A box that isolates the processor but leaves the network open lets an agent carry the data out without ever leaving the box. Vercel adds a host-level firewall and keeps secrets outside the sandbox entirely.
- On August 11 Vercel announced network controls for its sandboxes: a host-level firewall with domain filtering and address-range restrictions.
- Credentials are injected at TLS termination on the host, meaning they never enter the agent's virtual machine.
- It is available on all plans, including the free one.
We run agents that write and execute code inside closed boxes. The box protects the machine underneath. It does not protect the data.
Compute isolation answers one question: keep foreign code away from your machine. It does not answer the second one, which today is the expensive one. Code with a free path outward carries out whatever it has seen, without ever leaving the box.
The smart part here is where the key sits. Once the secret is injected at the boundary rather than inside, code that leaks out of the box carries nothing. There is nothing to steal from a place that never held it.
If you run agents, this week's question is one: how far does my agent reach when it asks. If the answer is anywhere, your box is decoration.