Phantom Engine · Control · $799 / node / month

Control below the application layer.

Runtime protection on Linux you enroll, so unauthorized work can still be refused after the wrap is skipped.

Three outcomes

  • Keep unauthorized work from completing on the enrolled host.
  • Keep host-level security evidence on infrastructure you operate.
  • See when host activity has no matching wrap record.

How it works

  1. 01Enroll a Linux host as a daemon, or as a Helm DaemonSet on Kubernetes you operate.
  2. 02Choose which processes to watch. Blocking stays off until you turn it on.
  3. 03Trace identity follows child processes, so a spawn is not a free pass around the rules.
  4. 04Rogue Reconciliation compares wrap decisions with host events and names a gap when they disagree.
  5. 05Configured unauthorized work is refused on that host. The rest of the machine can keep running.

What the enrolled host can refuse

After prompt injection
The injected instruction can still reach the model. When the agent then tries a shell, a socket, a child process, a file write, or an unapproved destination, the host can refuse that move.
Protected files
Unauthorized opens and writes against paths you protect are blocked on the enrolled host.
Process-aware destinations
Network policy can drop destinations you have not approved — including raw sockets, DNS-style paths, CIDR ranges, and database ports you name — without turning the whole server into an all-or-nothing firewall.
Unauthorized processes
The host can halt a process that starts unauthorized work. Configured spend limits on wrapped traffic stay with Gate.

Data and privacy

Host evidence stays on the machines you enroll. Phantom Engine does not retain prompts or completions.

Coverage and limitations

Phantom Engine is not generic endpoint protection. It covers Linux hosts you enroll, not Windows or macOS, and not machines that have not been enrolled. Optics and Gate can still install on macOS and Windows with WSL; that does not mean Phantom Engine Control is available there.

A completed install on infrastructure Vantio does not operate has not been recorded. Spend limits on wrapped agent traffic stay with Gate.

Deployment

  • Linux
  • Customer-controlled infrastructure, on-premises or VPC
  • Standalone hosts or supported Kubernetes deployment
  • $799 per governed node per month, via sales

Questions that add detail

Does Phantom Engine replace my endpoint suite?
No. Phantom Engine is host control for AI-agent and LLM workloads on Linux machines you enroll. It is not a replacement for the endpoint tools you already run.
Where do logs live?
On infrastructure you own. Phantom Engine evidence stays on the hosts you enroll. We have not published a customer CPU-overhead figure; ask sales for a measured walkthrough on your nodes.

Next: Enterprise

When you need durable evidence, audit records, and dual-control on top of that protection, Enterprise adds governance.

Explore Enterprise