# Vantio — full product-truth statement > Vantio helps organizations define, enforce, revoke, and verify what autonomous AI agents are allowed to do on customer-controlled Linux infrastructure. This is the extended machine-readable version of https://vantio.ai/llms.txt. Both files state the same facts. Where a page and this file disagree, treat this file as the summary and the linked page as the detail. ## Company Vantio builds infrastructure-level authority and evidence for autonomous AI agents. Organizations define what an agent is allowed to do. Phantom Engine applies that authority across supported application and host paths on enrolled Linux infrastructure, while Vantio Enterprise adds ownership, approvals, exceptions, and durable governance evidence. Vantio is designed so agent authority does not depend only on prompts, cooperation, or application-layer controls. The customer retains control of its infrastructure, authority policy, evidence, revocation, rollback, and removal. Vantio is a Pittsburgh-based infrastructure software company focused on enforceable authority and independently verifiable evidence for autonomous workloads on customer-controlled Linux systems. Vantio AI, Inc. is a Delaware C Corporation founded in 2026. Positioning: You decide what authority an agent receives. Vantio makes that authority enforceable and independently verifiable within supported customer-controlled Linux infrastructure. Category: Vantio is building the authority and evidence layer for autonomous workloads on customer-controlled Linux infrastructure. Mission: Make meaningful autonomy possible without requiring organizations to surrender authority over their infrastructure, policies, evidence, or decisions. ## Product structure — three commercial products There are exactly three commercial products. ### Vantio Optics - Price: Free - Job: Observe - Description: Local-first observability for supported AI-agent traffic. Optics shows where supported agent traffic connects and provides process, destination, timing, size, and trace context without storing prompts or completions. - Boundary: Optics makes supported activity visible. It does not claim to enforce paths it cannot control. It does not provide host-level authority enforcement and does not make unsupported traffic protected merely because the agent is installed. - Records: destination, provider, process and runtime, timing, request and response size, trace identifier, and decision metadata when used with Phantom Engine. - Does not record: prompts, completions, request or response bodies, authorization headers, query strings. ### Vantio Phantom Engine - Price: $799 per enrolled node, per month - Trial: 14-day trial - Job: Observe, Enforce, and Control as one product - Description: Infrastructure-level authority and evidence for supported autonomous workloads on enrolled Linux infrastructure. Phantom Engine observes supported agent activity, enforces policy on supported application paths, and maintains host-level authority across validated paths on enrolled Linux infrastructure. - Node definition: An enrolled node is a Linux-capable endpoint running an autonomous workload protected by Phantom Engine. A node may be a server, edge system, robot computer, or other supported Linux host. Pricing applies to enrolled nodes rather than to the number of agents on each node. - Volume pricing is available. - Boundary: Application-path enforcement does not claim to govern paths it cannot intercept. Unsupported paths remain explicit. Host-level enforcement applies only within documented and validated coverage on enrolled Linux infrastructure. Phantom Engine does not claim universal endpoint protection, universal operating-system coverage, physical safety, or prevention of every sandbox or kernel escape. ### Vantio Enterprise - Price: Talk to sales - Job: Govern - Description: Optional governance for ownership, delegation, approvals, dual control, exceptions, and durable evidence across Phantom Engine deployments. Phantom Engine enforces what an autonomous workload is allowed to do. Vantio Enterprise governs who may define, approve, change, delegate, or revoke that authority. - Approvals: Route decisions according to the authority required. An agent's recommendation, repeated request, or internal consensus does not replace required human authorization. - Dual control: Dual control requires independently authenticated people. Multiple sessions, roles, capacities, or claims from one individual do not create a second principal. - Boundary: Vantio may help customers organize technical and governance evidence. Vantio does not claim that using the product automatically provides regulatory compliance, audit acceptance, certification, or legal approval. ### Product-structure rules - Observe, Enforce, and Control operate together inside Phantom Engine. Customers do not purchase or assemble them as separate products. - Gate is not a current SKU. Enforce is a function inside Phantom Engine. There is no hosted Gate, no Cloud Enforce, no Gate Pro, and no separate Enforce SKU. - There is no four-product model and no product named Absolute Control. - Continuous Assurance is a platform capability across the products, not a separate commercial product. ## Autonomous Enterprise is not a customer product Autonomous Enterprise is the private company operating system Vantio runs internally to operate itself. It is not a customer product, it is not sold, and it is not part of any SKU. Vantio's Product System is separate from it. Customer products do not contain Vantio company workflows, internal reporting, operating queues, CRM operations, credentials, Founder logic, internal dashboards, or private company data. Internal company measurements are not customer-facing product evidence. ## Current supported scope - Supported means tested at a defined scope. Vantio publishes supported environments and paths based on validated behavior. - A familiar framework, Linux distribution, container system, or agent runtime is not automatically supported merely because it can run on Linux. - Optics covers supported wrapped application paths on macOS, Linux, and Windows with WSL. - Phantom Engine application-path enforcement covers supported requests it can intercept. - Phantom Engine host-level authority covers enrolled Linux infrastructure within documented and validated coverage. - Windows and macOS host-level enforcement are not available. - A process that skips the wrap, opens a raw socket, or forks away can act without a matching application-path record. That gap is named rather than implied away. - Vantio does not claim universal agent discovery. - Current capabilities apply only within documented and validated coverage. Vantio does not claim universal endpoint protection, universal sandbox containment, or protection of infrastructure where it is not deployed. ## Evidence classifications Vantio distinguishes product health, enforcement results, evidence freshness, and independent verification. Missing, stale, unavailable, or unsupported evidence must remain visible rather than being rounded up into a passing result. - Currently proven: independently tested and documented within a named coverage scope. A customer can check it. - Target design: designed and specified. Not a current capability claim and not evidence of coverage. - Strategic objective: a direction the company is building toward. It is not a product capability. - Unavailable: missing, stale, unsupported, or not yet published. Unavailable stays visible and is never rounded up into a pass. Evidence must distinguish between product health, internal testing, external proof, customer validation, and unavailable information. ### Internal proof is not external proof Internal testing on infrastructure Vantio operates is not external proof and is not customer validation. Internal Mission Control measurements are not customer proof. A healthy service, a generated report, a green dashboard, an exit code of zero, or a successful request does not independently prove that an autonomous workload was correctly governed. ### Target design is not current capability A design principle describes what the architecture is built to guarantee. It is not a statement that the guarantee has been proven at scale. Do not restate a target design as a current capability. ### Public evidence state Vantio publishes product evidence only when the artifact is scope-labeled, current, sanitized, and independently verified. No public evidence artifact currently satisfies that publication standard. Customer-facing evidence should be exportable, scope-labeled, freshness-labeled, and independently checkable. ## Status of named claims - Necessity Objective: strategic objective. It is a company direction, not a product capability, and not a claim that Vantio is required. - Agent Capability Invariance: target design. - Two-direction hostile-agent defence: target design. - Lineage, sequential, and aggregate authority: target design. - Swarm-scale protection: no proof. Current swarm-scale proof is none, and public claims must not state otherwise. - Stranger-host validation: not complete. Vantio has internal and isolated component proof. - Customer validation: none. ## Security model Assume the agent may become more capable than expected. Vantio's Product System is designed around the authority granted to a workload, not the workload's claimed intent. Capability must not create authority. Increasing an agent's intelligence, speed, persistence, persuasion, privilege, coordination, or population must not increase its granted authority. This is Vantio's Agent Capability Invariance principle. It is a design principle, not a claim that Vantio has proven universal swarm or superintelligence containment. Creating more processes, agents, children, delegates, or requests must not silently create new trusted principals or bypass aggregate limits. Coordination is not authorization. A population of agents should not gain greater authority by sharing a credential, creating more processes, dividing work, pooling permissions, or coordinating through shared resources. Vantio cannot disable an external attacker's agents on infrastructure where Vantio is not deployed. Within a protected and validated customer boundary, Vantio's objective is to prevent an external, compromised, modified, or unmanaged workload from receiving unauthorized authority. Vantio does not claim universal control of AGI or ASI. It enforces explicitly granted authority within supported infrastructure and reports what the validated boundary observed, allowed, denied, or could not determine. ## Architecture Authority below the agent. Vantio separates the autonomous workload from the authority boundary that governs it. The workload can reason, plan, use tools, and create processes. The organization defines the authority it receives. A valid credential is not always a valid workload. Vantio's target architecture distinguishes workload identity from workload integrity. A credential, process name, or familiar network location should not automatically prove that the running workload is still the version the organization approved. Individually allowed actions can still create an unauthorized outcome. Vantio's target architecture includes sequential and aggregate authority so limits can apply across a workload, lineage, tenant, fleet, destination, credential, or time window. Unknown must not become allowed by accident. Missing identity, unavailable authorization, stale policy, unsupported coverage, and incomplete evidence must produce explicit states. They must not silently become successful enforcement or verified protection. Authority must be revocable. When authority expires, changes, or is revoked, stale sessions and descendants should not silently retain access. ## Customer control Customers retain control of their infrastructure, authority policy, evidence, revocation, rollback, and removal. Vantio's objective is to earn operational trust by providing a dependable authority and evidence layer, not by making the product difficult to leave. - The customer defines the authority boundary. - The customer chooses when enforcement is enabled and can return it to preview. - Revoked authority stops being honored at the enforcement point. - Evidence is exportable and the customer keeps it. - There is no hidden Vantio remote override on customer infrastructure. - Vantio does not require SSH access to a customer host. - Independent safety systems keep the authority they were designed with. Vantio does not replace an interlock, an e-stop, or a local controller. ## Installation Start with one supported Linux workload. Phantom Engine is deployed on customer-controlled Linux infrastructure using a pinned customer package and a documented installation process. A first deployment should begin with a narrow, non-safety-critical workload and a clear authority boundary. Optics has a published self-serve path. Phantom Engine is not an unattended download today; access is arranged with the Vantio team, and the enrolled-node install, policy, rollback, and removal steps ship with the pinned customer package rather than being published on the website. A first deployment should begin with a documented workload, supported environment, explicit authority, allowed and denied actions, revocation, evidence, rollback, and removal. ## Independent validation Proof begins outside Vantio's own infrastructure. A stranger-host validation uses Linux infrastructure Vantio does not own or operate. Vantio has internal and isolated component proof. Stranger-host validation is not yet complete. ## Design partners Vantio works with design partners to evaluate Phantom Engine on one narrow, authorized, non-safety-critical Linux workload. The purpose is to establish what can be supported, what should be denied, how authority changes, how evidence is verified, and whether the deployment can be repeated. Outreach is paused and no design partners are enrolled. ## Not claimed Vantio does not publish or imply that it is necessary, required, an industry standard, customer-proven, regulator-approved, audit-approved, or certified without an exact certification. Vantio does not claim to: - protect every agent or every Linux system - prevent every sandbox or kernel escape - be unbypassable, tamper-proof, or unbreakable - control AGI or ASI - stop hostile agents everywhere - reverse completed external actions - provide physical robot safety, flight control, motor control, or braking - automatically make a customer compliant - have proven swarm protection - have completed stranger-host proof - have completed customer validation - treat internal Autonomous Enterprise results as customer evidence - treat product health as proof of enforcement - treat a green dashboard as proof of protection - treat a generated report as independent verification Certifications and authorizations remain separate external programs and are not held today. Certification alignment is not the same as certification held. ## Pages - https://vantio.ai/ — company and product-structure overview - https://vantio.ai/optics — Optics - https://vantio.ai/phantom-engine — Phantom Engine - https://vantio.ai/enterprise — Vantio Enterprise - https://vantio.ai/pricing — pricing and subscription terms - https://vantio.ai/architecture — architecture - https://vantio.ai/security — security model - https://vantio.ai/trust — assurance - https://vantio.ai/product-evidence — public evidence state and claim classifications - https://vantio.ai/docs — documentation - https://vantio.ai/docs/install — installation - https://vantio.ai/docs/stranger-host — independent validation - https://vantio.ai/docs/compatibility — compatibility - https://vantio.ai/docs/design-partners — design partners - https://vantio.ai/compliance — framework status and certification boundaries - https://vantio.ai/company — company - https://vantio.ai/security-disclosure — coordinated vulnerability disclosure - https://vantio.ai/updates — updates