Dock vs boat
boat and Dock share the same machine model: a persistent Ubuntu VM with SSH, Docker, a desktop, and forks. Dock adds the controls around the guest that boat leaves to you.
Side by side
boat in its own words: “The cheapest, most powerful sandbox for agents, built for agent factories.”
| Capability | Dock | boat |
|---|---|---|
| Isolation | Firecracker microVMs on KVM bare metal (Standard, Premium); gVisor containers for the Nano tier. | Full VM with its own kernel on dedicated hosts, with a cloud VM fallback when capacity is short. |
| Persistence | Archive snapshots the filesystem; resume keeps the same dock identity. Stopped docks incur no compute charge. | Stop snapshots the disk; resume behaves like a reboot. Default auto-stop TTL can be disabled. |
| Snapshots and forks | Branch any snapshot into independent, writable docks with recorded lineage. | Fork, named snapshots, templates, and downloadable snapshots. |
| Docker inside | Root, systemd, and Docker inside every dock. | Docker with BuildKit, root, systemd, and nested KVM. |
| SSH | Native SSH and SCP, plus REST, TypeScript and Python SDKs, and the dock CLI. | Native SSH to a dedicated IPv4 or IPv6 address. |
| Desktop | Full desktop or browser-only sessions with control locking for human takeover. | 60fps desktop over Moonlight or noVNC. |
| Network egress | Deny by default on every dock; allowed destinations set per Environment, enforced on the host. | No platform egress policy; add your own controls inside the VM. |
| Secrets | Vault Gateway: the agent uses an approved credential without the secret entering the guest. | Environment variables and files are injected into the sandbox, or withheld entirely. |
| Audit | Flight Recorder: runs, prompts, commands, file changes, network decisions, and cost in one timeline. | Event stream, signed webhooks, and per-sandbox usage. |
| Status | Preview. Pricing is preview packaging. | Available with published pricing; SOC 2 in progress. |
Where Dock is different
- Policy enforced by the platform
- Dock denies egress by default on the host, where root inside the guest cannot change it.
- Use without reading
- Vault Gateway lets an agent use a credential without the secret ever being readable in the guest.
- A record and a budget
- Flight Recorder timelines plus workspace roles, budgets, and approvals for fleets of agent machines.
Where boat is strong
- Shipping today
- boat is available now with built-in agent harnesses and a published API.
- Aggressive pricing
- Low published hourly rates, and stopped sandboxes are free.
Choose Dock if
your agents touch real credentials, private systems, or customer data and you need egress policy, brokered secrets, and an audit trail.
Choose boat if
you want the same machine model available today at a low published price and will manage guardrails yourself.
Tell us what your agents need to run.
Private beta is open. Describe your workload and we will reply about access.