CreateOS Sandbox

Instant, hardware-isolated sandboxes for AI agents — ~30ms provisioning without sacrificing real isolation

Visit website →

About

Every sandbox tool makes you pick: fast provisioning or real isolation. CreateOS Sandbox refuses that tradeoff: it runs every workload in a Firecracker micro-VM with its own kernel, with roughly 30ms provisioning (p90), private sandbox-to-sandbox networking, pause-to-zero with state preserved, and no egress fees. You can mount your own Amazon S3, MinIO, or Cloudflare R2 as a filesystem, so your data stays in storage you control.

Code inside one sandbox cannot see the host or any other tenant; a guest kernel compromise stays inside that one micro-VM and does not spread to the host or the rest of your fleet — making it suitable for running untrusted or model-generated code without exposing your infrastructure. A configured sandbox can be saved as a template and identical environments launched from it in a single call, with no reprovisioning per run, and a run's output syncs automatically without manual copy steps. It ships with a CLI, SDK, and 51+ real-world examples (Claude-managed agents, multi-node clusters, batch inference, ffmpeg transcoding, and more), plus a Sandbox plugin for Claude that lets it run untrusted code in a box that self-destructs when idle.

Pricing is set at the E2B and Daytona reference rate with a published comparison, and new sign-ups get 500 free credits, no card required.