SANDBOX AGENTS & UNTRUSTED CODE

Run agents safely.

Agents need to write and execute code, work with sensitive data, and interact with systems outside the model — safely. Chalk gives every agent an isolated sandbox that runs inside your cloud with the identity, network controls, data access, and tools you define.

hero gradient image

Teams running AI/ML in production with Chalk

logologologologologo

Agents that your CISO approves.

Designed to help AI teams deploy safely and securely. Production-grade by default.

In your cloud.

Run inside the environment you already govern. Chalk's agent runtime deploys sandboxes directly inside your private cloud. InfoSec clears Chalk once inside your VPC, allowing your team to ship new agent use cases without new review cycles.

Secure.

Run in gVisor-isolated sandboxes with their own filesystem, network namespace, resource limits, and CPU/GPU allocation. Least privilege is the starting state. Add outbound access by hostname, CIDR, and port ranges allowlist. Each sandbox launches with its own OIDC-compliant cloud identity, scoped to that workload alone.

Fast, at scale.

Start isolated sandboxes in under a second, and scale up to thousands of concurrent workloads. From a single coding agent to large-scale parallel agent jobs, Chalk handles the execution layer.

Chalk Compute was the only integrated compute and context engine for agents that ran entirely inside our own environment, at the scale we needed, without becoming an infrastructure project. What would have taken months took weeks.

AJ Balance CPO, Grindr

company logo

Run agents safely on the AI data platform for inference.

Sandboxes and network policy.

Run every agent in a gVisor-isolated sandbox with its own filesystem, network namespace, and resource limits, with support for CPU and GPU workloads. Control outbound access with hostname, port, and CIDR allowlists. Define which services and IP ranges an agent can reach, while connections to non-allowlisted destinations are dropped at the network layer.

Workload proxying and identity.

Give each sandbox a workload-scoped cloud identity, rather than embedding long-lived credentials in agent code or images. Let agents hit endpoints with a dummy token, and the sandbox injects the right authentication token.

MCP Gateway.

Register approved tools with the MCP Gateway, authenticate each sandbox through its workload identity, and route tool calls through a governed proxy for centralized policy enforcement and auditability. Enforce Rego policies on every MCP tool call, making decisions based on the user, scopes, backend, tool, and tool-call arguments.

Volumes and functions that scale.

Mount a repo or a dataset as a versioned volume and parallelize work with no copies. Deploy Python callables as remote endpoints. Run durable agent loops and bulk jobs through a function queue with retries.

Context Engine.

The same feature definitions that serve models in production provide the context for agents.

Go deeper on running agents safely.

Building an agent is easy. Deploying it safely is harder.

Bring us the agent deployment that's stuck in security review.

We'll show you how to deploy agents with complex data and governance needs in your cloud, at massive scale.

TALK TO AN ENGINEER