Features
Everything an agent needs to work like an engineer.
A real machine, a disk that remembers, a browser that renders, and a network that only goes where you allow. Built for software that runs itself.
Persistent disks
Everything under /workspace survives sleeps, restarts and redeploys. Encrypted at rest, replicated across zones.
Instant snapshots
Fork a running machine in under a second. Branch an agent’s state, try something risky, roll back if it fails.
Headful browser
A real Chromium with a display, not a headless shim. Agents click, scroll and read what a human would see.
Private networking
Egress‑filtered by default. Allow the domains an agent may reach and block everything else.
Secrets and auth
Inject credentials at boot without ever exposing them to the model. Rotate keys without redeploying.
Scheduled wake
Machines sleep when idle and wake on a cron, a webhook or the first request. Pay only while awake.
Under the hood
A microVM, not a container. Hardware isolation with container‑like boot times.
hypervisor
Firecracker · KVM
guest kernel
Linux 6.8 · hardened
cold boot
≈ 400 ms
wake from sleep
≈ 40 ms
regions
iad · sfo · fra · sin
compliance
SOC 2 Type II · GDPR
Integrations
Works with the agent stack you already run. Any MCP client, any framework, any language.
claude
codex
cursor
langchain
github actions
vercel
slack
linear