How we contain Claude across products
Anthropic published detailed documentation of how it sandboxes Claude agents across its products.
“if credentials never enter the sandbox, they can't be exfiltrated, regardless of whether the cause is a user, a model finding a “creative” path, or an attacker.”
Anthropic released a detailed overview of the sandboxing techniques it uses to contain Claude agents across Claude.ai (gVisor), Claude Code (Seatbelt/Bubblewrap), and Cowork (full VMs), spanning process sandboxes, filesystem boundaries, and egress controls. It matters because agent security and exfiltration risks are a growing concern, and transparent documentation lets engineers evaluate how much to trust agentic AI products.