Transient MicroVM lifecycle
Boot guest → run one tool command with limits → stream logs → destroy. No long-lived multi-tenant VM service.
Under Validation
A Linux CLI that boots Firecracker or QEMU in under a second, runs untrusted agent commands with CPU/memory throttling, and destroys the guest when the tool returns. No cloud, no shared daemon.
Concept validation only. No payment, no commitment, no recurring newsletter.
Proposed workflow
Honest scope: Linux/KVM first. Boot-time and agent-framework adapters are still open questions.
Boot guest → run one tool command with limits → stream logs → destroy. No long-lived multi-tenant VM service.
Optional read-only bind of the workspace; writes stay in the guest unless you explicitly promote an artifact.
No telemetry backend. You keep the binary and the policy files on your machine.
The honest status
The concept is being validated before development time is committed. Joining tells us the problem is relevant to you and gives you first access if the evidence supports a build.
Before you decide
The current scope, privacy model, and next step without launch-day promises.
Not in the first design. Firecracker needs KVM. macOS would need a different backend (e.g. lightweight VM) and is out of scope for the smoke test.
No. It targets a harder isolation boundary for untrusted agent tool runs. If containers already meet your threat model, you may not need it.
No. Isolation quality depends on host KVM, guest image, and policy. Human review of agent actions remains required.
Your email is recorded for this experiment only. You receive one relevant update or beta invitation if the concept moves forward.
Early access
Join the waitlist. No spam — one update if we ship a Linux beta.
Leave your email to receive the beta invitation if this concept moves forward.