Tech riderRev. 4 Oct 2026
Sandlock
- 1Runs onAPI, Linux, self-hosted
- 2CostsFree plan
- 3Persistent storageYes
- 4Network controlsYes
- 5API or CLI accessYes
- 6Deploymentself hosted
6 lines stated Written from the maker's own pages: sandlock.io

Overview
Sandlock is ranked #15 of 22 in sandbox software on Specifiction. It runs on API, Linux, Self-hosted. There is a free plan.
Sandlock plans and pricing
All plansSandbox HTTP API Not published Annual license Unlimited sandboxes and keys per deployment · priced by fleet size · self-hosted sandlock.io · 4 Oct 2026
Sandbox Scheduler Not published Annual license Priced by node count · self-hosted sandlock.io · 4 Oct 2026
Compared on sandbox software
- Free plan
- Yessandlock.io
- Persistent storage
- Yessandlock.io
- Network controls
- Yessandlock.io
- API or CLI access
- Yessandlock.io
- Deployment
- self_hostedsandlock.io
Facts
- Purpose
- Sandlock is a lightweight Linux process sandbox for confining untrusted code with kernel-enforced policies.sandlock.io · 4 Oct 2026
- Enforcement
- It uses Landlock, seccomp-bpf, and seccomp user notification to control filesystem, network, syscalls, and resources.sandlock.io · 4 Oct 2026
- Policy controls
- Policies can restrict filesystem access, default-deny network egress, apply HTTP method/host/path rules, inject credentials, stage writes with copy-on-write, and set resource limits.sandlock.io · 4 Oct 2026
- Interfaces
- The product provides a CLI, Python SDK, Rust API, Go SDK, OCI runtime, and MCP server.sandlock.io · 4 Oct 2026
- Integrations
- The OCI runtime works with containerd, CRI-O, and Kubernetes, and the remote MCP API can be used with Claude Desktop, Cursor, or another MCP client.sandlock.io · 4 Oct 2026
- Use cases
- The maker describes use for AI agent tool use, CI and untrusted builds, and per-request code execution.sandlock.io · 4 Oct 2026
- Privileges
- Sandlock runs as an ordinary user and does not require root, a container runtime, or a hypervisor.sandlock.io · 4 Oct 2026
- Kernel requirement
- Linux 6.12 or later supports the full protection set by default; older kernels can be used if missing protections are explicitly waived per policy.sandlock.io · 4 Oct 2026
- Threat boundary
- Sandlock shares the host kernel, and its security guarantees do not cover kernel vulnerabilities or hardware side channels.sandlock.io · 4 Oct 2026
- Credential handling
- The supervisor attaches secrets in the proxy only after the HTTP ACL check, so the sandboxed workload does not hold the secret value.sandlock.io · 4 Oct 2026
- Commercial deployment
- The commercial HTTP API and Scheduler are licensed software deployed on the customer's infrastructure, with no hosted or shared-tenant offering.sandlock.io · 4 Oct 2026
- Support
- Engineering support and a response SLA are included with each commercial license.sandlock.io · 4 Oct 2026
- Company
- Sandlock is a Multikernel Technologies project; the maker lists its address as San Jose, California.sandlock.io · 4 Oct 2026
Company
- Headquarters
- San Jose, California, United Statessandlock.io · 28 Sept 2026
Best Sandlock alternatives
See all 20 All accessCh 01 ANY.RUN Free planFree trialAndroid Free to start8.0 All accessCh 02 Daytona Free planFree trialAPI Free to start7.6 All accessCh 03 Northflank Free planAPILinux Free to start7.4 All accessCh 04 Zscaler Private Access AndroidiOS 7.4 All accessCh 05 Docker Desktop Free planLinuxMac from $9/mo7.3 All accessCh 06 microsandbox Free planAPILinux from $49/mo7.2
Where it ranks on Specifiction
- Best Sandbox Software in 2026#15 of 22
Is Sandlock yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- sandlock.io· checked 4 Oct 2026
- sandlock.io/enterprise.html· checked 4 Oct 2026
- sandlock.io/docs/getting-started.html· checked 4 Oct 2026
- sandlock.io/security.html· checked 4 Oct 2026






