Phantom Engine · Control · $799 / enrolled Linux node
Control below the application layer.
Runtime protection on Linux you enroll, so unauthorized work can still be refused after the wrap is skipped.
Three outcomes
- Keep unauthorized work from completing on the enrolled host.
- Keep host-level security evidence on infrastructure you operate.
- See when host activity has no matching wrap record.
How it works
- 01Enroll a Linux host as a daemon, or as a Helm DaemonSet on Kubernetes you operate.
- 02Choose which processes to watch. Blocking stays off until you turn it on.
- 03Trace identity follows child processes, so a spawn is not a free pass around the rules.
- 04Rogue Reconciliation compares wrap decisions with host events and names a gap when they disagree.
- 05Configured unauthorized work is refused on that host. The rest of the machine can keep running.
What the enrolled host can refuse
On configured and enrolled Linux workloads, Phantom Engine can enforce declared controls over supported process, filesystem, and network paths. Exact coverage and residual limitations are documented for the deployment.
- After prompt injection
- The injected instruction can still reach the model. Declared host controls then apply to supported process, filesystem, and network paths on that enrolled host.
- Declared filesystem and process paths
- Supported unauthorized opens, writes, and process starts against paths you enroll can be refused. Exact coverage is documented for the deployment.
- Declared network paths
- Supported network policy on the enrolled host can refuse destinations you have named. Residual paths stay named. Configured spend limits on wrapped traffic stay with Gate.
Data and privacy
Host evidence stays on the machines you enroll. Phantom Engine does not retain prompts or completions.
Coverage and limitations
Phantom Engine is not generic endpoint protection. It covers Linux hosts you enroll, not Windows or macOS, and not machines that have not been enrolled. Optics and Gate can still install on macOS and Windows with WSL; that does not mean Phantom Engine Control is available there.
A completed install on infrastructure Vantio does not operate has not been recorded. Spend limits on wrapped agent traffic stay with Gate.
Deployment
- Linux
- Customer-controlled infrastructure, on-premises or VPC
- Standalone hosts or supported Kubernetes deployment
- $799 per enrolled Linux node, via sales
Questions that add detail
- Does Phantom Engine replace my endpoint suite?
- No. Phantom Engine is host control for AI-agent and LLM workloads on Linux machines you enroll. It is not a replacement for the endpoint tools you already run.
- Where do logs live?
- On infrastructure you own. Phantom Engine evidence stays on the hosts you enroll. We have not published a customer CPU-overhead figure; ask sales for a measured walkthrough on your nodes.
Next: Enterprise
When you need governance, durable evidence, and dual-control on top of that protection, add Enterprise.