Evidence: Product Site · Case Study · Clean-room Demo
A coding agent needs more than a container process. It needs a workspace, interactive terminal, long-running processes, a browser, preview routing, network policy, pause/resume behavior, audit events, and a recovery story when a worker disappears.
Agent / user / SDK
│
control plane: auth · lifecycle · routing · audit
│
worker: process supervisor · PTY · browser · preview
│
runtime: OCI bundle · namespaces · cgroup v2 · seccomp
│
workspace volume + runtime metadata + append-only events
The control plane decides who may do what and where a sandbox lives. The worker executes. The runtime constrains. Workspace bytes are not confused with control-plane metadata.
The following is a self-reported inventory from a local private-code review on 2026-09-06. It includes OCI/runc execution; mount, PID, network, IPC, and UTS namespaces; cgroup v2 resource controls; a read-only root with a writable workspace; reduced capabilities; NoNewPrivileges; a default seccomp allowlist; offline, restricted-egress, and full-egress modes; lifecycle/process/filesystem APIs; PTY; Chromium/CDP; and signed preview URLs.
Public readers cannot independently verify this inventory, so it is not presented as public implementation evidence.
| Failure | Required behavior |
|---|---|
| Worker heartbeat expires | Reassign only when storage is shared, a live target exists, and cooldown permits it. |
| Network policy is restrictive | Preserve required DNS behavior while denying other egress. |
| Preview token leaks | Limit it to one sandbox and port; never authorize control APIs. |
| Browser or dev server is still running | Pause/resume and process state must remain explicit. |
| Runtime isolation is insufficient | Route to a stronger isolation tier or refuse the workload. |
gVisor and Firecracker are stronger-isolation directions, not current public capabilities. Multi-node high availability and safe execution of arbitrary hostile code are also outside the claim.
The Talon Sandbox product site publicly exposes the product positioning plus documentation, Playground, and sign-in entry points. Site copy is not treated as independent implementation proof.
The Evidence Lab uses synthetic data to demonstrate lifecycle, policy, worker-loss, retry, evidence, and acceptance behavior. It copies no private source and does not pretend to be the production sandbox.
Security-boundary reasoning, runtime lifecycle design, Linux isolation primitives, browser/PTY/workspace product integration, recovery policy, and honest capability disclosure.