
sandbox-runtime
A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

Ephemeral microVM sandbox for AI agents with network allowlisting, secret injection via MITM proxy, and VM-level isolation. Boots in under a second,…

A Microservices-based framework for the study of Network Security and Penetration Test techniques

WASM sandbox with capability enforcement for AI agent code. Agents can only call explicitly provided tools with defined constraints. Sandboxed…

Secure OCI container runtime that runs workloads inside lightweight VMs, providing strong isolation across Kubernetes, containerd, and CRI-O with…

Automate the creation of a lab environment complete with security tooling and logging best practices

A secure low code deception runtime framework, leveraging AI for System Virtualization.

Ultrafast CLI on Apple Silicon macOS for fast, sandboxed development and LLM agents.

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

Manage OpenClaw in your team (Enterprise) by providing it compute infrastructure, tool integration, Authentication and security primitives

Lightweight, secure Linux sandboxes for untrusted processes. Runs in the browser and on the server.

Firecracker made simple. Spin up secure microVMs in milliseconds, from install to interactive shell in one command.

ArmourBird CSF - Container Security Framework


A lightweight command sandbox for Linux, secure-by-default, built on Landlock.

Run Firefox in a rootless Podman container with dropped capabilities, isolated networking, and ephemeral storage to contain sandbox escapes and…

kali-linux-docker