Zerobox is a lightweight, cross-platform process sandboxing powered by OpenAI Codex's sandbox runtime. Single binary, no Docker, no VMs with ~10ms overhead.
Zerobox offers deny by default security policy, credential injection, file access control and network filtering which lets you allow or deny outbound traffic by domain.
Zerobox also offers SDKs for Rust, TypeScript, and Python with a consistent API across languages.
ClawRun deploys AI agents into secure, isolated sandboxes with one command. No infrastructure to build.
Agents need to run code, browse the web, and manage files — but you can't give them your server. ClawRun gives each agent its own Firecracker microVM with configurable network policies, and manages the full lifecycle.
One command sets up everything: sandbox, webhook routing from Telegram/Discord/Slack, LLM cost tracking with budget enforcement.