01
WATCH · analyst overrideBUILDING · github + research + webmultikernel/sandlock
multikernel/sandlock — process-based AI agent sandbox for Linux, no container
- Builder / team
- Cong Wang and the Multikernel Technologies team (8 human contributors on sandlock)
- Actual artifact
- github.com/multikernel/sandlock (Rust, Apache-2.0) + arXiv:2605.26298
- Why it surfaced — and why company-first sourcing misses it
- 358 stars on the sandbox repo; the founder has 72 GitHub followers, no blog field and no X-native presence; the strongest corroborating evidence sits on LKML and arXiv. No institutional financing was identified in the public sources reviewed, so no funding database would surface it.
- Why now
- 807 owner commits, pushed the day of review; sandlock.io registered 2026-08-08; an arXiv paper published 2026-05-25; and a company products page that now lists "Multikernel Sandbox (AI agent sandboxing runtime)" as a commercial product.
- Formation evidence
- GitHub org Multikernel Technologies, Inc. created 2025-03-08 (F-02, F-06); multikernel.io and sandlock.io (F-01); commercial product page and demo booking (F-07). No public financing round was found in the sources reviewed.
- Technical-depth evidence
- Kernel-level isolation using unprivileged Linux primitives, from a maintainer of the Linux networking traffic-control subsystem. Systems depth OBSERVED; technical difficulty remains UNKNOWN until the escape surface is tested.
- Strongest positive
- Four independent channels spanning 17 months (org registry, company domain, LKML, arXiv), plus a paper co-authored with the AgentSight author — a cross-link between two independently-surfaced Phase 1 leads.
- Strongest negative
- The company is already selling. This is closer to the late edge of Day 0 than Phase 1 assumed, and a round may exist that is simply not public.
- Array relevance
- Agent execution isolation. Array's own AI coworker runs "in its own filesystem sandbox with isolated execution", and the April 2026 security post argues agents move data through syscalls where existing tooling cannot see them.
- What must be verified before an introduction
- Whether a priced round has closed; team size; whether sandlock is the commercial focus or a research artifact beside the cloud-OS product.
The technical question
Sandlock claims confinement using unprivileged Linux primitives. What is the actual escape surface compared with a microVM boundary, and what does the paper's threat model deliberately exclude?
The commercial / formation question
Multikernel now sells three products (Private Cloud, Sandbox, LiveUpdate). Is the agent sandbox a wedge into the cloud-OS business, or the business itself? Those imply different buyers and different funding paths.
signals B-01 · B-02 · B-03 · B-08 · B-09 · C-03 · D-01 · D-05 · F-01 · F-02 · F-06 · V-02 · V-03