Give the agent capability. Not your keys.
Agents make mistakes and can be tricked. Dock assumes that, and puts isolation, credentials, network rules, and the audit trail outside the machine the agent controls.
Root inside a dock is root inside a dock. It does not reach the host, the network rules, the stored credentials, or the record of what happened.
Layers between the agent and everything else.
The dock runs inside its own microVM on dedicated hardware. Guardrails stand on the host, outside the glass, where the agent cannot reach them.
Isolation
The boundary between one dock and everything else.
- Standard and Premium
- Each dock is a Firecracker microVM with its own kernel, launched through the jailer on KVM bare metal. A process inside the dock, even as root, is inside a virtual machine.
- Nano
- Docks run as gVisor containers. gVisor intercepts system calls in a user-space kernel, so the dock never talks to the host kernel directly.
- Per-dock resources
- Every dock gets a guaranteed CPU and memory floor through cgroups, from small (1 vCPU, 2 GiB) to xlarge (8 vCPU, 16 GiB), so one busy agent cannot starve another.
- Host truth
- CPU, memory, and network usage are measured on the host from cgroup and network counters. A dock cannot report its own usage.
Guardrails outside the guest
Controls the agent cannot see, edit, or switch off.
- Network policyEgress is denied by default. You allow destinations per Environment, and the host enforces the rules outside the guest. Every permitted and blocked connection lands in Flight Recorder.
- Vault GatewayFor credentials an agent should use but never hold. The gateway attaches the secret to approved requests from outside the dock, so the long-lived key never enters the machine.
- Safe docksCreate a dock with noEnv and it starts with no repositories, no environment variables or files, and no account credentials. Resuming with noEnv scrubs owner secrets before the dock becomes reachable.
- Flight RecorderRuns, prompts, commands, SSH sessions, file changes, snapshots, network decisions, and cost in one ordered timeline per dock.
- Workspace controlsRoles, budgets, and approvals. Payment, account closure, identity links, and membership stay dashboard-only, out of reach of service keys.
Your data
- Stopping never loses work by accident
- If the final snapshot fails, Dock refuses to stop, keeps the dock running, and retries. Data is discarded only when you explicitly force a stop.
- Secrets stored as hashes
- Account tokens and keys are stored as one-way hashes. A raw API key is shown exactly once, when you create it.
- Hosts connect outbound only
- Sandbox hosts dial out to the control plane over authenticated channels. They expose no inbound management port.
- Deletion and retention you control
- Retention follows your plan and workspace policy, and account closure and erasure are explicit, dashboard-only actions.
Dock is in private beta. We publish isolation, retention, and compliance status only once each is verified, and we do not claim certifications we have not been audited for. Found a security issue? Email hello@usedock.io.
Running agents near sensitive systems?
Tell us what they touch. We will walk you through the controls that apply.