Agents inside the company, with guardrails outside them.
Platform teams want agents to touch real systems without handing them permanent keys or open networks. Dock puts the controls on the host, where the agent cannot switch them off.
- Deny-by-default egress
- Allow only the internal and external destinations a workload needs.
- Brokered secrets
- Vault Gateway keeps long-lived credentials outside the guest.
- Approvals and budgets
- Require a person for sensitive actions and cap spend per workspace.
- Audit for every run
- Flight Recorder gives security teams a replayable history per dock.
Features that fit
Persistent Linux computers
Full Ubuntu with root, Docker, and SSH. Files and packages stay put between tasks.
Learn moreSnapshots and branching
Copy a dock from any snapshot. Each copy is independent and remembers its parent.
Learn moreLive desktop and human takeover
Open the desktop or browser, take over from the agent, and hand it back.
Learn moreVault Gateway
Agents use API keys without ever being able to read them.
Learn moreFlight Recorder
Commands, file changes, connections, and cost in one timeline per dock.
Learn moreNetwork policy
Outbound traffic is blocked until you allow it, enforced on the host.
Learn moreWorkspace controls
Roles, budgets, and approvals for a fleet of agent machines.
Learn more
Tell us what your agents need to run.
Private beta is open. Describe your workload and we will reply about access.