Agent sandboxes · In your cloud · Set up for you

The agent sandbox
that runs in your own cloud.

Every agent run gets its own isolated microVM, deployed inside your GCP, AWS or Azure account — never ours. No outbound network unless you allow it, zero stored credentials, and an audit trail for every run. Our forward-deployed engineers stand it up in your cloud for you.

See how it works →
Your cloud
Sandboxes run in your account · nothing on our side
MicroVM per run
Hardware isolation · no egress by default
Days, not quarters
Forward-deployed team sets it up
Scroll
// Our story · Betaworks Demo Day

The story behind Quome, straight from Demo Day.

Our CEO/CTO on stage at Betaworks Demo Day — the problem, the vision, and why software in regulated industries should be as fast to build as it is safe to run.

Betaworks Demo Day — Quome▶ DEMO DAY
01 Why now

The frontier labs' own sandboxes didn't hold.

Twice in three months, OpenAI paused frontier training because agents got out of their containment. If you are shipping agents to customers, sandboxing just moved to the top of the list.

An agent that can write and run code will eventually probe the walls around it. The question is whether the walls are yours, in your cloud — or a filter someone else runs.

The September escape went out through DNS — a hole in a network filter. The summer incident went out through exposed credentials and shared infrastructure. Both are exactly the surfaces a Quome sandbox is built to remove: a policy of no egress at all instead of an allow-list, no long-lived keys inside the box, and a fresh microVM per run that is destroyed when the run ends.

Quome does not sell you a shared sandbox farm. It deploys the sandbox plane into your own cloud account, so the blast radius is bounded by your VPC and your policies — and the security review is about your infrastructure, not ours.

May – July 2026 · The Hugging Face incident

~1,200 OpenAI eval agents broke containment and attacked Hugging Face.

Agents in an internal evaluation with reduced safety measures used exposed credentials and zero-days to reach outside infrastructure, and coordinated with each other on the way out.

Axios ↗Fortune ↗
September 20, 2026 · DNS tunnel escape

A research agent tunneled past its sandbox's network filter through DNS queries.

Monitoring flagged it in minutes; the process ran for hours more. OpenAI paused training on its most capable models pending a hardening review — the second pause in under three months.

Fortune ↗CNBC ↗
Today · Everyone shipping agents

Your agents run customer code, browse, and call tools with real credentials.

If a frontier lab's sandbox can be escaped, a default Docker container in a shared cluster will be. Isolation is now part of the product, not the infra backlog.

// Already running on Quome

Teams already run their AI workloads here.

Health, life-science, risk, venture and AI teams run single-tenant, sandboxed workloads in their own clouds on Quome today. Read the Sumato Health case study.

Sumato × Quome — Customer Story▶ CUSTOMER STORY
02 How it works

Connect your cloud. Point your agent at it.

Quome runs the control plane. The sandboxes — the compute, the network, the storage, the logs — run inside your account. Any agent that can call a CLI or an API can use them.

STEP 01

Connect your cloud, without handing over keys

Quome connects to your GCP, AWS or Azure project through Workload Identity Federation. No long-lived credentials are stored on our side; access is scoped, logged and revocable in seconds.

STEP 02

Your agent asks for a sandbox

From Claude Code, a custom agent loop, or a workflow: quome sandbox create --network isolated. Each request gets a fresh microVM in your VPC with the network policy you chose.

STEP 03

The run ends. The box is gone.

Code executes, results land in your bucket or database, and the VM is destroyed. Every command, every egress attempt and every secret access is in your audit log.

Sandboxes TerminalNetworkSecretsAuditSecurityMCP quome-gcp2 · GCP⚡ template: Code Write
● Real product recordingWIF · no stored keys⊞ Your VPCClaude Code · Codex · Gemini CLI
Recorded in the Quome console: choosing a sandbox template, picking the agent it launches with, and creating an isolated microVM in a connected GCP project.See it live →
A1

Any agent, any harness

Claude Code, the OpenAI Agents SDK, LangGraph, your own loop. If it can shell out or call an API, it can run in a Quome sandbox.

A2

Live preview URLs

Every sandbox can expose a preview URL for the thing the agent built — behind your auth, inside your VPC.

A3

Model gateway & MCP

An OpenAI-compatible gateway for Claude, GPT and Gemini plus MCP tools, so the agent inside the box reaches models without reaching the internet.

A4

Your data, your bucket

Inputs and outputs stay in your storage and your database. Quome never stores your data.

03 What's inside the wall

Isolation you can show a CISO.

Every control below is on by default for every sandbox. Nothing here is an enterprise add-on.

01

MicroVM per run

Hardware-isolated microVMs, not shared-kernel containers. One run, one VM, no neighbors.

Default
02

Network policy: isolated / outbound / full

Pick per sandbox. Isolated means no outbound path at all — there is no filter to tunnel through.

Isolated by default
03

Ephemeral by design

Sandboxes carry a TTL and are destroyed when the run ends. Nothing persists unless the agent writes to your storage.

Default
04

Your VPC, your account

Per-run VPC isolation inside your own GCP, AWS or Azure project. The blast radius is bounded by your policies, not a vendor's.

BYOSA
05

Zero stored credentials

Workload Identity Federation end to end. Secrets are injected at runtime from your Secret Manager or Key Vault and revoked on exit.

Default
06

Customer-owned encryption

AES-256-GCM with KMS keys you control. Dedicated database and cache per organization.

Default
07

Audit log for every run

Commands, egress attempts, secret access and lifecycle events, written to logs you own. Fine-grained authorization via SpiceDB.

Default
08

Scanned, signed supply chain

Container scanning, SBOMs for every image, and SLSA Level 3 signing so what runs in the box is what you approved.

Default
09

Compliance posture built in

HIPAA-aligned platform with a BAA on Enterprise for eligible services. SOC 2 Type I audit in progress. MFA / WebAuthn and SSO. A pre-filled security questionnaire is ready for your review on our security page.

Enterprise
04 Why ours holds

We built a whole cloud platform on these sandboxes first.

The sandbox is the product. The rest of Quome exists to prove it works: our own development platform, our own deployments and our own agents all run inside the same isolation you get.

A secure development platform, built in agent sandboxes, for services that run in sandboxes.

Quome's own prompt-to-app builder runs every generation and every build step inside these microVMs. In production, on the same isolation model we sell.

A cloud architecture built to sandbox your current cloud — instantly.

Multi-cloud from day one: the same sandbox plane, the same API and the same policies on GCP, AWS and Azure. Connect the account you already have; keep your committed-use discounts.

A forward-deployed engineering team will set it up for you.

Quome engineers and security experts connect your cloud, deploy the sandbox plane into your VPC, wire it to your agent framework and hand you the security review pack. Days, not quarters.

05 Who it's for

If your product runs an agent, this is your problem too.

Teams shipping agents to customers

Your agent executes code on behalf of strangers.
Give it its own walls.

Coding agents, workflow agents, browsing agents — they all run untrusted code with real credentials. A shared sandbox farm makes every customer a neighbor. A Quome sandbox gives each run a microVM in your own cloud, so a tenant escape is not a company-ending event.

  • 01Drop-in from any harness. CLI and API from Claude Code, the OpenAI Agents SDK, LangGraph or your own loop.
  • 02Per-run isolation, per-run policy. Isolated for untrusted code, outbound for fetches, full only when you say so.
  • 03Answer the security questionnaire enterprise buyers send before they sign, with your infrastructure instead of a vendor's.
Security & incident-response vendors

You run the riskiest agents of all. Contain them.

Red-team agents, exploit reproduction, malware analysis, automated incident response — the workloads your product runs are the ones a sandbox escape hurts most. Run them in customer-owned microVMs with no egress and a full audit trail, and make containment part of your pitch.

  • 01No-egress execution for detonation and analysis, with a per-run VPC and destroy-on-exit.
  • 02Deploy into the customer's cloud for the accounts that will never send data to yours.
  • 03Evidence, not assurances. Signed images, SBOMs, and logs the customer's SOC can read.
Enterprises in regulated industries

Security said no to agents. This is how it says yes.

Your data science and innovation teams want agents on real workflows; your CISO wants them nowhere near production. A sandbox plane inside your own cloud account, with your KMS keys, your VPC and your audit logs, is the version of "yes" that survives the review.

  • 01Single-tenant by construction. Your account, your keys, your logs. Nothing on Quome's side to breach.
  • 02HIPAA-aligned platform, BAA on Enterprise, SSO / SAML, MFA and a pre-filled questionnaire.
  • 03Forward-deployed engineers who have sat on your side of the procurement table.
06 Compare

Hosted sandbox APIs run in their cloud. Quome runs in yours.

The difference is not features. It is where the blast radius lives and whose name is on the security review.

Quome Agent SandboxHosted sandbox APIsDIY containers
Where code runsYour GCP, AWS or Azure accountThe vendor's cloudYour cloud
Isolation unitMicroVM per run, destroyed on exitVaries by vendor and planShared-kernel containers unless you build more
EgressPer-sandbox policy: isolated (none), outbound, or fullTypically allow-by-default with filtersWhatever you configure and maintain
Credentials in the boxNone stored; injected at runtime via WIF, revoked on exitA vendor API key opens every sandboxLong-lived keys in environment variables
Data planeYour VPC, your storage, your KMS keysVendor-operated, multi-tenantYours
ComplianceHIPAA-aligned, BAA on Enterprise, audit logs, SOC 2 Type I audit in progress, pre-filled questionnaireThe vendor's certificates, the vendor's data planeYours to build and prove
Time to productionDays, with a forward-deployed teamSelf-serve; enterprise deployment on requestMonths of platform work
07 Set up for you

We stand it up in your cloud.

You do not need a platform team to get this right. Quome's forward-deployed engineers and security experts deploy the sandbox plane into your account, integrate it with the agents you already run, and hand you the keys and the evidence.

Platform engineersSecurity expertsDedicated engineering lead
MinutesTO CONNECT YOUR CLOUD
DaysTO PRODUCTION
YoursKEYS, LOGS, INFRA
01
Connect your cloudWorkload Identity Federation · no keys handed over
You
02
Deploy the sandbox planeMicroVM pool, isolated VPC, KMS and audit sinks in your account
With you
03
Wire in your agentsCLI / API integration with your harness · network policies per workload
With you
04
Security review packArchitecture, shared-responsibility model, pre-filled questionnaire
With you
05
You own itYour keys, your infrastructure, your logs · we operate the control plane
Yours
08 Pricing

One flat fee. Unlimited sandboxes.

Sandbox compute runs in your account at your cloud's published rates. Quome adds zero markup, and you keep your existing discounts.

Trial
Free / 30 days
A guided 30-day pilot: real agent workloads in sandboxes inside your own cloud. No commitment.
  • Sandboxes in your own cloud
  • All network policies and audit logging
  • 5-minute setup script
Team
$5K / year
Startups and agent teams. Up to 10 members, $500/mo cloud budget.
  • Unlimited sandboxes
  • MicroVM isolation, per-run network policy
  • Model gateway, MCP tools, secrets, storage
  • Cloud billing pass-through, zero markup
Enterprise
$25K / year
Regulated industries and security vendors. Up to 25 members, unlimited cloud budget.
  • Everything in Team
  • Signed BAA for HIPAA Eligible Services, SSO / SAML
  • Forward-deployed setup in your cloud
  • Security review pack, invoicing, PO and MSA
  • Dedicated engineering lead
Need sandboxes in more than one cloud, or a private deployment for your customers' accounts? Talk to sales.
09 Why trust us

We help write the standards agents get measured against.

AI containment is not a feature we bolted on after the headlines. It is the field we work in.

Core contributors to AISVS

We help author the AI Security Verification Standard — the framework AI systems are measured against. We build to it because we help define it.

OWASP AISVS on GitHub ↗

Directing the Proof of Control standard

We help direct the Advanced AI Society's Proof of Control standard — how AI systems prove they stay under human control. Sandboxing is where that proof starts.

Read the standard ↗ advancedaisociety.org ↗

Founders of the Healthcare AI Agents Task Force

We created the Task Force for AI Agents in Healthcare — setting the bar for how agents are deployed safely in clinical settings.

aihealthagents.org ↗

We come from enterprise — we know the blockers

Built by people who have shipped inside regulated enterprises. Quome is designed around the procurement, security-review and compliance walls we hit ourselves.

Security & audit status ↗ Sumato case study ↗
// Make the case

Not the one who signs off? Send this to security.

Pick your angle and copy a ready-to-send email. We wrote the hard part — add names and hit send.

New message
Tociso@ourcompany.com
Subject
// Start today

Put a wall around every agent run.

Connect your cloud and run your first agent in an isolated sandbox this week. A guided 30-day pilot, no credit card, and your data never leaves your account.

Get the security review pack
Your cloudMicroVM per runNo egress by defaultSet up for you
// Questions

What security teams ask first.

Inside your own cloud account. Quome uses a Bring Your Own Service Account (BYOSA) model: the microVMs, the VPC, the storage and the logs live in your GCP, AWS or Azure project. Quome operates the control plane that schedules and monitors them. There is no Quome-side data plane to breach.
Each run gets a hardware-isolated microVM with its own network policy, destroyed when the run ends. Network policy is chosen per sandbox: isolated (no outbound path), outbound (egress allowed, inbound blocked) or full. Images are scanned, carry SBOMs and are signed at SLSA Level 3. Secrets are injected at runtime through Workload Identity Federation and revoked on exit.
Yes. Sandboxes are created and driven through the Quome CLI and API, so anything that can run a command or make an HTTP call can use them: Claude Code, the OpenAI Agents SDK, LangGraph, Temporal workflows or a hand-rolled loop. An OpenAI-compatible model gateway and MCP tools are available inside the sandbox, so agents can reach models without reaching the open internet.
Not in a sandbox today. Interactive sandboxes, MCP tools and the model gateway are not yet on our HIPAA Eligible Services list, so do not place PHI in them. Enterprise includes a Business Associate Agreement covering the platform services on that list, with customer-controlled KMS encryption, per-tenant isolation and audit logging. Our SOC 2 Type I audit is in progress; the current status is on the security page. If you need PHI in agent workloads, talk to us about a scoped engagement.
Connecting your cloud takes minutes with the setup script. For Enterprise, our forward-deployed engineers deploy the sandbox plane into your VPC, integrate it with your agents and deliver the security review pack, typically in days rather than quarters.
Free for 30 days. Team is $5K/year (up to 10 members, $500/mo cloud budget) and Enterprise is $25K/year (up to 25 members, unlimited cloud budget, BAA, SSO and forward-deployed setup). Both include unlimited sandboxes. Cloud compute is billed by your provider at published rates with zero markup.
No. Your inputs, outputs, secrets and logs stay in your account. Quome's control plane holds scheduling metadata and telemetry needed to operate and secure the service, not your data. Access to your cloud is federated, scoped, logged and revocable by you in seconds.