Securely deploying AI agents changedagent-sdk/secure-deployment
Nearest release: v2.1.287, published 7 hours before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 2 Oct 2026 00:28 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 2 Oct 2026 00:37 UTC.
Upstream edited
Recorded here
Lines+3added
Lines−3removed
From line
72
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits5to this page, all time
The whole hunk
from line 72, old and new numbered
/
from line 72
7272
7373### Sandbox runtime
7474
75For lightweight isolation without containers, [sandbox-runtime](https://github.com/anthropic-experimental/sandbox-runtime) enforces filesystem and network restrictions at the OS level.
75For lightweight isolation without containers, [sandbox-runtime](https://github.com/anthropics/sandbox-runtime) enforces filesystem and network restrictions at the OS level.
7676
7777The main advantage is simplicity: no Docker configuration, container images, or networking setup required. The proxy and filesystem restrictions are built in.
7878
from line 142
142142
143143With `--network none`, the container has no network interfaces at all. The only way for the agent to reach the outside world is through the mounted Unix socket, which connects to a proxy running on the host. This proxy can enforce domain allowlists, inject credentials, and log all traffic.
144144
145This is the same architecture used by [sandbox-runtime](https://github.com/anthropic-experimental/sandbox-runtime). Even if the agent is compromised via prompt injection, it cannot exfiltrate data to arbitrary servers. It can only communicate through the proxy, which controls what domains are reachable. For more details, see the [Claude Code sandboxing blog post](https://www.anthropic.com/engineering/claude-code-sandboxing).
145This is the same architecture used by [sandbox-runtime](https://github.com/anthropics/sandbox-runtime). Even if the agent is compromised via prompt injection, it cannot exfiltrate data to arbitrary servers. It can only communicate through the proxy, which controls what domains are reachable. For more details, see the [Claude Code sandboxing blog post](https://www.anthropic.com/engineering/claude-code-sandboxing).
146146
147147**Additional hardening options:**
148148
from line 335
335335* [Claude Code security documentation](/docs/en/security)
336336* [Hosting the Agent SDK](/docs/en/agent-sdk/hosting)
337337* [Handling permissions](/docs/en/agent-sdk/permissions)
338* [Sandbox runtime](https://github.com/anthropic-experimental/sandbox-runtime)
338* [Sandbox runtime](https://github.com/anthropics/sandbox-runtime)
339339* [The Lethal Trifecta for AI Agents](https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/)
340340* [OWASP Top 10 for LLM Applications](https://owasp.org/www-project-top-10-for-large-language-model-applications/)
341341* [Docker Security Best Practices](https://docs.docker.com/engine/security/)
No line in this hunk matches that.