InferCrane Sandboxes · powered by Brezel

Give every agent its own computer.

Run coding agents, evaluations, and long jobs away from your laptop and credentials. The workspace outlives compute; the lifecycle contract stays explicit.

Firecracker microVM isolation Durable workspace across standby Offline-by-default network policy Short-lived, sandbox-scoped model access Commands, files, previews, and activity evidence Apache-2.0 self-hosted runtime

A lifecycle users can reason about

Keep the work. Choose whether compute sleeps.

Brezel does not pretend a sleeping machine keeps every process alive. Files persist; compute behavior is selected deliberately.

01 / STANDBY

Workspace remains. Compute sleeps.

Best for agent loops that wait on a model or a human. Explicit work wakes the sandbox. Cron, daemons, and inbound traffic do not run while it sleeps.

Idle state
Compute stopped
Files
Persist until expiry or deletion
Wake
Explicit command or resume
02 / RESIDENT

Keep the sandbox running.

Choose resident compute for scheduled jobs, daemons, and continuously reachable services. It consumes reserved host capacity for the time it remains active.

Idle state
Compute remains running
Processes
Cron and daemons continue
Capacity
Configured and qualified per host

One small interface

The infrastructure stays underneath.

Create, run, inspect, preview, and clean up from the CLI, Python, TypeScript, or the InferCrane console. No agent framework required.

Read the API and SDK guide
$ brezel new
Create a sandbox
$ brezel run <id> npm test
Run and stream a command
$ brezel put / get
Move files
$ brezel host <id> 3000
Open a temporary preview
$ brezel stop / start
Stand by and resume

Adopt without a platform bet

Start on one dedicated host. Keep the exit open.

  1. 01
    Self-host Brezel

    Run the Apache-2.0 runtime on an Ubuntu 24.04 x86-64 host with KVM.

    Open the repository →
  2. 02
    Connect dedicated capacity

    Operate the sandbox host alongside InferCrane’s model endpoints and access boundary.

    Connect a host →
  3. 03
    Use managed Brezel

    Top up once and pay by the second while compute runs. Standby compute is $0; the workspace remains.

    Open managed sandboxes →

Public evidence

Measure useful work, not only boot time.

Our public self-run of the exact Starsling Node CPU workload completed at 29.90 runs/second across five independent sandboxes, 5.9% above the published dataset leader at the time of the run.

Self-run evidence, not an official leaderboard placement. Exact workflow, artifacts, and cleanup are public.Inspect the public run
Node CPU throughput · higher is better
Brezel self-run29.90
Published leader28.23
Same agent. Different computer. Keys never enter the box.

Model access is scoped at the boundary; ordinary sandboxes remain offline unless an explicit policy is qualified.

Security model →