Isolated sandboxes
Agent sandboxes run in isolated GKE containers on GCP — separate from the control plane and from other tenants.
Auteryn is built for production use with encryption, isolation, and access controls. This page describes our security practices — for enterprise compliance requirements, contact security@auteryn.ai.
In transit:
At rest:
Isolated sandboxes
Agent sandboxes run in isolated GKE containers on GCP — separate from the control plane and from other tenants.
Network boundaries
The agent runtime (AWS) talks to the sandbox control plane (GCP) over HTTPS. Sandboxes do not access your local network.
Resource limits
Sandboxes enforce filesystem boundaries (/workspace) and block destructive system commands.
Authentication:
sk_live_...) exchanged for scoped agent JWTswk_pub_...) restricted by domain allowlistAuthorization:
If you discover a security issue: