Home / Companies / Boxd / Blog / Post Details
Content Deep Dive

Sandboxes with a hardware boundary

Blog post from Boxd

Post Details
Company
Date Published
Author
Michiel Voortman
Word Count
1,326
Company Posts That Month
12
Language
English
Hacker News Points
-
Post removed?
No
Summary

Boxd presents its sandboxing approach as hardware-level isolation through KVM microVMs, giving each workload its own kernel, network stack, and disk rather than relying on containers that share a host kernel. This design allows untrusted code to have root access within its disposable VM, including the ability to run Docker, modify system settings, or damage its own operating system, while limiting the effects to that machine; however, outbound internet access remains a potential route for data exfiltration. The platform claims fresh microVM boot times under 10 milliseconds and forks under 200 milliseconds, enabling per-task disposable environments, concurrent fleets, and snapshot-based provisioning with preinstalled tools. Machines can also persist and resume quickly, supporting longer-lived isolated environments such as tenant-specific infrastructure. The immutable `--isolated` setting removes access to an account’s default private network, in-VM Boxd credentials, connected integrations, and other owned machines, while retaining outbound internet, public HTTPS, SSH, and persistent storage. Selective connectivity can be restored through named network tags, allowing an isolated machine to access only explicitly designated non-isolated resources such as a job queue or database.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Real-time 1 4,432 1,050 222 -31%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.