Security and compliance
E2B runs untrusted, AI-generated code in isolated cloud sandboxes. This page states E2B's compliance status, what an independent auditor has verified, and how to get the underlying reports.
- Infrastructure security
- Product security
- Organizational security
- Internal security procedures
- Data privacy
One microVM per sandbox
Its own kernel. No shared filesystem or memory with another customer.
Isolation →Controls tested
across the period.
A SOC 2 Type II report tests whether controls operated effectively across an entire audit period, rather than whether they were designed correctly on a single day. When a period ends, E2B publishes a bridge letter covering the gap until the next report is issued.
The full report and the current bridge letter are available under NDA from the E2B Trust Center. SOC 2 does not certify a product; it attests that an independent auditor tested E2B's controls and found them operating as described.
E2B maintains a SOC 2 Type II report. The report is available under NDA from the E2B Trust Center, along with a current bridge letter.
HIPAA and SOC 2 questions
Yes. E2B maintains a SOC 2 Type II report. The report and a current bridge letter are available under NDA from the E2B Trust Center.
Every sandbox,
its own microVM.
Every E2B sandbox runs in its own Firecracker microVM with its own kernel. Isolation is at the hypervisor boundary, not the container or process boundary, which is what makes it safe to run untrusted or AI-generated code. Sandboxes never share a kernel, a filesystem, or memory with another customer's sandboxes.
Sandboxes are destroyed on timeout or shutdown. Filesystem and memory state can be preserved across a pause and restored on resume.
Google Cloud,
encrypted by default.
E2B's managed sandboxes run on Google Cloud. Sandbox storage sits under Google Cloud's default encryption at rest; E2B adds no encryption layer of its own and holds no key material for it. Traffic to and from sandboxes is encrypted with TLS.
Available regions, and the plan each is available on, are listed in the docs.
- Google Cloud
- Google Cloud default encryption. No E2B key material.
- TLS
Your VPC,
your controls.
BYOC deploys E2B sandboxes inside your own VPC, in your own AWS or Google Cloud account. BYOC is available on Enterprise plans. Azure is not yet supported.
For a regulated workload this means the data residency, key management, and audit logging that apply are your own. E2B's SOC 2 Type II report covers the E2B software and control plane; the cloud account it is deployed into, and that account's compliance posture, remain yours. BYOC is a managed deployment in your account, not self-hosting.
Stays in your account
Sandbox traffic, template build sources, snapshots, logs, and storage, under your own encryption, retention, and access controls.
Crosses to E2B
Control-plane calls in, over TLS. Anonymized cluster CPU and memory metrics out.
Talk to us →Continuously monitored,
independently tested.
E2B's security controls are continuously monitored with Vanta, spanning infrastructure security, product security, organizational security, internal security procedures, and data privacy. Each control and its current status are published in the E2B Trust Center.
E2B commissions independent penetration testing, and the report is available under NDA. Customer data is deleted when a customer leaves. E2B offers a Data Processing Addendum for GDPR; request the template from the Trust Center, or email trust@e2b.dev for a signed copy.
Security and compliance questions?
Email trust@e2b.dev for a BAA, a signed DPA, a completed security questionnaire, the subprocessor list, or to report a security vulnerability. Please contact us before running any test against E2B — our terms of service require prior written consent.
Email trust@e2b.dev