HELIOS DOCS

Sandboxes

Helios agents run in isolated cloud sandboxes with a shell, a filesystem, code execution, web access, and the Library mounted read-only or read-write.

Every Helios agent runs inside its own sandbox - an isolated cloud computer, provisioned per chat or per workflow run. Nothing is shared between sandboxes.

This is what separates an agent from a chatbot. It doesn't describe the work; it does the work, on a machine, with tools.

What's inside

A shell and a filesystem. The agent can run commands, read, write, and edit files, and search across them.

Code execution. The default environment is Debian with a build toolchain, git, jq, and a JavaScript / TypeScript runtime. The agent installs what else it needs. You can also build your own environment from a Dockerfile.

Web access. The agent can search the web and scrape a URL into clean markdown.

Your tools. Integrations (the full API of each connected service), databases, and any attached MCP servers.

Files

The sandbox filesystem belongs to one run. When the run ends, the filesystem is discarded.

Shared files come from the Library. Helios mounts the Library folders the run may see under ~/context. The agent reads them from disk. Edits under ~/context are staged as a proposed change that a person approves or discards. Nothing reaches the Library without approval.

Agents are told to use $TMPDIR for scratch work. See context for what carries between runs.

Lifetime

A sandbox stays alive while the agent is active and shuts down after a period of inactivity, roughly fifteen minutes. The next message in a chat or the next run of a workflow gets a fresh sandbox with the same Library mounts.

Workflow runs have a hard 30-minute execution limit. See runs and outputs.

Isolation and credentials

Sandboxes start with outbound network access closed. Helios opens access to specific hosts only as the agent's task requires, and injects the necessary authentication at the network layer.

This is the important part: the agent never holds your credentials. When it calls the GitHub API or clones a pinned repository, Helios attaches a short-lived, narrowly scoped token to the outbound request. Nothing readable as a secret exists inside the sandbox for a prompt injection to exfiltrate.

Your secrets are envelope-encrypted at rest and are never passed into the agent's context.

Database access is deliberately narrow

The agent reaches your databases through a dedicated tool. The credentials stay with Helios. Queries run read-only, with a statement timeout and a row limit. See databases and database security for how to bound this further on your side.

Last updated on