Used for

Give the agent root. Walk away.

Every agent gets a real virtual machine with its own kernel — root, systemd, Docker, and no way to reach anything outside it. It will occasionally destroy its own environment, and that will not be a production incident.

Inside every machine

What the agent finds when it opens the box, before it installs anything of its own.

Ubuntu 24.04rootsystemddockerits own kernel2 vCPU / 8 GiB

Its own kernel

Not one shared with other tenants. A KVM boundary the agent cannot cross.

Root from the first minute

Install it, patch it, break it. It is the agent's machine, not a rented shell.

Still there tomorrow

The branch, the dependencies and the database the last run wrote.

The line is one layer higher than you're used to.

"Isolated" is a word every sandbox uses and none of them mean the same thing by. Here is where the line actually falls, and where it falls when a sandbox is a container.

A boxd machineOne kernel each
The agentclaude · npm · psql
root, systemd, dockerit can install anything
Its own Linux kernelUbuntu 24.04
KVM
The host, and every other machine on it

Everything above the line is the agent's to break. Nothing below it is reachable — not the host, not the machine next door.

A container sandboxOne kernel, shared
The agentsame processes
Namespaced rootrestricted, not sovereign
Namespaces
A kernel shared with every other tenant
The host

The line sits one layer lower, and the layer underneath it is common ground. One kernel bug is every sandbox on the box.

This is the whole reason you can stop reviewing what an agent is about to run. Inside its own kernel there is nothing it can break that isn't already its to break.

GIFNeeded

An agent run that ends mid-task, the machine going to sleep, then a second run days later resuming on the same machine with its branch and node_modules intact. The gap between the two runs is the point — caption it with the real elapsed time.

A sandbox that forgets isn't a sandbox.

Most agent sandboxes hand back a clean container every run, so the agent spends its first minutes rebuilding the world and its last minutes losing it again. A boxd machine is the same machine tomorrow:

  • The repo, the branch and the uncommitted mess
  • Installed packages and warmed caches
  • A database with the rows the last run wrote
  • Whatever the agent left running

In Europe, or on your own metal.

boxd runs in European data centres, which for a lot of teams is the difference between an agent being allowed near the codebase and not. The same binaries also run on your own hardware, where nothing leaves your network — the platform is self-hostable because it was built to be, not as an enterprise upsell.

boxd m new agent-7boxd machine fork base agent-7
<10ms
to boot a machine from cold
<200ms
to fork one that is already running
1
kernel per agent, shared with nobody

Stop babysitting what the agent is about to run.

Give it a machine of its own and let it install, break and rebuild whatever it needs to.

Set it up yourself
Sign in and the first machine is yours.
Start now
Talk it through
Tell us the workload and we'll size it with you.
Talk to us