This security policy covers public Vantio GitHub repositories under vantioai, primarily:
vantio-open-core— Vantio Optics open-core (CLI, SDKs, observe-only MCP)vantio-optics-cursor-plugin— Cursor/MCP observe-only plugin
Phantom Engine source is private and is not an open contribution or public disclosure surface via these repos.
Please report suspected security issues responsibly:
- Email: security@vantio.ai (preferred)
- Or open a private GitHub Security Advisory on the affected public repository, if enabled
Do not open a public issue for unfixed vulnerabilities.
Include: affected package/repo, version or commit, reproduction steps, and impact. Avoid attaching secrets, customer data, or prompts/completions.
We will acknowledge receipt when we can and work to understand and fix confirmed issues in public Optics packages. We do not promise a response time.
Good-faith research that stays within legal and ethical bounds, and that does not disrupt production customer systems, is appreciated. Do not access data that is not yours.
Security fixes are applied to current published Optics package lines on a best-effort basis. Older tags may not receive backports.
- Social engineering
- Denial-of-service against third-party infrastructure you do not own
- Issues in private Phantom Engine source (contact security@vantio.ai instead)