Hardened sandbox
Dropped capabilities, read-only root filesystem, no new privileges and per-job network isolation.
Execution sandbox
Governed execution of containers over HTTP, with full lifecycle control.
A REST API and MCP server for running Docker containers in hardened, isolated sandboxes on a dedicated host. Submit, pause, resume and observe jobs over HTTP; no SSH, no shared runners.
Who it is for. Teams that execute untrusted or machine-generated code and need isolation, observability and control rather than a general-purpose runner.
Dropped capabilities, read-only root filesystem, no new privileges and per-job network isolation.
Pause a live computation with its in-memory state and resume exactly where it stopped.
Fan-out and fan-in pipelines with conditional branching, retries, data passing and human approval gates.
Streaming logs, live CPU, memory and network use, and the full state history of every run.
Jobs queue with position and estimated start when at capacity; schedule for later or defer to business hours.
Software agents connect with a URL and an API key; every operation is exposed as an MCP tool.
The product site has the documentation and the way in. For procurement questions, a pilot or an integration, talk to us directly.