Skip to main content

Security and compliance

E2B runs untrusted, AI-generated code in isolated cloud sandboxes. This page states E2B's compliance status, what an independent auditor has verified, and how to get the underlying reports.

Trust Center · Controls
  • Infrastructure security
  • Product security
  • Organizational security
  • Internal security procedures
  • Data privacy
SOC 2 Type II · HIPAA BAA · GDPR DPAContinuously monitored
At a glance

SOC 2 Type II

Report and bridge letter under NDA, in the Trust Center.

Trust Center

HIPAA BAA

Business Associate Agreements signed on Enterprise plans.

Request a BAA

One microVM per sandbox

Its own kernel. No shared filesystem or memory with another customer.

Isolation

E2B's contracting entity is FoundryLabs, Inc., a Delaware corporation.

SOC 2 Type II

Controls tested
across the period.

A SOC 2 Type II report tests whether controls operated effectively across an entire audit period, rather than whether they were designed correctly on a single day. When a period ends, E2B publishes a bridge letter covering the gap until the next report is issued.

The full report and the current bridge letter are available under NDA from the E2B Trust Center. SOC 2 does not certify a product; it attests that an independent auditor tested E2B's controls and found them operating as described.

E2B maintains a SOC 2 Type II report. The report is available under NDA from the E2B Trust Center, along with a current bridge letter.

HIPAA and SOC 2 questions

Yes. E2B maintains a SOC 2 Type II report. The report and a current bridge letter are available under NDA from the E2B Trust Center.

Isolation and tenancy

Every sandbox,
its own microVM.

Every E2B sandbox runs in its own Firecracker microVM with its own kernel. Isolation is at the hypervisor boundary, not the container or process boundary, which is what makes it safe to run untrusted or AI-generated code. Sandboxes never share a kernel, a filesystem, or memory with another customer's sandboxes.

Sandboxes are destroyed on timeout or shutdown. Filesystem and memory state can be preserved across a pause and restored on resume.

Where sandboxes run

Google Cloud,
encrypted by default.

E2B's managed sandboxes run on Google Cloud. Sandbox storage sits under Google Cloud's default encryption at rest; E2B adds no encryption layer of its own and holds no key material for it. Traffic to and from sandboxes is encrypted with TLS.

Available regions, and the plan each is available on, are listed in the docs.

Provider
Google Cloud
At rest
Google Cloud default encryption. No E2B key material.
In transit
TLS
Bring Your Own Cloud

Your VPC,
your controls.

BYOC deploys E2B sandboxes inside your own VPC, in your own AWS or Google Cloud account. BYOC is available on Enterprise plans. Azure is not yet supported.

For a regulated workload this means the data residency, key management, and audit logging that apply are your own. E2B's SOC 2 Type II report covers the E2B software and control plane; the cloud account it is deployed into, and that account's compliance posture, remain yours. BYOC is a managed deployment in your account, not self-hosting.

Stays in your account

Sandbox traffic, template build sources, snapshots, logs, and storage, under your own encryption, retention, and access controls.

Crosses to E2B

Control-plane calls in, over TLS. Anonymized cluster CPU and memory metrics out.

Talk to us
Controls

Continuously monitored,
independently tested.

E2B's security controls are continuously monitored with Vanta, spanning infrastructure security, product security, organizational security, internal security procedures, and data privacy. Each control and its current status are published in the E2B Trust Center.

E2B commissions independent penetration testing, and the report is available under NDA. Customer data is deleted when a customer leaves. E2B offers a Data Processing Addendum for GDPR; request the template from the Trust Center, or email trust@e2b.dev for a signed copy.

Contact

Security and compliance questions?

Email trust@e2b.dev for a BAA, a signed DPA, a completed security questionnaire, the subprocessor list, or to report a security vulnerability. Please contact us before running any test against E2B — our terms of service require prior written consent.

Email trust@e2b.dev