Tilion private beta

Sandboxes for AI agents

A computer for every agent,
kept as long as the work takes.

Each sandbox is a Linux microVM with its own kernel, a shell, files, Docker, and a real Chromium, isolated in hardware. It pauses when idle and resumes with its processes still running, even on another machine. Pick the vCPUs, memory, and disk each one gets.

1.4 mscreate to first command, from the warm pool
44 mscold boot to a ready agent
1,000sandboxes started at once in 0.39 s
16 vCPU · 32 GiBlargest size; any mix from 1 vCPU, 512 MiB

Measured on bare metal; the methods are in the benchmarks. Times from your own network add your round trip.

Create an account

Access is by invite during the private beta. You get an API key right away.

Sign in

Paste an API key to open your dashboard. It stays in this browser only.

Start in a minute

Set your key, install a client from this service, and create a sandbox.

pip install https://sandbox.tilion.dev/downloads/tilion_sandbox-0.2.0-py3-none-any.whl
from tilion_sandbox import Sandbox

sbx = Sandbox.create(vcpus=2, memory_mib=4096)          # sizes are optional
print(sbx.exec("python3 -c 'print(6*7)'").stdout)        # 42
sbx.files.write("/workspace/app.py", "print('hello')")
print(sbx.exec("python3 /workspace/app.py").stdout)
sbx.pause()                                              # everything is kept
print(sbx.exec("ls /workspace").stdout)                  # any call resumes it

Kept, not rebuilt

Idle sandboxes pause with memory and processes saved, and come back where they were. Paused state lives in object storage, so it survives a lost host.

Code and a browser

Chromium runs on the same machine as the agent's commands, so it can open what the agent serves on localhost. Drive it with Playwright over CDP.

Your size, your image

1 to 16 vCPUs, 512 MiB to 32 GiB, 5 to 200 GiB of disk, per sandbox. Bring a container image or Dockerfile as a template.

Isolated in hardware

Every sandbox is a Firecracker microVM under a jailer, with its own kernel and capped CPU and memory. Nothing is shared between sandboxes.