Skip to main content

Run agents your
security team can sign off on.

Every agent session runs in its own Firecracker microVM. Control egress per sandbox and keep credentials outside the guest. Run in E2B Cloud or in your own AWS or GCP account.

  • SOC 2 Type II
  • BYOC on AWS and GCP
  • Apache-2.0 runtime
  • 1B+

    sandboxes started

  • 10M+

    monthly SDK downloads

  • 94

    of the Fortune 100 signed up

  • AWS · GCP

    BYOC in production

Trusted in production by

  • Genspark
  • Hugging Face
  • Meta
  • The Access Group
  • Manus
  • Lindy
  • Groq
  • Gumloop
  • Rogo
  • Dust
  • Xiaomi
View all customers →
Security

Untrusted code.
Its own kernel.

Each control below is in the docs. The runtime is Apache-2.0, so your team can read what it is approving.

Isolation

A microVM with its own kernel per session. A kernel exploit inside the sandbox still needs a Firecracker escape to reach the host.

Docs

Network

Egress allow and deny per sandbox. Your own proxy, in private beta. Public URLs can require a token.

Docs

Secrets

Values resolve at egress. No API response, log, or sandbox holds them.

Observability

Metrics and logs to your OTLP endpoint. Every lifecycle event as a signed webhook.

Compliance

SOC 2 Type II. Reports and DPA in the trust center. HIPAA BAA on request.

Trust center

Runtime Apache-2.0 · The only open-source hosted microVM sandbox platform · security@e2b.dev

Visit the trust center
Deployment

Same API.
Your boundary.

Run the data plane where your data must stay. Use the same SDK, CLI, and API across every deployment option. Change deployment without rewriting your integration.

E2B Cloud · Available
E2B control plane. Data plane · US, EU, APAC
Data path
Google Cloud, operated by E2B. One microVM per session.
Keys and storage
Managed by E2B on Google Cloud
Provisioning
Sign up
Best for
Most teams start here

Azure BYOC in progress · Private cloud and on-prem design partners welcome · The open-source infra repo self-hosts with Terraform today. Embed is its single-node package.

Talk BYOC with an engineer
Security overview

What the security review asks.

The controls behind the answers.

Shared by E2B Cloud and BYOC.

Shared security controls

  • Control outbound requests.

    Allow or deny by IP, CIDR, or domain.

    Self-run SOCKS5 proxy: private beta. Fails closed.

  • Resolve secrets at egress.

    Short-lived OIDC identity tokens.

    OIDC identity is in private beta.

  • Observe session activity.

    OTLP metrics and logs on Enterprise, with signed lifecycle webhooks.

    Telemetry uses best-effort delivery.

  • Give reviewers the evidence.

    SOC 2 Type II report, penetration test report, and DPA in the Trust Center.

    HIPAA BAA and questionnaire on request.

Where the deployments differ.

TLS in transit on both deployments.

Network placement

E2B Cloud

E2B-managed infrastructure

BYOC

Your VPC

Internal load balancer and VPC peering

Regions

E2B Cloud

US, EU, and APAC

BYOC

Your region

Encryption at rest

E2B Cloud

Google Cloud default encryption

BYOC

Your own controls

Provisioning

E2B Cloud

Managed service

BYOC

Terraform and machine images

E2B provisions and monitors the cluster

SLA and support terms are set in your Enterprise agreement. Discord and support@e2b.dev on every plan.

SSO, SCIM, and RBAC are planned. Ask about timelines.

Have a questionnaire?

Send it before the call.

Open Trust Center
How teams buy
  • Usage-based

    Start on Hobby or Pro. Billed per second for CPU and RAM while a sandbox runs. Paused sandboxes are not billed.

    See pricing
  • Committed use

    A one-year minimum usage commit. Higher concurrency at lower rates, custom session length and resources, and an Enterprise agreement with SLA and support terms.

  • BYOC

    Enterprise plan. E2B provisions and operates the cluster in your AWS or GCP account.

Talk to engineers, not a sales funnel.

The first call is with an engineer who can answer your security and scale questions.

  • An architecture review for your boundary: Cloud, BYOC, or private.
  • Your security questionnaire, answered by the engineers who built the isolation.
  • Pricing for your concurrency and regions.

in production · 1B+ sandboxes started