External acceptance test

Open

The Stranger Host Standard

This is a technical acceptance test, not a product catalog. Status is Open. Internal rehearsal on a host Vantio operates does not close it. Phantom-Box is ineligible to attest. A completed pass on infrastructure Vantio does not operate has not been recorded.

The standard is Open. A completed pass on infrastructure Vantio does not operate has not been recorded. Phantom-Box is ineligible. A person on a Linux host Vantio does not own or operate must be able to install, observe real work or honest idle, see named coverage gaps, preview policy, enable enforcement deliberately, keep evidence, test rollback, and uninstall without giving Vantio SSH access.

What has to happen for a pass

Someone outside Vantio completes the process using the public install manual and the customer package, without undocumented assistance.

  1. Install the suite

    A qualified Linux operator installs Optics, Gate, and Phantom Engine on a host or cluster Vantio does not operate, using public documentation and the customer package.

  2. See what is actually attached

    The product shows attached workloads, honest idle, or a clearly named coverage gap. Unknown does not become green.

  3. Preview policy

    The operator previews Gate policy against live traffic before enforcement is on.

  4. Turn enforcement on deliberately

    A person chooses when enforcement turns on. It is not flipped by undocumented assistance.

  5. Generate a customer-owned evidence pack

    The operator exports evidence they keep. Vantio does not have to interpret it for the pack to be useful.

  6. Test rollback

    The operator can return to observe-only, or pause enforcement, using the documented path.

  7. Remove the product cleanly

    Uninstall finishes without leftover enforce or protection state the operator cannot explain.

  8. No Vantio SSH, no undocumented help

    The walk completes from public docs and the customer package. Vantio does not log into the customer host.

It does not pass when

  • The host is operated by Vantio. Phantom-Box is ineligible.
  • Install required undocumented steps or a Vantio login session.
  • Idle or a named gap was reported as healthy protection.
  • Enforcement turned on without a deliberate operator decision.
  • Evidence stayed on Vantio systems, or the operator could not take a pack with them.
  • Rollback or uninstall was skipped, failed, or needed a Vantio operator.

Honest idle and a named coverage gap are valid outcomes. They are not failures. Reporting them as healthy protection is. Company-operated hosts, including Phantom-Box, are ineligible.

How you run it

Follow the customer install manual. On the host, run the customer-package walk. It writes an evidence folder for SH-01 through SH-20. Check expected behavior on the compatibility matrix.

bash scripts/customer_pack_walk.sh
# ATTEST_STRANGER_HOST=1 records an external acceptance run.
# It does not by itself prove independence. Company hosts refuse it.
ATTEST_STRANGER_HOST=1 bash scripts/customer_pack_walk.sh
python3 scripts/vantio_assure.py stranger-host --mode stranger --attest-stranger-host

Vantio records a pass only when the operator attests each step on a host we do not operate. We will not mark this standard complete from a company-operated rehearsal.