
gvisor
Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

A secure low code deception runtime framework, leveraging AI for System Virtualization.

Zero-trust agentic AI platform. Supports SaaS and OnPrem (airgapped) deployments.

GoTEE - example application

AndroSH No-Root Multi-Distro Linux on Android via Shizuku/ADB - Run Arch, Fedora, Alpine, Debian, Ubuntu, Kali, Void, Manjaro, OpenSUSE & Chimera…

Framework for compiling and executing Go applications on bare metal processors, enabling secure firmware development with reduced attack surface…

Let your AI go full send. Your home directory stays home.

Give coding agents a disposable Linux VM, not your laptop

Tracking Januscape (CVE-2026-53359), the KVM/x86 guest-to-host escape

Tracking ITScape (CVE-2026-46316), the KVM/arm64 guest-to-host escape

Rex is a safe and usable kernel extension framework that allows loading and executing Rust kernel extension programs in the place of eBPF.

Ephemeral microVM sandbox for AI agents with network allowlisting, secret injection via MITM proxy, and VM-level isolation. Boots in under a second,…

Manage OpenClaw in your team (Enterprise) by providing it compute infrastructure, tool integration, Authentication and security primitives

Go Trusted Execution Environment (TEE)

Open-source sandboxed runtime for AI agents — gVisor/Docker isolation, credential vault, immutable audit log. Built after CVE-2026-25253.

A lightweight command sandbox for Linux, secure-by-default, built on Landlock.

The fastest LoongArch sandbox

GO sandbox to run untrusted code