Solutions · Agent computers

When the whole machine exists to run agents.

Give agents their own computer and the blast radius becomes the computer. The good news is that if it runs Linux and you own it, the control you need already exists. The honest news is that the fleet story around it does not.

Available today

If the agent computer is a Linux machine you own and enroll, everything Phantom Engine does on a host already applies to it, and Optics and Gate work on the supported agent paths running there. Nothing about the box being dedicated to agents changes that.

Roadmap

The rest of this idea is design work. Purpose-built agent-computer form factors, enrolling a fleet of them at scale, and anything that is not Linux are not available, and nobody has run this in production on hardware Vantio does not operate.

What you are actually trying to do

The pattern keeps showing up. Instead of agents living inside an application server next to everything else, a team gives them their own machine. It has its own credentials, its own network position, its own tools installed, and it runs more or less continuously.

That is a better operational story and a worse security story at the same time. The work is easier to reason about because it is in one place, and it is harder to bound because the whole machine now exists to let software act on your behalf. A dedicated box tends to accumulate reach.

So the question you are really asking is narrow and practical. On a computer whose entire job is running agents, what can you actually constrain, and what evidence do you get back?

What works today on this node class

A dedicated agent machine is, from our side, an enrolled Linux host. That is why the present slice here is real.

Available todayHost control on Linux you enroll
Enroll the machine and Phantom Engine holds the execution envelope underneath whatever the agents are doing. It observes TLS connections with eBPF, carries trace identity into child processes so forking is not an escape hatch, protects the paths you declare, and scopes egress by cgroup and CIDR. Host evidence stays on the machine. At $799 per enrolled Linux node, this is the piece that matters most on a dedicated box.
Available todayOptics and Gate on the supported agent paths
The agents on that machine still make ordinary model and tool calls. Optics records the destination, process, timing, volume, and trace for the supported Node and Python paths without keeping prompts or completions, and Gate applies destination policy, field redaction, and size and spend caps once you decide what the rules are. Gate is $499 a month after a 14-day trial that our team sets up for you.
Available todayRogue Reconciliation between the two
This is the part that earns its keep on a dedicated machine. When the host sees traffic that has no matching application-layer record, you find out. On a box where a dozen tools are installed and any of them might open a socket, that mismatch is the signal you want.
RoadmapEnterprise governance on the same enrolled hosts
Durable evidence, audit records, and dual-control sit on top of Phantom Engine on the Linux you enroll, and that path exists today. What has not been done is running it across a population of agent computers as a managed fleet, which is where most of the interesting problems live.

How host control works

What is not available yet

Stated as facts, so you can plan around them.

  • There is no purpose-built Vantio agent computer, and no hardware partnership behind one. If you are picturing a device you buy from us, that does not exist.
  • Fleet enrollment at scale has not been proven. Enrolling one Linux host is a documented path; enrolling and operating hundreds of dedicated agent machines is not.
  • Anything that is not Linux is out of scope for host control. Windows and macOS host enforcement are not available, and calling the machine an agent computer does not change that.
  • No customer has run this on hardware Vantio does not operate. Everything proven so far was proven on infrastructure we run ourselves.
  • Control of every process on the machine is not on offer. Phantom Engine covers the supported process, filesystem, and network paths you declare, and the residual paths get named rather than implied away.

See what enrolling a host involves

What stays true regardless

Dedicated machine or shared one, the ownership model is the same.

  • You own the policy. Vantio does not decide what your agents are for.
  • You set the level of autonomy, and you can turn it down at any time.
  • You can revoke a capability, and the enforcement point stops honoring it.
  • You can export the evidence and take it with you.
  • There is no hidden Vantio remote override on your infrastructure.
  • Independent safety systems keep the authority they were designed with. Vantio does not replace an interlock, an e-stop, or a local controller.

Try it on the machine you already have

You do not need special hardware to find out whether this fits. Run Optics on the agents first, and if the box is Linux you own, enrolling it is the next honest step. Tell us what the machine is doing and we will tell you which parts apply.

The node class that is fully supported today is enterprise agents.