local. a real microvm in milliseconds.
one command gives untrusted code its own kernel on your machine. no daemon, no root, no account. when the code goes rogue, it trashes its computer, not yours.
agent / ubuntu:latestactual microvms, a kernel per sandbox. run generated code, third-party software, or your own apps. local, in our cloud, or on your own infra.
talk to a founderChoose the interface you already use, copy one command, and run it on your machine.
open the full quickstartnpx microsandbox run ubuntu:latestagent / ubuntu:latestone command gives untrusted code its own kernel on your machine. no daemon, no root, no account. when the code goes rogue, it trashes its computer, not yours.
agent / ubuntu:latestthe sandbox you built locally runs unchanged in our cloud. orgs, sso, audit logs, quotas, invoicing. local or cloud is a config change, not a rewrite.
agent / ubuntu:latestregulated, or just careful? the exact same runtime is apache 2.0 open source. run it in your own vpc or on your own metal. contact us to evaluate.
agent / ubuntu:latestEach sandbox carries its own kernel behind a hardware boundary.
A separate kernel boundary for every workload.
03 / open by default
read the security model. reproduce the benchmarks. run the runtime on your own machine before you put it in your fleet.
book a demoone sdk. one api. local or cloud is a config change, not a rewrite. private beta. access is by request.
Docker is excellent for trusted application packaging. microsandbox is the Docker replacement for untrusted workloads: the same OCI-image workflow, but every sandbox gets its own kernel inside a microVM, so an agent escape hits a hardware boundary before it reaches the host.
The local runtime runs on your machine. For managed deployments, we review data handling, residency, audit, and secrets requirements with your team before rollout.
macOS · Linux · Windows (WHP, preview). byoc brings the runtime to your own cloud or metal. contact us to evaluate.
Rust, TypeScript/Node, Python, Go, and a CLI today. MCP workflows are also part of the developer surface.
by default, sandboxes can reach the public internet. private, host-local, link-local, and metadata destinations are blocked. egress can be reduced to an allowlist or disabled entirely. in the cloud, the non-public block cannot be lifted, even by you. credentials are destination-bound. the sandbox works with a placeholder; the real value is substituted host-side into supported intercepted outbound requests, only for destinations on your allow-list. an approved destination still receives the real credential and could reflect or misuse it, so scope your allow-lists accordingly.
microsandbox runs untrusted code in hardware-isolated microVMs with their own kernel. It is open source under Apache 2.0.
running the apache 2.0 runtime locally is free. private beta. access is by request. private beta pricing is published at /pricing; rates need owner confirmation before promotion.