Skip to main content
Every session runs in its own isolated sandbox. Sandboxes are ephemeral: spun up for the session, destroyed when it’s done. No code or state persists after execution. While a sandbox is running you can watch and control its desktop from the Computer tab, and use keep alive to hold it open after the agent finishes.

Data handling

Your repository is cloned into the sandbox for the duration of a session and torn down when the session ends — no repository contents or working state persist afterward. The one exception is projects. When you use a project to speed up environment setup, its repositories and pre-installed dependencies are cached in reusable environments so future sessions start faster. Those cached copies persist until the project is rebuilt or removed. Model providers handle prompt data according to their own retention policies — see the retention table in Max for Tembo-hosted models. With BYOK, model requests run against your own provider account, so provider-side retention follows that account’s terms.

Sandbox sizes

Each session runs in a dedicated Linux VM, and no two sessions share the same VM. Micro and Medium are best for routine code analysis, fixes, features, and reviews. Large and XL are best for heavier builds, integration tests, Docker workloads, large repositories, or multi-container setups. Your plan sets the largest size you can select — see Plans. XXL and Ultra are not included in a standard plan; contact support@tembo.io to request access. VM sandboxes include full nested virtualization for Docker-in-Docker and provide a stronger isolation boundary. If your org requires that untrusted code only runs with a VM boundary, we can enforce a VM-only posture. Contact support@tembo.io.

Pre-installed tools

All sandbox sizes come with:
Go and Elixir are available through Nix dev shells. Add a tembo.nix to install language-specific tooling for your project.

Add custom dependencies

Add a tembo.nix file to your repository when your project needs tools that are not pre-installed in the sandbox.