Supported agent CLIs
Direct agent CLI launch
Start supported coding-agent CLIs directly through Brig.
Brig gives supported coding agents a microVM boundary. Probity adds independent observation and evidence outside the agent.
Brig is free and open source under Apache 2.0. The waitlist is for Probity governance updates, not Brig access.
The microVM keeps agent execution behind a hardware boundary. Probity adds independent observation and signed evidence outside the agent's own account of what happened.
Explore AI GovernanceObserve supported microVM boundary activity from outside the guest.
Correlate boundary evidence with what the agent says it did. Declare gaps rather than treating every action as verified.
Keep an independent record with coverage and integrity status for existing security workflows and SIEMs.
Brig reports which runtime, image, credentials, and network a coding-agent session will use.
Swipe to read the full terminal output
$ brig info claude
$ brig run claude ~/code/demo
brig: image and boot assets verified
Example from the Brig quickstart. Values depend on host, profile, and project. Shared networking is not an egress policy.
Coding agents now install packages, change code, and execute commands where developers work. Brig gives each supported agent CLI a dedicated lightweight microVM boundary on the laptop.
Works with the coding agents teams already use
Brig launches supported coding-agent CLIs directly. OCI packaging, lightweight microVMs, and familiar lifecycle controls provide the execution layer underneath.
Supported agent CLIs
Start supported coding-agent CLIs directly through Brig.
Session isolation
Give every coding-agent session its own lightweight Linux microVM boundary.
Lifecycle controls
Run, inspect, follow logs, stop, remove, and execute one-shot jobs.
microVM backends
Use Apple Virtualization.framework or QEMU for the underlying agent environment.
Multi-service support
Start supported multi-service definitions as separate microVM-isolated environments.
Permissive mode
Run supported agent CLIs in permissive or auto-approve mode inside their dedicated microVM environment.
Brig supplies the microVM boundary for coding agents. Probity adds independent observation and signed evidence. Its AI Governance page explains that layer in detail.
Yes. Brig is free and open source under Apache 2.0. The waitlist on this page is for Probity governance updates, not access to Brig.
Apple Silicon Macs with macOS 15 or newer and Linux hosts on x86-64 or ARM64. macOS 14 works with BRIG_HYPERVISOR=vz. Linux needs nerdctl, containerd, and the urunc shim.
Yes. The microVM isolates guest execution, but agents can still modify mounted projects and use any credentials provided. The default network is shared.
No. Brig is the coding-agent sandbox CLI. It uses the urunc shim with containerd on Linux and hull on macOS.
Get AI Governance updates. Brig is free and open source and available now.