The agent sandbox
that runs in your own cloud.
Every agent run gets its own isolated microVM, deployed inside your GCP, AWS or Azure account — never ours. No outbound network unless you allow it, zero stored credentials, and an audit trail for every run. Our forward-deployed engineers stand it up in your cloud for you.
The story behind Quome, straight from Demo Day.
Our CEO/CTO on stage at Betaworks Demo Day — the problem, the vision, and why software in regulated industries should be as fast to build as it is safe to run.
The frontier labs' own sandboxes didn't hold.
Twice in three months, OpenAI paused frontier training because agents got out of their containment. If you are shipping agents to customers, sandboxing just moved to the top of the list.
An agent that can write and run code will eventually probe the walls around it. The question is whether the walls are yours, in your cloud — or a filter someone else runs.
The September escape went out through DNS — a hole in a network filter. The summer incident went out through exposed credentials and shared infrastructure. Both are exactly the surfaces a Quome sandbox is built to remove: a policy of no egress at all instead of an allow-list, no long-lived keys inside the box, and a fresh microVM per run that is destroyed when the run ends.
Quome does not sell you a shared sandbox farm. It deploys the sandbox plane into your own cloud account, so the blast radius is bounded by your VPC and your policies — and the security review is about your infrastructure, not ours.
~1,200 OpenAI eval agents broke containment and attacked Hugging Face.
Agents in an internal evaluation with reduced safety measures used exposed credentials and zero-days to reach outside infrastructure, and coordinated with each other on the way out.
Axios ↗Fortune ↗A research agent tunneled past its sandbox's network filter through DNS queries.
Monitoring flagged it in minutes; the process ran for hours more. OpenAI paused training on its most capable models pending a hardening review — the second pause in under three months.
Fortune ↗CNBC ↗Your agents run customer code, browse, and call tools with real credentials.
If a frontier lab's sandbox can be escaped, a default Docker container in a shared cluster will be. Isolation is now part of the product, not the infra backlog.
Teams already run their AI workloads here.
Health, life-science, risk, venture and AI teams run single-tenant, sandboxed workloads in their own clouds on Quome today. Read the Sumato Health case study.
Connect your cloud. Point your agent at it.
Quome runs the control plane. The sandboxes — the compute, the network, the storage, the logs — run inside your account. Any agent that can call a CLI or an API can use them.
Connect your cloud, without handing over keys
Quome connects to your GCP, AWS or Azure project through Workload Identity Federation. No long-lived credentials are stored on our side; access is scoped, logged and revocable in seconds.
Your agent asks for a sandbox
From Claude Code, a custom agent loop, or a workflow: quome sandbox create --network isolated. Each request gets a fresh microVM in your VPC with the network policy you chose.
The run ends. The box is gone.
Code executes, results land in your bucket or database, and the VM is destroyed. Every command, every egress attempt and every secret access is in your audit log.
Any agent, any harness
Claude Code, the OpenAI Agents SDK, LangGraph, your own loop. If it can shell out or call an API, it can run in a Quome sandbox.
Live preview URLs
Every sandbox can expose a preview URL for the thing the agent built — behind your auth, inside your VPC.
Model gateway & MCP
An OpenAI-compatible gateway for Claude, GPT and Gemini plus MCP tools, so the agent inside the box reaches models without reaching the internet.
Your data, your bucket
Inputs and outputs stay in your storage and your database. Quome never stores your data.
Isolation you can show a CISO.
Every control below is on by default for every sandbox. Nothing here is an enterprise add-on.
MicroVM per run
Hardware-isolated microVMs, not shared-kernel containers. One run, one VM, no neighbors.
DefaultNetwork policy: isolated / outbound / full
Pick per sandbox. Isolated means no outbound path at all — there is no filter to tunnel through.
Isolated by defaultEphemeral by design
Sandboxes carry a TTL and are destroyed when the run ends. Nothing persists unless the agent writes to your storage.
DefaultYour VPC, your account
Per-run VPC isolation inside your own GCP, AWS or Azure project. The blast radius is bounded by your policies, not a vendor's.
BYOSAZero stored credentials
Workload Identity Federation end to end. Secrets are injected at runtime from your Secret Manager or Key Vault and revoked on exit.
DefaultCustomer-owned encryption
AES-256-GCM with KMS keys you control. Dedicated database and cache per organization.
DefaultAudit log for every run
Commands, egress attempts, secret access and lifecycle events, written to logs you own. Fine-grained authorization via SpiceDB.
DefaultScanned, signed supply chain
Container scanning, SBOMs for every image, and SLSA Level 3 signing so what runs in the box is what you approved.
DefaultCompliance posture built in
HIPAA-aligned platform with a BAA on Enterprise for eligible services. SOC 2 Type I audit in progress. MFA / WebAuthn and SSO. A pre-filled security questionnaire is ready for your review on our security page.
EnterpriseWe built a whole cloud platform on these sandboxes first.
The sandbox is the product. The rest of Quome exists to prove it works: our own development platform, our own deployments and our own agents all run inside the same isolation you get.
A secure development platform, built in agent sandboxes, for services that run in sandboxes.
Quome's own prompt-to-app builder runs every generation and every build step inside these microVMs. In production, on the same isolation model we sell.
A cloud architecture built to sandbox your current cloud — instantly.
Multi-cloud from day one: the same sandbox plane, the same API and the same policies on GCP, AWS and Azure. Connect the account you already have; keep your committed-use discounts.
A forward-deployed engineering team will set it up for you.
Quome engineers and security experts connect your cloud, deploy the sandbox plane into your VPC, wire it to your agent framework and hand you the security review pack. Days, not quarters.
If your product runs an agent, this is your problem too.
Your agent executes code on behalf of strangers.
Give it its own walls.
Coding agents, workflow agents, browsing agents — they all run untrusted code with real credentials. A shared sandbox farm makes every customer a neighbor. A Quome sandbox gives each run a microVM in your own cloud, so a tenant escape is not a company-ending event.
- 01Drop-in from any harness. CLI and API from Claude Code, the OpenAI Agents SDK, LangGraph or your own loop.
- 02Per-run isolation, per-run policy. Isolated for untrusted code, outbound for fetches, full only when you say so.
- 03Answer the security questionnaire enterprise buyers send before they sign, with your infrastructure instead of a vendor's.
You run the riskiest agents of all. Contain them.
Red-team agents, exploit reproduction, malware analysis, automated incident response — the workloads your product runs are the ones a sandbox escape hurts most. Run them in customer-owned microVMs with no egress and a full audit trail, and make containment part of your pitch.
- 01No-egress execution for detonation and analysis, with a per-run VPC and destroy-on-exit.
- 02Deploy into the customer's cloud for the accounts that will never send data to yours.
- 03Evidence, not assurances. Signed images, SBOMs, and logs the customer's SOC can read.
Security said no to agents. This is how it says yes.
Your data science and innovation teams want agents on real workflows; your CISO wants them nowhere near production. A sandbox plane inside your own cloud account, with your KMS keys, your VPC and your audit logs, is the version of "yes" that survives the review.
- 01Single-tenant by construction. Your account, your keys, your logs. Nothing on Quome's side to breach.
- 02HIPAA-aligned platform, BAA on Enterprise, SSO / SAML, MFA and a pre-filled questionnaire.
- 03Forward-deployed engineers who have sat on your side of the procurement table.
Hosted sandbox APIs run in their cloud. Quome runs in yours.
The difference is not features. It is where the blast radius lives and whose name is on the security review.
| Quome Agent Sandbox | Hosted sandbox APIs | DIY containers | |
|---|---|---|---|
| Where code runs | Your GCP, AWS or Azure account | The vendor's cloud | Your cloud |
| Isolation unit | MicroVM per run, destroyed on exit | Varies by vendor and plan | Shared-kernel containers unless you build more |
| Egress | Per-sandbox policy: isolated (none), outbound, or full | Typically allow-by-default with filters | Whatever you configure and maintain |
| Credentials in the box | None stored; injected at runtime via WIF, revoked on exit | A vendor API key opens every sandbox | Long-lived keys in environment variables |
| Data plane | Your VPC, your storage, your KMS keys | Vendor-operated, multi-tenant | Yours |
| Compliance | HIPAA-aligned, BAA on Enterprise, audit logs, SOC 2 Type I audit in progress, pre-filled questionnaire | The vendor's certificates, the vendor's data plane | Yours to build and prove |
| Time to production | Days, with a forward-deployed team | Self-serve; enterprise deployment on request | Months of platform work |
We stand it up in your cloud.
You do not need a platform team to get this right. Quome's forward-deployed engineers and security experts deploy the sandbox plane into your account, integrate it with the agents you already run, and hand you the keys and the evidence.
One flat fee. Unlimited sandboxes.
Sandbox compute runs in your account at your cloud's published rates. Quome adds zero markup, and you keep your existing discounts.
- Sandboxes in your own cloud
- All network policies and audit logging
- 5-minute setup script
- Unlimited sandboxes
- MicroVM isolation, per-run network policy
- Model gateway, MCP tools, secrets, storage
- Cloud billing pass-through, zero markup
- Everything in Team
- Signed BAA for HIPAA Eligible Services, SSO / SAML
- Forward-deployed setup in your cloud
- Security review pack, invoicing, PO and MSA
- Dedicated engineering lead
We help write the standards agents get measured against.
AI containment is not a feature we bolted on after the headlines. It is the field we work in.
Core contributors to AISVS
We help author the AI Security Verification Standard — the framework AI systems are measured against. We build to it because we help define it.
OWASP AISVS on GitHub ↗Directing the Proof of Control standard
We help direct the Advanced AI Society's Proof of Control standard — how AI systems prove they stay under human control. Sandboxing is where that proof starts.
Read the standard ↗ advancedaisociety.org ↗Founders of the Healthcare AI Agents Task Force
We created the Task Force for AI Agents in Healthcare — setting the bar for how agents are deployed safely in clinical settings.
aihealthagents.org ↗We come from enterprise — we know the blockers
Built by people who have shipped inside regulated enterprises. Quome is designed around the procurement, security-review and compliance walls we hit ourselves.
Security & audit status ↗ Sumato case study ↗Not the one who signs off? Send this to security.
Pick your angle and copy a ready-to-send email. We wrote the hard part — add names and hit send.
Put a wall around every agent run.
Connect your cloud and run your first agent in an isolated sandbox this week. A guided 30-day pilot, no credit card, and your data never leaves your account.