Phantom Engine · Runtime planeAbsolute Control · Rogue Reconciliation · Customer-hosted

Enforce at runtime · Absolute Control

Runtime boundaries that hold when the app path is skipped.

Phantom Engine is Vantio’s runtime-enforcement plane. It runs on servers or VPC nodes you already operate, uses eBPF-based controls, and keeps Absolute Control with the operator when ordinary app controls miss a path. Optics still sees. Gate still governs. Phantom Engine remains the stronger layer that does not lose to the agent.

This page describes capabilities proved as shipped on customer-hosted infrastructure. Kill-on-enforce stays off by default and human-approved. Multi-tenant cloud SaaS is roadmap, not sold today. For deployment, packaging, and the sales path, continue to Enterprise.

Live · host under protection

phantom · absolute control · protected hostLive
[ ∅ PHANTOM ENGINE ] absolute control · host path
  telemetry · phantom online

  host:  metadata.google.internal
  BLOCKED · rogue — app controls silent

[ ∅ PHANTOM ENGINE ] Summary
  rogue stopped: 47
  gate blocked:  812
  proof:         retained for humans

Where it sits

Optics sees. Gate governs. Phantom Engine holds on the host.

Autonomous agents need more than a dashboard. When a prompt injection steers a process off-script, a loop never loads your SDK, or a workload talks straight to the network, the app path is no longer enough. Phantom Engine attaches where agents already run so you can release powerful agents without handing over Absolute Control.

Start with Optics for visibility and Gate for app-path decisions. Phantom Engine completes the hierarchy when host force is required.

Live · Mission Control · our company suite

Updated 2026-08-01

12,900+

LLM calls observed

20,400+

Calls blocked by policy

26,300+

Payloads redacted

Drill pack

Instrumented drill pack

Live counts from Vantio’s Phantom-Box dogfood — Optics, Gate, and Phantom Engine on our company host. Snapshot of suite traffic we generate and govern, not a customer SLA. Residual paths (including some SaaS HTTPS that never hits Gate) stay named, not erased.

Shipped capabilities

What Phantom Engine proves today — and what it does not claim.

Claims below stay inside Present capabilities. Emergency kill and break-glass remain operator tools under human approval. We do not claim AGI, consciousness, or a multi-tenant cloud control plane.

Path Absolute Control

On protected hosts, non-root opens against enforce paths return EACCES. The workload does not negotiate past the boundary you set.

Scoped enrollment

Docker cgroup enroll and scoped enforcement apply to the workloads you mark. Observe-only is the default chart posture until your team approves enforce.

Network controls that ship today

Sever-CIDR hard-block, L4 database-port block, content-aware TLS sever, and per-cgroup egress controls are proved on the dogfood path. Multi-tenant cloud SaaS is not sold.

Rogue Reconciliation

When the host sees outbound traffic with no matching Optics or Gate record, the suite raises BYPASS_INDICATOR on the same TraceId story so operators can act on a named gap.

Rogue Reconciliation

Rogue Reconciliation: close the story the app layer cannot see alone.

Rogue Reconciliation compares what Optics saw, what Gate decided, and what Phantom Engine saw on the host, and raises a BYPASS_INDICATOR when the host sees traffic with no matching app-layer record. That workflow is how operators keep evidence-backed control when a process tries to leave without the SDK or Gate path.

  1. 01

    Observe on the host

    Phantom Engine records kernel-side evidence for enrolled workloads while Optics and Gate keep filling the app-layer data log.

  2. 02

    Compare the three planes

    Rogue Reconciliation lines up what Optics saw, what Gate decided, and what the host actually transmitted.

  3. 03

    Name the gap

    When the host sees traffic the app layer never recorded, the ledger surfaces BYPASS_INDICATOR instead of pretending coverage was complete.

  4. 04

    Keep proof durable

    Stops, matches, and indicators stay in the data logs your security and risk teams can export when leadership asks what happened.

Deployment boundary

Customer-hosted today. Observe first, then enforce.

Phantom Engine runs on your nodes — on-prem or in your VPC. The documented path is Helm and a DaemonSet on protected hosts, an enroll annotation on the pods you choose, then a deliberate ramp from observe-only to enforce when your security lead approves. Continuous Assurance keeps loader health, enrollment, blocks, and Rogue Reconciliation proven after install.

Your infrastructure

Control stays on customer-hosted nodes. There is no multi-tenant Phantom Engine cloud product for sale today.

Human Absolute Control

Operators set posture. Kill-on-enforce and break-glass stay human-approved and off by default so the suite does not invent authority the customer never granted.

Enterprise packaging

For buyer outcomes, node packaging, and the sales conversation, see Enterprise. This page stays on the product plane and shipped runtime behavior.

Next step

Put Absolute Control on the hosts that need it.

If your agents already run in production and ordinary app controls are not enough, talk through where Phantom Engine deploys, what Rogue Reconciliation proves, and how Enterprise packages the suite for your environment.