SANDBOXISOLATED NETNS
EGRESSDENY-BY-DEFAULT
CREDENTIALSAGENT-BLIND
RUNTIME 1.0OPENSHELL
RUNTIME ONLINE CPU 04% MEM 31% LAT 12ms DIFFRACT v1.0 SCROLL 0%
DIFFRACT — SECURE AGENT RUNTIME v1.0 AGENTS YOUR SECURITY TEAM CAN APPROVE KERNEL-ISOLATED · POLICY-CONTROLLED · AUDITABLE
Runtime v1.0 — Stable Built on NVIDIA OpenShell One-command deploy

Autonomous AI agents your security team can actually approve.

Diffract runs every agent inside a kernel-isolated sandbox — deny-by-default egress, credentials it can never read, and a complete audit trail. Any model, any provider, hot-swapped at runtime. Deploy it in one command, self-hosted or fully managed.

Scroll
00
Model Providers
00
Command to Deploy
00
Secrets the Agent Can Read
00
Tool & Channel Integrations
NVIDIA OpenShell Landlock LSM seccomp-BPF Network Namespaces Caddy HTTPS Anthropic Claude NVIDIA Nemotron OpenAI-compatible

Built for zero-trust
autonomy.

Six pillars that turn unpredictable agents into auditable infrastructure.

01 / ISOLATION

Kernel-Level Sandbox

Every agent runs in its own sandbox built on NVIDIA OpenShell — network namespaces, Landlock and seccomp enforce isolation at the syscall boundary. It can't touch the host, your network, or another workload.

02 / EGRESS

Deny-by-Default Networking

The sandbox's only way out is a policy proxy. Your agent reaches the hosts you approve — and nothing else. Every connection is inspected, logged, and revocable in seconds.

03 / SECRETS

Credentials the Agent Can't Read

API keys and tokens are injected at the boundary, never into the agent's reach. Even a fully compromised agent has no secret to steal and nothing to exfiltrate.

04 / TOOLS

Connect Your Stack, Safely

Give the agent your CLIs, CRMs, and internal APIs through scoped, credential-isolated connections. It acts on your behalf — and reaches Slack, Telegram, Discord and 20+ channels — without ever holding the key.

05 / OPS

Built to Run in Production

Watchdog supervision, resource caps, and self-healing recovery, plus a full dashboard for sessions, logs and policy. Operable 24/7 by the team that owns it.

06 / MODELS

Any Model, No Lock-In

Hot-swap Claude, GPT, Gemini, Llama or NVIDIA Nemotron at runtime — no restarts, no SDK churn. Bring any OpenAI-compatible provider, and your own keys.

Six layers,
zero trust.

Every request crosses a defined boundary. Every boundary enforces policy. From the dashboard down to the kernel, every action an agent takes is logged and reviewable.

Diffract — Dashboard & CLITypeScript
Caddy — Reverse ProxyHTTPS · TLS
NemoClaw — OrchestrationProvisioning
OpenShell — Sandbox RuntimeNVIDIA
Egress Policy Proxynetns
Diffract Agent — IsolatedLandlock · seccomp

Contained
by design.

Six controls enforced in the runtime — not bolted on afterward. Each one is something you can put in front of your auditors.

i.

Deny-by-Default Networking

No egress unless you declare it. The sandbox routes out through a single policy proxy — every connection inspected, logged, and rate-limited.

ii.

Network-Namespace Isolation

Each agent gets its own network namespace, filesystem, and process tree. It can't see the host, your internal network, or another tenant's workload.

iii.

Agent-Blind Credentials

Keys are injected at the boundary, never into the agent. A compromised agent has no secret to steal and nothing to leak.

iv.

Host Approval & Egress Control

Add or revoke the exact hosts an agent may reach from one policy. Changes apply live, and every approval is recorded.

v.

Resource Containment

Cgroup limits cap CPU, memory, and process count. A runaway or forked agent is killed before it can touch the host.

vi.

Full Audit Trail

Every session, tool call, and egress decision is logged and reviewable in the dashboard — the evidence your compliance team asks for.

Any model,
one router.

Switch providers in real time. No SDK reshuffling, no environment swaps, no re-leaked tokens. Bring your own keys — or use ours.

Model
Provider
Strength
Status
01
Claude Opus 4.8
Anthropic
frontier reasoning
Available
02
Claude Sonnet 4.6
Anthropic
fast · balanced
Available
03
GPT-class
OpenAI
general-purpose
Available
04
Gemini
Google
multimodal
Available
05
Llama
Meta
open weights
Available
06
Nemotron
NVIDIA NIM
runs on your GPUs
Active

+ DeepSeek, Qwen, Moonshot, Mistral, GLM and OpenRouter — or any OpenAI-compatible endpoint.

Three steps to
production.

From zero to a sandboxed, multi-provider agent in minutes — self-hosted, or fully managed by us.

i

Install

One command pulls everything — Node, Docker, the OpenShell runtime, and the Diffract stack.

$ curl -fsSL https://diffraction.in/install.sh | bash
ii

Onboard

Provision an isolated sandbox, register your model providers, and bring up the gateway and dashboard.

$ diffract onboard
iii

Operate

Open the dashboard to chat, connect your tools, and set the egress policy your security team signs off on.

# open your private dashboard

Ready to deploy your
first agent?

Self-hosted or fully managed. Audit-ready from day one. Built for teams who refuse to trade safety for speed.