep vantio-loader is empty. On your host, you own disable.

bash scripts/customer_pack_uninstall.sh          # prints the plan
bash scripts/customer_pack_uninstall.sh --yes    # actually removes

One-command walk

Non-destructive on an ordinary customer install. The ATTEST line is only for an external acceptance run.

bash scripts/customer_pack_walk.sh
# On a host Vantio does not operate, after you attest that fact:
ATTEST_STRANGER_HOST=1 bash scripts/customer_pack_walk.sh

ATTEST_STRANGER_HOST=1 records that the operator attested an external acceptance run. It does not by itself prove independence. Company-operated Vantio hosts refuse that attestation.

Ordinary install versus the external acceptance test

This page is the customer install. You wrap Optics, enroll Linux for Phantom Engine, watch honest idle or a named gap, preview policy, turn enforcement on on purpose, keep evidence, roll back, and uninstall.

The Stranger Host Standard is a separate external acceptance test (Open). It is not a product roadmap. A pass counts only on infrastructure Vantio does not operate, with no Vantio SSH. Company-operated hosts are ineligible.

python3 scripts/vantio_assure.py stranger-host --prove          # fixture
python3 scripts/vantio_assure.py stranger-host --mode internal  # this company host
python3 scripts/vantio_assure.py stranger-host --mode stranger --attest-stranger-host