It runs on hardware you own
A private tunnel connects your browser to the sandbox. On a server, it keeps running without you.
Chat, files, editor, terminal
Sandboxes, repos, credentials, capabilities
Stores your identity and sandbox URL. Does not handle commands or files.
You control what is installed
A Dockerfile defines the sandbox's installed software. The agent can propose a change, but it waits for your approval before applying it.

See usage where it happens
The sandbox records the tokens and cost of each turn. The usage stays in your own ledger because the AI account is yours.

What the platform actually holds
It stores your identity, sandbox URL and teammate access. It does not store your code, keys or transcripts.
Stays inside your sandbox
- Your code and repos
- Every credential and token
- The agent's transcripts
- The container and its image
All the platform holds
- Your identity (Google sign-in)
- The sandbox's name and URL
- Billing state
- Grants to invited teammates
Stored records use AES-256-GCM encryption. The product has no feature that can decrypt them.
One sandbox, several people
The owner installs the tools; invited teammates share the sandbox, each signed in as themselves.
- Invite people by email. The sandbox enforces their access, not just the interface.
- Teammates can chat, work, review and open the web apps running in the sandbox.
- Removing someone's access takes effect immediately.
