As said in the title. The default Vantage install should come with a securityContext with the highest restrictions the Vantage developers believe their app can run with, and Vantage should run as non-root user out of the box.
These are things I can tweak when installing Vantage. But inexperienced Kubernetes maintainers will probably leave the defaults, following Vantage documentation exactly, and result in a less-than-ideal configuration. This is especially important for clusters with Restricted requirements.