Open a sandbox
A computer in the cloud with your project already installed, ready in a blink. Work in it, pause it, pick it up tomorrow.
- Debug a failed run
- Try your agent by hand
- A dev box that keeps its state
Production-grade sandboxes for coding agents, CI, evals and RL, ready in 8 ms and lightning fast at scale. Each is fully isolated, can run behind an outbound allow-list, wakes in milliseconds and bills only when awake.
Promigence10.5 ms
Google Agent Sandbox497 ms
AWS Bedrock AgentCore1.04 s
Provider A578 ms
Provider B1.13 s
Each sandbox is requested through the public API and counted when it answers its first command. One at a time.
8 msready-to-go sandboxes
A sandbox is ready for your agent 8 milliseconds after it asks.
5×faster first command
Your agent is running code 47 milliseconds after it asks for a machine.
15×faster repeat runs
A type-check that costs 24 seconds on a cold machine costs 1.5 seconds here.
7×faster whole tasks
A twenty-step agent task that takes nine minutes finishes in just over one.
Your customer waits through every second your agent spends on the machine, and waiting is where they leave. On Promigence the answer arrives while they are still there, and a fast answer is the experience they come back for.
Promigence
Cold start at every step
| p50 unless noted | Promigenceunloaded | Other providersbest managed platform | Self-hostedbest Docker / Kubernetes build |
|---|---|---|---|
| Sandbox ready to run a commandcreate to first command, 2 vCPU / 4 GiB, n=100 | 8 ms | 578 ms | 32 mswith a warm pool; 475 ms without |
| 100 at once, slowest 5%p95, every run completed, n=400 | 0.94 s | 47.0 s | 26.7 s |
| Whole coding-agent task20 steps on a 3 GB repo, n=30 | 43.7 sunder load 58.0 s | 100.3 s | 48.9 stuned Kubernetes |
| CI job, start to finishclone, install, type-check; 4 vCPU / 16 GiB vs hosted CI runners, n≥3 | 48.5–55.9 s | 105.9–148.7 sthe other: 129.7–182.0 s | 81.8–94.7 sa 4 vCPU / 16 GiB VM |
| Wake a paused sandboxresume to first database query, n=100 | 104 msunder load 127 ms | 487 ms | 2.20 s |
| Agent step on a warm repoedit, then type-check, 4 vCPU, n=30 | 0.66 sunder load 0.80 s | 1.80 s | 0.67 stuned Kubernetes |
| RL rollouts per minute8 at once, n=40 | 1,343 | 303 | 416 |
| Code-interpreter sessionstart to result, n=100 | 1.13 s | 4.03 s | 1.72 s |
| 20 copies of a warm workspaceall 20 usable, 2026-09-18, 3 rounds | 1.41 s | not measured | 8.42 sfrom a committed image |
Every sandbox opens on your project, already set up.
A computer in the cloud with your project already installed, ready in a blink. Work in it, pause it, pick it up tomorrow.
Your GitHub Actions and GitLab CI jobs, unchanged, in Promigence sandboxes. One line moves them, and they finish 2–3.5× sooner than hosted runners of the same size.
same CI job · same size
Half the time
of GitHub Actions, on the same CI job
53 s
Promigence, median
135 s
GitHub Actions, median
Claude Code, Codex or OpenCode works on a task in a copy of your repo, already set up. Start it yourself or from your CI.
task
fix the flaky login test
diff
+14 −3
tests pass
$ promigence agent start claude --snapshot my-app --prompt "fix the flaky login test"
illustrationGive each of your users a sandbox for their code. It sleeps when they stop and wakes on their next call.
Plug in from the framework you already useadapters, pre-release
+import { Sandbox } from '@promigence/sdk'
A fresh copy for every eval task, RL episode or command, a thousand at once. You see the most it can cost before it starts.
1 snapshot → 1,000 copies in ~1 s100 shown
every copy returns a verdict 3 environment failures, not billed
Security
Six promises, one on every side. Whichever way you turn it, the sandbox inside stays sealed.
01 Sealed from everyone
No sandbox can see, reach or address another, yours or anyone else's.
02 Tested by attack
We try to break out and to cross between customers, so any gap is ours to find first.
03 You choose the network
Everything, nothing, or a list of domains. Every refusal is logged.
04 Keys it never holds
Bind a secret to a host. Its value never enters the sandbox.
05 Nothing lingers
Secrets never enter a snapshot. What a run changes is gone unless you keep it.
06 Your code stays yours
Encrypted at rest and never trained on. Roles, an audit log and spend caps.
Every plan starts with $50 of free credit. Billed per second.
$0
pay as you go
Start free, then pay only for the seconds you run.
$50
per month
For teams running agents, evals and CI every day.
$250
per month
Then below list, by commitment
For large eval fleets, RL and continuous agentic CI.
Custom
volume pricing, set on one call
For vendors and labs running millions of episodes.
No sales cycle. One call with an engineer, a plan shaped on that call, and your first run the same hour.
Talk to us, live in an hourPromigence is a sandbox platform for AI agents: production-grade, fully isolated sandboxes that start in milliseconds, stay fast at a thousand at once, and bill by the second. It runs coding agents, background agents, evals and RL environments, each in its own sandbox built from your repository.
An AI agent sandbox is an isolated computer where an AI agent can write and run code, install packages and use tools without touching anyone else's systems. Promigence provides them as a service: production-grade sandboxes that are ready in milliseconds, open on your own project already installed, and bill by the second.
An environment runtime treats the execution environment as the product: it proves the environment works before anything runs in it, reproduces it exactly from a hash, and forks it many times over. A sandbox provider gives you a box that starts; an environment runtime gives you an environment that is known good.
Promigence solves silently broken environments. In a thousand-episode run some environments fail to install or come back cold, and that shows up as the agent failing the task, which corrupts the eval number and poisons the reward signal in RL. Promigence verifies every environment first and reports environment failures separately from task failures.
Yes. Change one line, runs-on: promigence in a GitHub Actions workflow or a runner tag in GitLab CI, and the same jobs run in Promigence sandboxes, billed per second. On the same unmodified CI job at the same size (4 vCPU / 16 GiB), Promigence finished in 48.5–55.9 s against 105.9–182.0 s on two hosted runner services, measured in October 2026.
A validity report is what Promigence returns after every run: how many environments were verified, which failed, and whether each failure was the environment's or the task's. Most teams running evals today cannot produce that number, which means they cannot say how much of their result is real.
A Promigence sandbox is ready to run its first command in 8 ms at the median (2 vCPU / 4 GiB, n = 100), against 578 ms for the best other managed sandbox platform measured. Start 100 runs at once and even the slowest 5% finish in under a second (0.94 s). Measured in September 2026; the latest figures are at www.promigence.ai/#numbers.
Promigence is built around four things together: sandboxes that are ready in milliseconds and stay fast at a thousand at once, environments verified before an agent runs in them, a report that labels every failed run as the task's, the environment's or Promigence's, and a bill that is quoted and capped before the run starts. Runs that fail because of Promigence are not billed when our side can show the failure was ours.
Promigence meters per second at $0.0504 per vCPU-hour plus $0.0162 per GiB-hour, the market's standard list rate. That works out at $0.17 an hour for a small sandbox (2 vCPU, 4 GB), $0.46 for medium (4 vCPU, 16 GB) and $0.92 for large (8 vCPU, 32 GB). New accounts get $50 of free credit for 30 days: $10 straight away with no card, and $40 more once a card is added (card payments open after the private beta).
Promigence has four plans. Free is pay as you go, with $50 of free credit and 20 sandboxes at once. Pro is $50 a month, includes more compute than it costs, and runs up to 100 sandboxes at once. Max is $250 a month for 5× the usage of Pro and up to 500 sandboxes at once, or $500 for 20× and up to 1,000. Enterprise is priced on a call. Current prices are at www.promigence.ai/#pricing.
Promigence runs one primitive: verify, snapshot, fork, exec, report. You declare a container image, setup steps (a clone of your repository at a pinned commit among them) and a verify command. The snapshot is stored only if verification passes. You then copy it N times into warm environments and get back a validity report and a bill that never exceeds the quote you saw first.
An agent runs code that nobody has reviewed, so it can break things, leak secrets or reach systems it should not. A sandbox gives each task its own isolated computer, with its own files, network rules and spend cap, so a mistake stays inside it. Promigence also starts that computer on the customer's project, already installed and tested, so the agent starts work instead of setup.
Promigence is for teams that run AI agents: agent companies building products on them, eval and platform engineers, benchmark producers and RL environment vendors. Any agent work fits, from one interactive sandbox to thousands of episodes at once.
Promigence runs any agent workload: coding agents, background agents, code review, agentic CI, evals and benchmarks, reinforcement-learning rollouts, and a sandbox per user inside an app. Ordinary GitHub Actions and GitLab CI jobs run on it too, with a one-line change to the workflow.
No. Promigence is the execution plane eval platforms run on, it has no datasets, scorers, judges or experiment tracking, which belong to your eval tools. It provides the verified environment the episode runs inside, and plugs in as a backend for those harnesses.
An episode is one environment's life in Promigence: fork, execute, terminate: 15 minutes by default, up to an hour in the private beta. Usage is metered per second, like the rest of the market, but the episode is the unit a quote and a spend cap are written against, so the maximum cost of a run is a multiplication you can do before you start it.
Yes. A sandbox pauses when it goes idle, wakes on the next request, and bills only while it is awake.
In tests against five other agent sandbox platforms in September 2026, Promigence was fastest on all but four of the measured workloads, and much faster at scale: with 100 runs at once, its slowest 5% finished in 0.94 s against 47 s for the best other managed platform. Figures change over time, so check the dated comparison at www.promigence.ai/#numbers.
Because a do-it-yourself setup cannot tell you how many of your environments were broken on the last run. What Promigence adds is verification, reproducibility, burst scheduling and nobody on call.
Free accounts run 20 Promigence sandboxes at once, Pro up to 100, and Max up to 500, or 1,000 on its $500 level. Enterprise contracts set their own limit and can reserve capacity.
Per second, at the market's standard list rate, because that is what the market meters and a price nobody can compare against is worth very little. The episode survives as the unit you are quoted in: promigence run quote returns the maximum a run can cost before it starts, and --cap refuses one that would go past your ceiling.
Yes. promigence run quote returns the exact maximum cost before any environment starts, and --cap refuses a run that would exceed your ceiling rather than stopping halfway through. Paused time is not invoiced, and nothing accrues before an environment is handed to you.
Yes: $50 of free credit for 30 days, $10 straight away with no card and $40 more once you add one (card payments open after the private beta), with 20 concurrent sandboxes and sessions up to an hour. During the private beta, signing up needs an invite code. Separately, any team can send their environments in for 1,000 verified episodes, a validity report and an exact bill quote, free and once.
Our servers are on the US East Coast. From far away, each call adds your network's round trip.
Each environment is fully isolated from every other, and nothing is shared with another customer. We test that boundary by attacking it rather than asserting it, and runs can start with no network at all.
Promigence starts each copy from an environment that has already finished installing and building, so nothing is installed again. A copy takes 39 ms, and a hundred at once still land at 122 ms.
The same snapshot hash returns a bit-identical environment on any later date, so an eval you ran in October can be re-run in March and the comparison means something. That is stronger than a recipe that re-resolves package versions underneath you on every build.
Yes. Adapters for common eval harnesses are in pre-release, and the TypeScript SDK exposes a compatibility Sandbox class with the familiar sandbox calls, so existing call sites run unchanged.
You store a secret once and name it on the runs or commands that need it (--secret NAME). It is encrypted at rest, given only to the commands that name it, and removed from logs and outputs. It is never written into a snapshot you build, and a snapshot of a sandbox that was given a secret is refused unless you force it.
Yes. Each Promigence sandbox can have full outbound access, none, or run behind an outbound allow-list of the destinations it needs, and refused connections are recorded. Agents that read untrusted input, such as web pages or user uploads, should run behind an allow-list.
No. Promigence does not use customer code, files, prompts or agent outputs to train AI models. It accesses customer content only to run the service, keep it secure, investigate abuse or comply with the law.
Promigence has a command-line tool, TypeScript and Python SDKs, and a REST API. Coding agents can drive it directly: the CLI prints a short guide written for agents (promigence agent-guide) and runs as an MCP server (promigence mcp), for example inside Claude Code.
Not as a self-serve product today. If your data cannot leave your boundary, talk to us about running it in your own cloud account.
Promigence records the failure as the environment's in the validity report. A sandbox that fails before hand-over is retried once automatically; one that fails mid-run can be re-run with promigence run replay, as a new sandbox billed under the run's cap. A run with a 3% environment failure rate reports 3%, instead of quietly reporting a 3% worse agent.
Every figure in the comparison on the home page (www.promigence.ai/#numbers) states its date, its sample size and the conditions it was measured under, and the free validity report runs your own workload so you can check the numbers yourself.
Promigence is in a private beta: signing up needs an invite code, and support@promigence.ai is where to ask for one. New accounts get $50 of free credit: $10 straight away with no card, and $40 more once a card is added (card payments open after the private beta). Teams who want a number on their own workload first can send their environments in for a free 1,000-episode run and a validity report.
No. Promigence is not owned by a lab or a hyperscaler and runs any vendor's agent. Neutrality is a requirement rather than a stance: a cross-lab evaluation cannot run inside one lab's harness.
Questions 1 to 6 of 37