Security
AIec runs code written by autonomous agents. That code is treated as hostile, and the isolation boundary is the product.
The boundary
tenant A sandbox ─┐
├─ microVM: own kernel, own filesystem, own netns
tenant B sandbox ─┘
│
├─ vsock control channel (never on the network)
└─ egress filtered by nftables policy
Firecracker, always, for untrusted code
Public workloads run in microVMs with their own guest kernel. A tenant cannot request a weaker runtime and downgrade their own isolation. Docker remains available only for trusted self-hosted deployments and local development.
Nothing shared
Each sandbox gets its own kernel, root filesystem and network namespace. A bug in one guest does not reach another guest, and the host kernel is not exposed to the workload at all.
Filtered egress
A sandbox cannot reach the host LAN, RFC1918 ranges, link-local and cloud metadata addresses, the control plane, worker management endpoints, or another tenant. Restricted network mode fails closed rather than silently allowing traffic.
Tenancy is enforced server-side
Every tenant-scoped query is filtered by the authenticated tenant.
Possession of a sandbox ID does not grant access to it; guessing another
tenant's ID returns 404, not their data.
Credentials
- API keys are stored hashed and compared in constant time.
- Keys are shown once, scoped, rotatable and revocable.
- Secret values never appear in logs, metadata, snapshots, error messages or audit records.
- Transient in-sandbox secret material is destroyed with the sandbox.
Abuse resistance
Quotas
Per-tenant limits on active sandboxes, vCPU, memory and disk, enforced at placement time under a database lock.
Rate limits
Per-tenant and per-address admission control on the public API, with
429 and a Retry-After header.
Budget ceiling
A global execution budget stops new creation rather than allowing a runaway agent to become a charge.
Reporting a vulnerability
Do not open a public issue. Email security@gobrowse.dev with what an attacker can do, how to reproduce it, the affected component and version, and any request IDs (with secrets redacted). We acknowledge within 3 business days and triage within 7.
There is no bug bounty. Our full policy, including known limitations, is in SECURITY.md.
Known limitations
We would rather list these than have you find them. The current ones, and what is not yet enforced, are in SECURITY.md and summarised on the status page.