Security model
| Boundary | What enforces it | Where it stops |
|---|---|---|
| Egress | Rules are enforced on the host, outside the sandbox, so code inside cannot change or bypass them. IP, CIDR and port rules are matched in the host kernel; domain rules are matched on the TLS server name (HTTPS) or Host header (HTTP). No rules means open. Once any rule is set, everything not listed is denied. | Domain rules are tight for HTTPS, where TLS verifies the name. For plain HTTP, allow by IP or CIDR instead of by domain. See Egress. |
| Credentials | Your API key stays on your machine and never enters a sandbox. Hand a worker a scoped access token for one sandbox instead. envs and disk credentials are write-only through the API and are never returned in any response. Disk credentials are encrypted at rest. | Anything you put into a sandbox is readable by code running in it: envs, files you upload, and the keys of any attached disk, which the sandbox needs to mount the bucket. Give disks bucket keys scoped to that bucket only. |
| Isolation | Every sandbox is a Firecracker microVM with its own guest kernel, filesystem and network identity. Sandboxes cannot reach each other unless you put them on the same private network. | Disks are the one thing sandboxes can share. A disk belongs to one account; only that account's sandboxes can attach it. Several of your sandboxes can mount the same disk at once and see the same bucket, with S3's last-write-wins semantics. What is inside the bucket is governed by your bucket policy. |
| Audit | Control-plane actions are recorded as audit events: sandbox create, destroy, pause, resume, fork, resize, egress and SSH-key changes; disk, network, template and device changes. Events cannot be edited or deleted through the API and are kept for 90 days. | Activity inside a sandbox is not recorded yet: commands, file reads and writes, processes, and network traffic. |
| Self-host | Run sandboxes on your own hardware, cloud account or on-premise, so compute and data stay in your environment. | Enterprise customers only, onboarded with our team. See Run on your own infrastructure. |
Questions or a security review: talk to us.