Skip to content

Security model

Sandbox Loom treats generated code and sandbox contents as untrusted. The control plane remains authoritative, and the disposable execution plane receives only the capabilities needed for the current workflow.

Trust boundaries

flowchart LR
  Policy[Policy and audit authority] -->|authorized request| Gateway[Gateway / brokers]
  Gateway -->|bounded operation| Executor[Sandbox executor]
  Executor --> Workspace[Untrusted code and artifacts]
  Gateway --> External[External systems]
  Human[Human approval] --> Policy

The sandbox cannot acquire authority merely because a process, file, or network primitive exists inside it.

Responsibility boundary

Sandbox Loom supplies the control points and evidence model; operators remain responsible for choosing the repositories, profiles, credentials, external systems, retention period, and approval policy placed in scope. A configured capability is not automatically an authorized capability for every workflow.

Reviewers should be able to trace a consequential operation through the selected profile, policy decision, gateway or broker, sandbox session, result, and audit or acceptance evidence. If that trace is unavailable, the operation should be treated as unverified.

Default protections

  • workspace-only writable mount;
  • read-only root filesystem;
  • isolated namespaces and bounded CPU, memory, and PID resources;
  • dropped Linux capabilities and noNewPrivileges;
  • no host home, SSH, cloud credential, browser profile, or Docker socket mounts;
  • explicit policy profile and identity binding;
  • short-lived credential leases rather than raw secrets;
  • feature-branch-only automated Git pushes;
  • human escalation for protected operations.

Fail-closed behavior

Unknown capabilities, invalid paths, profile mismatches, unavailable capabilities, conflicting constraints, failed required audit writes, invalid approvals, and unavailable required runtimes are errors or denials. They do not silently broaden access.

The security model is a shared responsibility: Sandbox Loom provides boundaries and evidence, while operators choose the policies, resources, repositories, and external systems placed in scope.