Boundlane Sheet D-104 / Security model

D-104 Start

Security model

The model is not trusted, and neither is the agent process. The rules live in the sandbox, outside both, so a bad prompt or a confused plan cannot move them. This sheet says what each layer stops and who has to be trusted for that to hold.

For security reviewersApplies to Free, Team, and License

Who is trusted

PartyTrusted withNot trusted with
The modelNothing. Its output is treated as untrusted input.Deciding what the agent may touch.
The agent processThe project copy, and the hosts the policy lists.Your home folder, your keys, other hosts, or approving its own requests.
The sandbox runtimeEnforcing the policy and holding keys. It runs on your machine.Talking to our cloud. It has no connection to us.
The person approvingOpening a door the policy did not list.Moving a wall in a running sandbox. Paths change only in the next one.
The machine's ownerOn Free and Team, everything on that machine, including the runtime.On License, the gateway. It runs where they do not administer it.
Our cloudPolicy text and decision records, on Team.Source code, file contents, terminal output, the agent's conversation, model keys, or Git tokens.

What each layer stops

The agent tries toWhat stops itWhat the agent sees
Read ~/.aws or ~/.sshYour home folder is not in the sandbox. Only the project copy is uploaded.The file does not exist.
Write outside the projectFilesystem rules, enforced by Landlock in the kernel.Permission denied
Call a host the policy does not listThe sandbox's network namespace and its policy proxy. DNS and the connection are both refused.A failed connection. The reason is in the log.
Use a listed host in a way the rule does not allowThe proxy reads the request and checks method and path.HTTP 403 with policy_denied and the rule that is missing.
Skip the proxy with a raw socketSeccomp blocks raw sockets. Direct connections are refused.Protocol not supported or Permission denied
Use a listed host from another programEach rule names the programs allowed to use it, by real path. Programs the agent starts inherit its rules; others do not.A refused connection.
Read the model keyThe agent holds a placeholder. The runtime adds the real key on the way out, and only on requests to the endpoints bound to that key.The placeholder.
Approve its own requestApprovals are a person's action, outside the sandbox. Automatic approval is never turned on.A request that waits.

Each row comes from the runtime's own enforcement. Boundlane writes the policy and checks it. It does not add a second enforcement layer of its own, and it does not ask the agent to behave.

Checked before start

Before a sandbox starts, the compiled policy is checked by OpenShell's policy prover against a boundary. After the sandbox is created, the policy it actually holds, including the endpoints each key adds, is checked again. If either check finds an action outside the boundary, nothing runs. See The check before start.

The prover shows what a policy allows. It does not show that the agent is good, and we do not present it that way.

When rules change

Network rules can change while a sandbox runs. Filesystem and process rules cannot. A change to paths or workspace access takes effect in the next sandbox, and Boundlane says so instead of pretending a running agent picked it up. See Walls and doors.

What a laptop cannot enforce

A developer owns their laptop and the runtime on it. They can change it, approve their own requests, or start an agent outside Boundlane. Team cannot prevent that. It records it as drift. Enforcement the machine's owner cannot change needs a gateway they do not administer, which is the License plan.

Channels outside the sandbox

Some traffic leaves through an allowed path. The clearest case: Claude Code's web search runs on Anthropic's side. The only request the sandbox sees is the call to the model API, so search queries leave inside that call, and the sandbox cannot block them without blocking the model. If that matters, turn web search off in the agent's own settings or your Anthropic organization. That setting is not enforced by the sandbox. The full list is in Known limits.