







Instant Linux microVMs with defense-in-depth security for running untrusted code.
microsandbox - Every agent deserves its own machine
Run lightweight microVMs locally. Programmable networking, custom filesystems, secrets that never leak.
shuru - Local-first microVM sandbox for AI agents
Local-first microVM sandbox for AI agents on macOS, with experimental Linux ARM64 support

Why AVF?
AVF and pKVM: next-generation Trustworthy Execution Environment for connected products

Sprites - Stateful sandboxes
Persistent, hardware-isolated execution environments for arbitrary code. Run AI agents, untrusted code, and more in secure sandbox environments with checkpoint & restore.
Vercel Sandbox
Vercel Sandbox allows you to run arbitrary code in isolated, ephemeral Linux VMs.
Tock OS A Rust Based Open Platform for Transparent and Secure Root of Trust Devices
TrenchBoot Anti Evil Maid (current plan - v2) - Dasharo Universe
As Qubes OS users, promoters, and developers, we understand how essential it is to be aware of the latest developments in maintaining the security of your favorite operating system. We're excited to share our plans to integrate the TrenchBoot Project into Qubes OS's new Anti-Evil Maid (AEM) implementation. As you may know, traditional firmware security measures like UEFI Secure Boot and measured boot, even with a Static Root of Trust (SRT), may only sometimes be enough to ensure a completely secure environment for your operating system. Compromised firmware may allow for the injection of malicious software into your system, making it difficult to detect. To overcome these limitations, many silicon vendors have started implementing Dynamic Root of Trust (DRT) technologies to establish a secure environment for operating system launch and integrity measurements. We're excited to take advantage of these advancements through integration with the TrenchBoot Project.
earendil-works/gondolin
Experimental Linux microvm setup with a TypeScript Control Plane as Agent Sandbox
SGX.Fail
Intel's Software Guard Extension (SGX) promises an isolated execution environment, protected from all software running on the machine. In the past few years, however, SGX has come under heavy fire, threatened by numerous side channel attacks. With Intel repeatedly patching SGX to regain security, we set out to explore the effectiveness of SGX's update mechanisms to prevent attacks on real-world deployments.
anthropic-experimental/sandbox-runtime
A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.
Cloudblast - Pricing
Secure and scalable virtual machine hosting, featuring built-in DDoS protection to ensure continuous, safe operation for your critical applications.
Genode - Genode Operating System Framework
We understand the complexity of code and policy as the most fundamental security problem shared by modern general-purpose operating systems. Because of high functional demands and dynamic workloads, however, this complexity cannot be avoided. But it can be organized. Genode is a novel OS architecture that is able to master complexity by applying a strict organizational structure to all software components including device drivers, system services, and applications. The Genode OS framework is an open-source tool kit for building highly secure component-based operating systems. It scales from embedded devices to dynamic general-purpose computing.
TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition
Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition

Xous: A Pure-Rust Rethink of the Embedded Operating System
Xous is a message-passing microkernel implemented in pure Rust, targeting secure embedded applications. This talk covers three novel aspe...
