Sandboxes

Isolated sandboxes for agent code, in your own cloud

Chalk runs agent-generated and untrusted code in gVisor-hardened sandboxes inside your cloud account. Your sandbox can’t talk to anything outside your network policy.

hero gradient
Whatnot logo
Socure logo
Sunrun logo
Grindr logo
Turo logo
MoneyLion logo
Melio logo
Mission Lane logo
Medely logo
Iwoca logo
Nowsta logo
Apartment List logo
Pipe logo

Explore Chalk Sandboxes

Secure by default at every layer

The sandbox kernel, filesystem, network, resource limits and egress are all locked down by default. Agent code never sees a shared secret.

Network policy on egress

Name the hostnames, CIDRs and ports a sandbox may reach. The rest are blocked.

Kernel-hardened by gVisor

Even if agent code escapes the container, it can’t reach the host.

In your VPC, on your hardware

Runs in your account, on your nodes, with the CPU, memory, and GPU you set, under an IAM role or its own OIDC cloud identity.

Replay agents against real data as it unfolded

Run a sandbox against your production data at any point in time. Every sandbox in a parallel run reads the same consistent snapshot.

Versioned state, shareable across agents

Use copy-on-write versioning across sandboxes to mount the exact model, dataset, or repo you want your agent to work with.

company logo

Chalk Compute was the only integrated compute and context engine for agents that ran entirely inside our own environment, at the scale we needed, without becoming an infrastructure project. What would have taken months took weeks.

AJ Balance
AJ BalanceCPO, Grindr

How Chalk Sandboxes work

Isolated by default

gVisor gives each workload its own filesystem, namespace and limits.

Sandbox Docs

Restrict egress explicitly

Allowlist exact hostnames like api.github.com or wildcards like *.github.com. Anything unlisted is blocked.

Network Policy

Mount what the job needs

A versioned volume for a repo, dataset or model weights.

VOLUMES & HOST POOLS

One security review covers every agent

Security signs off on agent projects. Sandboxes deploy inside the environment your security team already governs, so the second agent use case ships without opening a second review.

Security Architecture

Keep up with Chalk

What we've been up to and where to find us next.

Agents that your CISO approves

Talk to an engineer about running agents in your own cloud.