How we contain Claude across products
Summary
Anthropic published a detailed engineering overview of the sandbox techniques used to contain Claude across its products including Claude.ai, Claude Code, and Claude Cowork, covering process sandboxes, VMs, filesystem boundaries, and egress controls. The article explains the rationale and technologies (gVisor, Seatbelt, Bubblewrap) and mentions the srt open-source tool.
View Cached Full Text
Cached at: 05/30/26, 11:11 PM
Similar Articles
How we contain Claude across products
Anthropic discusses how they contain Claude across products by capping blast radius through containment architectures and reducing human supervision fatigue, sharing lessons from deploying Claude.ai, Claude Code, and Claude Cowork.
Anthropic just published how they contain Claude agents, including two security incidents they got wrong
Anthropic published a detailed engineering post on how they contain Claude agents in claude.ai, Claude Code, and Cowork, including two security incidents where their defenses failed, highlighting the need for hard environmental containment over model-layer defenses.
@AnthropicAI: New on the Engineering Blog: The access and permissions we grant agents should evolve with their capabilities. In our o…
Anthropic's engineering blog details how they contain Claude agents across products using sandboxing and access controls to cap the blast radius, sharing lessons from deploying Claude Code, Claude Cowork, and claude.ai.
Claude Code's product lead talks usage limits, transparency, and the "lean harness"
Ars Technica interviews Anthropic's Cat Wu, head of product for Claude Code, about the product's rapid growth, compute constraints, and the company's iterative, model-driven development strategy without a long-term roadmap.
@claudeai: Live from Code with Claude London: we're launching self-hosted sandboxes (public beta) and MCP tunnels (research previe…
Anthropic launches self-hosted sandboxes (public beta) and MCP tunnels (research preview) in Claude Managed Agents, enabling agents to run within the user's own perimeter with default security controls.