Give Devboxes access without putting your company at risk
Your data stays on servers in Germany, and your company decides what Devboxes can use.
A task holds stand‑ins, so there's no secret to leak
If someone gets an agent to send its credentials somewhere, all they get is a stand-in. Your real secrets stay in the Devboxes vault and are added only as a request leaves the workspace.
Vault
GitHub token ••••••••
Upgrade the logging library
github.com stand-in
This is the only token the agent ever sees.
Egress Cloud only
github.com Receives the real token
Your company decides which hosts a task may reach
Tasks read pages that anyone on the internet can write, and an agent can also go wrong on its own. A task only reaches the hosts your company allows, so your code can't end up anywhere else.
Upgrade the logging library
Network policy Cloud only
github.com
registry.npmjs.org
Your model provider
unlisted-host.net
Your systems get tokens with fine‑grained permissions
Create a delegation token for a tool inside your company and pick the exact operations it may run. Devboxes refuses any operation you didn't grant.
Support portal
- Start tasks
- Follow a task
- Read results
- Change secrets
- Remove members
- Create more tokens
Hosted in Germany and running on your own model subscription
We store your company's data encrypted on European-owned servers in Germany.
Your own infrastructure
We run Devboxes there for you, with every Cloud feature.
Ask about a dedicated deploymentTasks on a machine you register run without the Cloud only features.
Send us your security questions
We reply by email. Devboxes has no SOC 2 report yet. For personal data, write to privacy@devboxes.ai.