Boundlane Sheet D-307 / License plan

D-307 Team

License plan

The same control plane, in your VPC. Code, decisions, and approvals stay in your account, and gateways can run where developers do not administer them. That is the difference between recording what a laptop did and enforcing it.

WaitlistNo public price yet

What it adds to Team

TeamLicense
Control planeHosted by usIn your VPC
Decision recordsSent to us, kept 90 days by defaultKept in your account, for as long as you set
Sign-inConsole accountsSingle sign-on through your identity provider
ExportJSONLJSONL, plus SIEM export
GatewaysOn developers' machinesOn developers' machines, and on your cluster
Enforcement against the machine's ownerNo. Changes show as drift.Yes, for agents that run on a cluster gateway.

Where sandboxes run

On laptops. The same as Team. The developer's machine runs the gateway, and the policy comes from your control plane instead of ours. A developer can still change their own machine, and the console records it.

On your cluster. Agents that run in CI or on shared workers start in sandboxes on a gateway in your Kubernetes cluster. Developers submit work to it. They do not administer it, so they cannot loosen its policy, approve their own requests, or delete its logs.

In both cases the gateways dial out to the control plane. Nothing needs an inbound port, and nothing reaches our cloud.

The Kubernetes install

The install pins the sandbox runtime's chart to a tested version and runs the forwarder in the cluster, next to the gateway.

Network policy has to be enforced

Kubernetes accepts a NetworkPolicy object even when the cluster's network plugin ignores it. If it is ignored, a sandbox's traffic can skip the policy proxy. The install tests that egress policy is actually enforced on your cluster, not only accepted, and refuses to finish if it is not.

The documentation for the install lists the network plugins we have tested.

Single sign-on

The console and boundlane login go through your identity provider, so people sign in with the account they already have and you manage access in one place.

SIEM export

Decision records are OCSF, an open schema for security events, so they need no translation layer. Export them as JSONL, push them to a webhook, or let your SIEM poll for them. Formats for specific tools are built on the same records, not on a separate collector.

Buying it

There is no public price in the first version. Join the waitlist and say why you want Team or License. Your cloud bill stays yours: the control plane and the cluster gateways run on your infrastructure, and we do not bill sandbox hours. See Price.