# Features — caas.sh

**One sandbox foundation for agents and MCP servers.**

Isolated compute, persistent state, network policy, and an audit trail. The same controls whether the workload is a coding agent or a tool server.

## Sandbox: a machine that keeps its state

- **Its own URL.** Reach the workload directly at a dedicated address.
- **Sized to the job.** Configure CPU, memory, and filesystem capacity.
- **Snapshots.** Save a point in time and restore it later.
- **Persistent workspaces.** Files survive between runs. Back up what must outlive the sandbox.

Example configuration: 2 vCPU, 4 GiB memory, persistent workspace, last snapshot saved.

## Network & credentials: the real key never enters the sandbox

- **Allow or deny destinations.** Set exactly which hosts a workload may reach.
- **Credentials at egress.** Keys are added after a request leaves the sandbox, not stored inside it.
- **Attempted vs. allowed.** Review what the workload tried and what policy let through.

Example outbound policy: `github.com` allow, `pypi.org` allow, `*` deny. Requests flow sandbox → egress (key added) → API.

## Operations: know who did what, and what it used

- **Usage.** Track CPU and memory for every workload.
- **Audit log.** Create, snapshot, restore, and delete, each with the actor who did it.
- **Backups.** Keep retained files durable beyond the sandbox's life.

## Try it on one workload

An agent or an MCP server. Same sandbox, same controls. Get started in the [console](https://console.caas.sh/).

[Agents](https://caas.sh/agents.html) · [MCP Cloud](https://caas.sh/mcp-cloud.html) · [Pricing](https://caas.sh/pricing.html)
