Skip to content
LogoLogo

Security model

BoundaryWhat enforces itWhere it stops
EgressRules are enforced on the host, outside the sandbox, so code inside cannot change or bypass them. IP, CIDR and port rules are matched in the host kernel; domain rules are matched on the TLS server name (HTTPS) or Host header (HTTP). No rules means open. Once any rule is set, everything not listed is denied.Domain rules are tight for HTTPS, where TLS verifies the name. For plain HTTP, allow by IP or CIDR instead of by domain. See Egress.
CredentialsYour API key stays on your machine and never enters a sandbox. Hand a worker a scoped access token for one sandbox instead. envs and disk credentials are write-only through the API and are never returned in any response. Disk credentials are encrypted at rest.Anything you put into a sandbox is readable by code running in it: envs, files you upload, and the keys of any attached disk, which the sandbox needs to mount the bucket. Give disks bucket keys scoped to that bucket only.
IsolationEvery sandbox is a Firecracker microVM with its own guest kernel, filesystem and network identity. Sandboxes cannot reach each other unless you put them on the same private network.Disks are the one thing sandboxes can share. A disk belongs to one account; only that account's sandboxes can attach it. Several of your sandboxes can mount the same disk at once and see the same bucket, with S3's last-write-wins semantics. What is inside the bucket is governed by your bucket policy.
AuditControl-plane actions are recorded as audit events: sandbox create, destroy, pause, resume, fork, resize, egress and SSH-key changes; disk, network, template and device changes. Events cannot be edited or deleted through the API and are kept for 90 days.Activity inside a sandbox is not recorded yet: commands, file reads and writes, processes, and network traffic.
Self-hostRun sandboxes on your own hardware, cloud account or on-premise, so compute and data stay in your environment.Enterprise customers only, onboarded with our team. See Run on your own infrastructure.

Questions or a security review: talk to us.