Every agent your teams run, in one history.
Vartio receives the signed record from every machine that runs an agent — laptops, CI runners, build boxes — compares each run against what your team has accepted, and keeps a history nobody can rewrite. Records are signed where they ran. Vartio never signs for a machine.
How it works
Selko records a run on one machine. Vartio is what an organization adds when many machines run agents: one place the records arrive, one baseline they are held against, one history that only grows. And when knowing isn’t enough: declare the boundary, and destinations you didn’t declare don’t exist.
What it does and what it never does
- Receives
- Behaviour Commits, each one sealed and signed on the machine that ran the agent. The local witness keeps control; Vartio adds supervision on top, never underneath.
- Compares
- Every run against the baseline your team has accepted. A new host, a new credential, a new binary shows up as a difference, not a verdict.
- Keeps
- An append-only history. A correction is a new record; the old one stays, and stays queryable.
- Answers
- What changed, where, and under whose grant, across every agent your teams run. It says what it knows, what is missing, and what later evidence changed.
- Never
- Rewrites a record, signs for a machine, or blocks a run. Vartio remembers. The boundary is a separate, declared thing.
Selko sees. Vartio runs the fleet. Taso is the gate.
Start with one machine. Add the fleet when you have one.
Vartio is paid, one per organization, and in early access. Selko is free for every seat and is where every record begins. One email gets you both conversations.