BetaPrivate beta is open. Teams are onboarded in stages.

Deny by default. Allow on purpose.

An agent with open internet access can leak data or pull in anything. Dock starts from deny-by-default egress and lets you allow exactly the destinations a workload needs.

Enforced outside the guest
Policy lives on the host, so root inside the dock cannot turn it off.
Per environment
Attach allowed destinations to an Environment and every dock created from it inherits the rules.
Every decision recorded
Permitted and blocked connections both land in Flight Recorder.
Previews on your terms
Expose ports as private preview URLs instead of opening the machine to the internet.

Questions

Can an agent with root bypass network policy?

No. Policy is enforced on the host outside the guest, not by software the agent can modify.

Tell us what your agents need to run.

Private beta is open. Describe your workload and we will reply about access.