Enterprise control for the AI agents on every machine. Run Claude Code, Codex and others inside a kernel-isolated sandbox you fully govern — while it stays seamless for the user.
Built for the teams adopting AI agents
The runtime
A governed runtime that sits between your people and the agents — enforcing what they can reach, touch, run, and spend.
Every session runs in its own micro-VM — own kernel, no host filesystem, one network path. Secure by design, not by configuration.
Every request — and every subprocess it spawns — exits through one policy proxy. Allow domains, repos, MCP servers, and tools. Default-deny the rest.
Choose which models are allowed, cap token and dollar spend, enforce guardrails — per group, from one dashboard. Every action audited.
The control plane is SaaS; the data plane is 100% local. Policies come down, audit goes up — your code and prompts never reach our servers.
How it works
Push the sandllm client to managed devices with Jamf or Intune. One-time, invisible to the user.
The user double-clicks Claude Code as always. It opens instantly — already sealed inside a governed micro-VM.
Set policy, budgets and allowlists per team. Watch usage and audit in real time. Change anything, anytime.
The guarantee
The control plane is SaaS. The data plane — the sandbox, the agent, the traffic, the code — is 100% local on the device. Only policy comes down and audit metadata goes up. Your source and prompts never reach our servers.
Give every team the agents they want — and the control you need.