Three operating systems
Windows, Linux, and macOS sandboxes from one API, for agents that operate real desktop and server software.
Own the machines your agents run on.
The sandbox service behind Engine, available standalone. Deploy it on-prem or in your cloud and give every agent an isolated Windows, Linux, or macOS machine with snapshots, network policy, and full session recording.
Linux
us-west / private
Windows
on-prem / finance
macOS
build pool / 04
Image ready
snapshot 01
Tools installed
snapshot 02
Before submission
snapshot 03
How it works
Each run keeps the request, actions, evidence, and final decision together.
01 · Create
Request a Windows, Linux, or macOS environment with the machine policy assigned to the workflow.
Output · Isolated machine
02 · Operate
The agent uses the machine while Context records actions and enforces the configured egress policy.
Output · Recorded session
03 · Preserve
Export artifacts and the run record, then restore a checkpoint or destroy the environment.
Output · Artifacts and snapshot
What you can inspect
Windows, Linux, and macOS sandboxes from one API, for agents that operate real desktop and server software.
Runs on-prem or in your VPC. Machine images, data, and traffic never leave your perimeter.
Checkpoint a machine mid-task, branch it, or roll it back. Reproduce any run from its snapshot.
Default-deny egress with allowlists per workflow, so an agent reaches exactly what its task requires.
Full video and input capture of every session, tied to the run's trace for review and audit.
Deployment boundaries
Agent Sandboxes can run as a standalone surface, while its traces, evals, and policy decisions remain part of the same Context system.
Operating-system availability and startup time depend on the images and hardware configured in your environment.
Retention, redaction, and access to session recordings follow your organization's policy.