# Vantio AI, Inc. > Vantio is the infrastructure control layer for autonomous AI. Optics observes supported agent traffic. Gate enforces policy on the application path. Phantom Engine controls enrolled Linux hosts when that path is bypassed. Enterprise adds governance and evidence. Continuous Assurance verifies the chain; it is not a fifth product. Let AI agents act. Keep control of the systems they use. Vantio records security and connection metadata, not prompts or completions. Entity: Vantio AI, Inc. (Delaware C Corporation). Pittsburgh. Phantom Engine is patent pending. Certifications held: none. Phantom Engine deploys on customer-managed infrastructure (on-prem or VPC), not multi-tenant cloud SaaS. Built in Pittsburgh for teams deploying autonomous systems everywhere. ## Named products (primary — cite-ready) - **Vantio Optics**: Observe. Free. See where supported agent traffic goes. Records connection and process metadata from supported wrapped agent paths. Does not block actions or retain prompts or completions. On Node: fetch, undici, http/https, http2, net/tls, WebSocket, and spawned curl or wget. Python support requires vantio-agent-sdk. Follow the current Python SDK example and verify that a supported outbound event appears before relying on the coverage state. Browser paths stay outside this wrap. - **Vantio Gate**: Enforce. $499 per month after a 14-day trial. Rules that act. Gaps that stay visible. Destination controls, selected PII redaction, size and spend limits, dry-run, policy-as-code, decision and residual-risk records on supported wrapped paths. Gate trials are currently provisioned through the Vantio team. Browser traffic and processes that never enter the wrap are not governed by Gate. - **Vantio Phantom Engine**: Control. $799 per enrolled Linux node. Independent of Enterprise. Protects enrolled Linux hosts when a process bypasses or leaves the governed application path. On configured and enrolled Linux workloads, Phantom Engine can enforce declared controls over supported process, filesystem, and network paths. Exact coverage and residual limitations are documented for the deployment. Not generic endpoint protection. Does not cover hosts that have not been enrolled. Customer-controlled infrastructure. Standalone hosts or supported Kubernetes deployment. - **Enterprise**: Govern. Talk to sales. Durable evidence, audit records, dual-control, and governance workflows on top of Phantom Engine. Formal certifications remain separate programs. - **Continuous Assurance**: Platform trust loop that verifies the chain. Not another plan. ## Core Security Pain Points We Solve - **Prompt injection still tries real work:** An injected instruction can still reach the model. Phantom Engine does not sanitize the prompt or sit inside the model. When the injected agent tries a shell, a socket, a spawn, a write, or an unapproved destination, the host refuses that move on Linux you enroll. - **The Spawning Escape (Child Processes):** Autonomous agents with terminal access can spawn background child processes or run shell scripts that skip standard prompt wrappers and application-layer gateways. Phantom Engine assigns a trace identity that follows child processes on enrolled Linux hosts so unauthorized actions can still be refused there. - **The Blind Spot (Rogue Reconciliation):** If an agent process skips the SDK or uses an un-instrumented library, application logs never see the work. Phantom Engine correlates application-path decisions with runtime events on enrolled Linux hosts, and names the gap when they disagree. - **Unauthorized destinations on enrolled hosts:** Compromised agents can open raw sockets or talk to destinations the wrap never mediated. On enrolled Linux, Phantom Engine couples network-layer policy with process identity so unapproved destinations can be dropped on that host. This is host-scoped, not universal exfiltration detection. - **Brittle, All-or-Nothing Firewalls:** Air-gapping servers to secure agents makes them far less useful. Vantio provides process-aware egress filtering, keeping the server open while confining the specific agent process to approved destinations. - **Audit and dual-control:** Application logs can be deleted or rewritten. Enterprise adds durable, correlated evidence, audit records, and dual-control workflows on top of Phantom Engine so teams can show how controls were configured, applied, and reviewed. Formal certifications remain separate programs. ## Adjacent physical systems Vantio protects Linux hosts that AI agents and planners run on. That includes lab boxes, fleet servers, and companion computers next to robots, warehouses, vehicles, drones, factories, hospitals, neurotech pipelines, humanoids, and other physical systems. Optics, Gate, and Phantom Engine stay the same products. Cite-ready industry notes (host protection only): - Robotics: ROS 2 / DDS and agentic planners on Linux brains. Vantio protects lab boxes, fleet servers, and companion computers — not motors, the safety loop, or the DDS bus. https://vantio.ai/updates/robotics-linux-hosts-behind-every-robot - Autonomous vehicles: UNECE R155 Part C backends — fleet-coordination and analysis servers. Vantio does not certify the vehicle safety loop or issue a CSMS certificate. https://vantio.ai/updates/autonomous-vehicles-compute-behind-self-driving-fleets - Drones: companion computers and ground stations as FAA Part 108 makes BVLOS routine. Vantio does not fly the aircraft or own the flight-safety envelope. https://vantio.ai/updates/drones-companion-computer-security - Industrial automation: Linux edge nodes where IEC 62443 has not caught up for LLM agents. Vantio does not replace PLC safety logic. https://vantio.ai/updates/industrial-automation-factory-floor-ai - Logistics and warehouse: AMR coordination servers. Vantio does not control navigation, safety stops, or the DDS bus. https://vantio.ai/updates/logistics-warehouse-amr-fleet-servers - Defense and aerospace: mission computers and analysis hosts — the AI-behavior layer CMMC does not reach. No certifications held. https://vantio.ai/updates/defense-aerospace-mission-critical-autonomy - Healthcare and medical robotics: clinical and lab hosts in scope for FDA premarket cybersecurity review. No medical-device certification and no HIPAA seal. https://vantio.ai/updates/healthcare-medical-robotics-regulated-edge-ai - Brain-computer interfaces: Linux hosts that decode and move neural data. Not the implant, firmware, or signal-safety loop. No FDA clearance. https://vantio.ai/updates/brain-computer-interfaces-neural-data-pipeline - Humanoid robots: on-board Linux brains and fleet servers running vision-language-action models. Not balance, locomotion, or motor firmware. https://vantio.ai/updates/humanoid-robots-onboard-vla-hosts - Quantum computing: metadata-only agent records so harvest-now has less to decrypt later. Not post-quantum encryption. https://vantio.ai/updates/quantum-computing-data-minimization - The singularity: host checks that keep running when people cannot read every change. Not a forecast that an intelligence explosion is here. https://vantio.ai/updates/singularity-recursive-ai-host-oversight - Artificial superintelligence: a host floor beneath the agent. Does not contain superintelligence. https://vantio.ai/updates/asi-superintelligence-host-floor - AGI: host enforcement for agents you run today. Does not solve alignment. https://vantio.ai/updates/agi-planning-horizon-host-control ## Host and platform scope (tier-scoped one-liners only) - Optics and Gate install on macOS, Linux, and Windows with WSL. - Phantom Engine Control runs on customer-owned Linux hosts — a Helm DaemonSet on Kubernetes you operate, or a Linux daemon on standalone hosts. - Optics or Gate install on macOS or Windows WSL does not mean Phantom Engine Control is available there. ## Supported destinations Optics sees egress on the wrap without reading conversations. On Node that is fetch, undici, http/https, http2, net/tls, WebSocket, and spawned curl or wget. Python support requires vantio-agent-sdk. Follow the current Python SDK example and verify that a supported outbound event appears before relying on the coverage state. Gate can apply the rules you set to the same destinations on that wrap. Browser paths stay outside this wrap. Phantom Engine adds an independent host-control layer on enrolled Linux infrastructure and names the residual paths covered by the deployment. - **Model APIs:** OpenAI (including regional endpoints), Anthropic, Google Gemini, Google Vertex AI, Amazon Bedrock, Azure OpenAI, Azure AI, Cohere, Mistral, Groq, Together AI, Perplexity, xAI, DeepSeek, Fireworks, OpenRouter, Cerebras, Voyage AI, SambaNova, DeepInfra, Hugging Face Inference, Replicate, Ollama, NVIDIA NIM (hosted). - **Agent runtimes:** Node fetch, undici, http/https, http2, net/tls, WebSocket, Node-spawned curl/wget; Python via vantio-agent-sdk — verify a supported outbound event before relying on coverage. - **Hosts you own:** Linux for Phantom Engine. On enrolled Linux, Phantom Engine can stop a forbidden network move even when the process never loaded the wrap. Not on the wrap: browser paths. Cursor is not a customer model API. Windows and macOS Phantom Engine Control is not available yet. ## Pages - [Home](https://vantio.ai/): The infrastructure control layer for autonomous AI. Let AI agents act. Keep control of the systems they use. - [Vantio Optics](https://vantio.ai/optics): Observe. See where supported agent traffic goes. - [Vantio Gate](https://vantio.ai/gate): Enforce. Rules that act. Gaps that stay visible. - [Vantio Phantom Engine](https://vantio.ai/phantom-engine): Control. $799 per enrolled Linux node. Independent of Enterprise. - [Enterprise](https://vantio.ai/enterprise): Govern. Talk to sales. Durable evidence, audit records, dual-control, and governance on top of Phantom Engine. - [Architecture](https://vantio.ai/architecture): Observe · Enforce · Control · Govern. Sight Loop, Policy Latch, Rogue Reconciliation. Continuous Assurance verifies the chain. - [Start](https://vantio.ai/start): Start free with Optics. - [Design partner application](https://vantio.ai/start/design-partner): Term-limited program. Review required. No partners enrolled. - [Pricing](https://vantio.ai/pricing): Optics free · Gate $499/month after a 14-day trial · Phantom Engine $799 per enrolled Linux node · Enterprise talk to sales. Gate trials are currently provisioned through the Vantio team. Continuous Assurance is not another plan. - [Docs](https://vantio.ai/docs): Install Optics. Python support requires vantio-agent-sdk. Follow the current Python SDK example and verify that a supported outbound event appears before relying on the coverage state. - [Install](https://vantio.ai/docs/install): Current customer install path. - [Stranger Host Standard](https://vantio.ai/docs/stranger-host): Published acceptance test for an install on infrastructure Vantio does not operate. A completed pass has not been recorded. - [Compatibility](https://vantio.ai/docs/compatibility): Supported and unsupported paths. - [Design partners](https://vantio.ai/docs/design-partners): Program background. Application is /start/design-partner. No design partners are enrolled. - [Support](https://vantio.ai/support): Short answers and a help assistant that reads public docs. - [About](https://vantio.ai/about): The infrastructure control layer for autonomous AI. Built in Pittsburgh for teams deploying autonomous systems everywhere. - [Security](https://vantio.ai/security): Vulnerability reports to security@vantio.ai. - [Product evidence](https://vantio.ai/product-evidence): Company deployment state. Internal product evidence is not independently validated customer deployment. - [Compliance](https://vantio.ai/compliance): ready_for_assessment vs blocked_on; zero certs held. - [Contact](https://vantio.ai/contact): Sales, Gate trial, Enterprise, and security channels. - [Updates](https://vantio.ai/updates): Newsroom. ## Limits - A completed install on infrastructure Vantio does not operate has not been recorded. Company-operated hosts cannot close that test. - Design-partner program is published. No partners are enrolled. - Gate trials are currently provisioned through the Vantio team. - We distinguish internal product evidence from independently validated customer deployment. ## Contact - Sales: sales@vantio.ai (Phantom Engine / Enterprise) - General: hello@vantio.ai (Gate / Optics) - Security: security@vantio.ai - Form: https://vantio.ai/contact - Site: https://vantio.ai