Run agents your
security team can sign off on.
Every agent session runs in its own Firecracker microVM. Control egress per sandbox and keep credentials outside the guest. Run in E2B Cloud or in your own AWS or GCP account.
1B+
sandboxes started
10M+
monthly SDK downloads
94
of the Fortune 100 signed up
AWS · GCP
BYOC in production
Untrusted code.
Its own kernel.
Each control below is in the docs. The runtime is Apache-2.0, so your team can read what it is approving.
Isolation
A microVM with its own kernel per session. A kernel exploit inside the sandbox still needs a Firecracker escape to reach the host.
Docs →Network
Egress allow and deny per sandbox. Your own proxy, in private beta. Public URLs can require a token.
Docs →Secrets
Values resolve at egress. No API response, log, or sandbox holds them.
Observability
Metrics and logs to your OTLP endpoint. Every lifecycle event as a signed webhook.
Runtime Apache-2.0 · The only open-source hosted microVM sandbox platform · security@e2b.dev
Visit the trust centerSame API.
Your boundary.
Run the data plane where your data must stay. Use the same SDK, CLI, and API across every deployment option. Change deployment without rewriting your integration.
Where it runs
| Compare | E2B Cloud | BYOC | Private cloud | E2B Embed |
|---|---|---|---|---|
| Data path | Google Cloud, operated by E2B. One microVM per session. | Client to your VPC, never through E2B Cloud. Aggregate CPU and memory metrics and control-plane API traffic reach E2B. | Nothing leaves | Nothing leaves |
| Keys and storage | Managed by E2B on Google Cloud | Your IAM role, VPC, storage, and cloud audit log | Yours | Yours |
| Provisioning | Sign up | Terraform and machine images. E2B provisions, monitors, and operates the cluster. | Terraform, inside your network | One Terraform module |
| Best for | Most teams start here | Regulated data, selling into enterprises | Air-gapped, sovereign, and on-prem networks | Teams that start self-hosted |
- Data path
- Google Cloud, operated by E2B. One microVM per session.
- Keys and storage
- Managed by E2B on Google Cloud
- Provisioning
- Sign up
- Best for
- Most teams start here
Azure BYOC in progress · Private cloud and on-prem design partners welcome · The open-source infra repo self-hosts with Terraform today. Embed is its single-node package.
Talk BYOC with an engineerWhat the security review asks.
The controls behind the answers.
Shared by E2B Cloud and BYOC.
Control outbound requests.
Allow or deny by IP, CIDR, or domain.
Self-run SOCKS5 proxy: private beta. Fails closed.
Resolve secrets at egress.
Short-lived OIDC identity tokens.
OIDC identity is in private beta.
Observe session activity.
OTLP metrics and logs on Enterprise, with signed lifecycle webhooks.
Telemetry uses best-effort delivery.
Give reviewers the evidence.
SOC 2 Type II report, penetration test report, and DPA in the Trust Center.
HIPAA BAA and questionnaire on request.
Where the deployments differ.
TLS in transit on both deployments.
Network placement
E2B-managed infrastructure
Your VPC
Internal load balancer and VPC peering
Regions
US, EU, and APAC
Your region
Encryption at rest
Google Cloud default encryption
Your own controls
Provisioning
Managed service
Terraform and machine images
E2B provisions and monitors the cluster
SLA and support terms are set in your Enterprise agreement. Discord and support@e2b.dev on every plan.
SSO, SCIM, and RBAC are planned. Ask about timelines.
Have a questionnaire?
Send it before the call.
"E2B gives us a fast, secure way to run AI-generated code at scale, so we can ship workflow automation our enterprise customers trust."
Usage-based
Start on Hobby or Pro. Billed per second for CPU and RAM while a sandbox runs. Paused sandboxes are not billed.
See pricingCommitted use
A one-year minimum usage commit. Higher concurrency at lower rates, custom session length and resources, and an Enterprise agreement with SLA and support terms.
BYOC
Enterprise plan. E2B provisions and operates the cluster in your AWS or GCP account.
Talk to engineers, not a sales funnel.
The first call is with an engineer who can answer your security and scale questions.
- An architecture review for your boundary: Cloud, BYOC, or private.
- Your security questionnaire, answered by the engineers who built the isolation.
- Pricing for your concurrency and regions.