Deny by default. Allow on purpose.
An agent with open internet access can leak data or pull in anything. Dock starts from deny-by-default egress and lets you allow exactly the destinations a workload needs.
- Enforced outside the guest
- Policy lives on the host, so root inside the dock cannot turn it off.
- Per environment
- Attach allowed destinations to an Environment and every dock created from it inherits the rules.
- Every decision recorded
- Permitted and blocked connections both land in Flight Recorder.
- Previews on your terms
- Expose ports as private preview URLs instead of opening the machine to the internet.
Questions
Can an agent with root bypass network policy?
No. Policy is enforced on the host outside the guest, not by software the agent can modify.
Use cases that fit
Coding agents
Run coding agents like Claude Code, Codex, and OpenCode in isolated, repository-aware Linux machines with Docker, previews, and cheap branches.
Learn moreBrowser and computer use agents
Keep Chrome profiles, logins, and session state on a persistent dock, with a live desktop for human takeover when the workflow needs judgment.
Learn moreQA and preview environments
Build branches, run services, expose private preview URLs, and keep screenshots, logs, and artifacts on a persistent dock per change.
Learn moreInternal agent platforms
Connect agents to internal tools and private systems with deny-by-default egress, brokered credentials, approvals, and a full audit trail.
Learn moreAgent evaluations
Branch one snapshot into many identical docks to run agents, prompts, or models side by side and compare results fairly.
Learn more
Tell us what your agents need to run.
Private beta is open. Describe your workload and we will reply about access.