Gate · Enforce · $499 / month
Rules that act. Gaps that stay visible.
Map supported agent and LLM traffic observed through enrolled Gate paths. Gate previews and enforces destination, redaction, size, and spend rules on the wrap you already run.
Three outcomes
- Enforce close to the running agent.
- Preview policy before turning it on.
- Keep a decision record you can review.
How it works
You write policy as code — destination allowlists, selected field redaction, and spend limits — keep it in Git, and let CI push it to Gate. Preview decisions on live traffic, then turn enforcement on so Gate acts when a line is crossed. Configured spend limits on that wrap stop a stuck loop from keeping the model call open. There is no mandatory outbound proxy; enforcement runs in the wrapped process.
The $499 product uses a Vantio-hosted control plane. You wrap the same agent process as Optics; policy, ingest, and the dashboard live with Vantio. On a Phantom Engine node, Gate runs on-prem inside that purchase.
What policy can do on the wrap
- Refuse a destination you have not allowed.
- Redact selected sensitive fields before they leave.
- Apply a configured size limit on the request.
- Apply a configured spend ceiling on that wrap.
- Dry-run those rules on live traffic before enforcement.
- Write the decision and residual-risk record to the enforce trail.
Data and privacy
Gate stores the policy decision and residual-risk record. It does not retain prompts or completions.
Coverage and limitations
Gate can only enforce traffic that enters a supported Gate path. Browser traffic, raw sockets, and processes that never load the wrap stay outside. Those gaps stay named. It is not a prompt-injection detector. Mapping Entra, Okta, or CyberArk identity into those decisions, and allowing or denying MCP tool calls, is not on the wrap today.
Gate is $499 per month after a 14-day trial. Gate trials are currently provisioned through the Vantio team.
Questions that add detail
- How do I know when Gate blocked something, stripped a field, or hit a spend limit?
- Every live decision is written to the enforce trail. Operators see it on the enforce view and the Approvals review list. You can set an optional webhook on the control plane. There is not a separate alert dashboard.
Next: Phantom Engine
When controls must continue after the wrap is skipped, Phantom Engine adds an independent host-control layer on enrolled Linux infrastructure and names the residual paths covered by the deployment.