Every agent gets
a sandbox.
Isolated execution environments for AI coding agents. Spawn, snapshot, fork — at the speed of thought.
Everything an agent needs.
Nothing it doesn't.
Multi-agent support
Run Codex, Claude, and Gemini agents in isolated sandboxes. Connect via REPL or standard terminal.
Snapshot & restore
Save sandbox state at any point. Restart, fork, or roll back.
Config management
Manage .env files and secrets. Attach configs to sandboxes. Version controlled, never leaked.
Local first
Everything happens on your machine. No cloud dependency, no external calls. Run it on a submarine, an air-gapped lab, or your laptop on a plane.
Docker in Docker
Agents can build, run, and compose containers inside their sandbox. Full Docker daemon access — isolated per agent. Test pipelines, spin up services, run CI locally.
Auditability
Every keystroke, every plan, every output — logged. Full stdin/stdout capture, agent reasoning traces, tool calls, and resource usage. Replay any session.
Integrated harness
Hook into every agent decision point. Approval gates, resource limits, tool permissions — all wired into the platform. Connect policies via webhooks or built-in rules.
Three commands. That's it.
From zero to running agent sandbox in under a minute.
Boring tech. Reliable infra.
Proven primitives. No magic. Everything is inspectable.
How we build.
Dangerous mode
Agents need real access. We give it to them — with isolation, not restriction.
Boring tech
K8s, Postgres, Linux. Proven primitives. No magic. Everything is inspectable.
Isolated by default
Every sandbox is a fortress. Network, filesystem, process — all contained.
Human in the loop
Attach anytime. REPL in. Override. Approve. The agent works for you.
Start building.
Open source. Self-hosted. Deploy in minutes.