Write jail + no network
Ephemeral unprivileged namespace: read input path, write only the designated output, network off by default.
Under Validation
A drop-in Linux wrapper with a pre-tuned bubblewrap/seccomp profile for media I/O paths. No gVisor. No custom DevOps week. Not a general-purpose sandbox.
Concept validation only. No payment, no commitment, no recurring newsletter.
Proposed workflow
Honest scope: FFmpeg-only. Speed and drop-in UX are the wedge; durable advantage has to come from search position, not the recipe itself.
Ephemeral unprivileged namespace: read input path, write only the designated output, network off by default.
Optional device map for GPU encoders where the host already has working NVENC/VAAPI — not a WASM codec detour.
Replace the ffmpeg binary name in your subprocess call. No rewrite of your media pipeline.
The honest status
The concept is being validated before development time is committed. Joining tells us the problem is relevant to you and gives you first access if the evidence supports a build.
Before you decide
The current scope, privacy model, and next step without launch-day promises.
Functionally the isolation primitive is bubblewrap. The product hypothesis is an opinionated FFmpeg media profile plus packaging. Free gists may be enough for many teams — this waitlist tests whether anyone still wants a maintained package.
No. Sandboxing reduces blast radius from malicious media; it does not patch FFmpeg itself. Keep FFmpeg updated.
No. The concept should state its limits clearly and preserve human review wherever judgment is required.
Your email is recorded for this experiment only. You receive one relevant update or beta invitation if the concept moves forward.
Early access
Join the waitlist. Planned pricing €9–€29/mo if demand clears the bar — no charge today.
Leave your email to receive the beta invitation if this concept moves forward.