Brig · free and open source

Run coding agents safely.

Brig gives supported coding agents a microVM boundary. Probity adds independent observation and evidence outside the agent.

Brig is free and open source under Apache 2.0. The waitlist is for Probity governance updates, not Brig access.

Brig isolates. Probity observes.

The microVM keeps agent execution behind a hardware boundary. Probity adds independent observation and signed evidence outside the agent's own account of what happened.

Explore AI Governance

microVM introspection (VMI)

Observe supported microVM boundary activity from outside the guest.

Agent context

Correlate boundary evidence with what the agent says it did. Declare gaps rather than treating every action as verified.

Signed evidence

Keep an independent record with coverage and integrity status for existing security workflows and SIEMs.

See the boundary before you run.

Brig reports which runtime, image, credentials, and network a coding-agent session will use.

TerminalBrig quickstart · macOS

Swipe to read the full terminal output

$ brig info claude

PROFILEclaude-code
SANDBOXbrig-claude-code (hull)
ISOLATIONmicroVM (hull, hvi backend)
WORKSPACE/Users/you/brig/claude-code (read-write)
IMAGEghcr.io/brig-sh/claude-code-stock:latest (pull missing)
VERIFYwarn, against brig's own trust policy
CREDENTIALS(none)
NETWORKshared (one network for every sandbox on this host)

$ brig run claude ~/code/demo

brig: image and boot assets verified

Example from the Brig quickstart. Values depend on host, profile, and project. Shared networking is not an egress policy.

Your laptop is the new prod.

Coding agents now install packages, change code, and execute commands where developers work. Brig gives each supported agent CLI a dedicated lightweight microVM boundary on the laptop.

Works with the coding agents teams already use

Claude Code
Cursor
GitHub Copilot
opencode
Supported CLI

Give coding agents freedom inside a real microVM boundary.

Brig launches supported coding-agent CLIs directly. OCI packaging, lightweight microVMs, and familiar lifecycle controls provide the execution layer underneath.

Supported agent CLIs

Direct agent CLI launch

Start supported coding-agent CLIs directly through Brig.

Session isolation

One session per microVM

Give every coding-agent session its own lightweight Linux microVM boundary.

Lifecycle controls

Familiar lifecycle

Run, inspect, follow logs, stop, remove, and execute one-shot jobs.

microVM backends

Two hypervisor paths

Use Apple Virtualization.framework or QEMU for the underlying agent environment.

Multi-service support

Compose subset

Start supported multi-service definitions as separate microVM-isolated environments.

Permissive mode

Auto-approve, inside the boundary

Run supported agent CLIs in permissive or auto-approve mode inside their dedicated microVM environment.

Common questions.

What is Brig?+

Brig supplies the microVM boundary for coding agents. Probity adds independent observation and signed evidence. Its AI Governance page explains that layer in detail.

Can I use Brig now?+

Yes. Brig is free and open source under Apache 2.0. The waitlist on this page is for Probity governance updates, not access to Brig.

What systems does Brig support?+

Apple Silicon Macs with macOS 15 or newer and Linux hosts on x86-64 or ARM64. macOS 14 works with BRIG_HYPERVISOR=vz. Linux needs nerdctl, containerd, and the urunc shim.

Can agents use auto-approval?+

Yes. The microVM isolates guest execution, but agents can still modify mounted projects and use any credentials provided. The default network is shared.

Is Brig the same as urunc?+

No. Brig is the coding-agent sandbox CLI. It uses the urunc shim with containerd on Linux and hull on macOS.

Join the Probity waitlist.

Get AI Governance updates. Brig is free and open source and available now.

We'll email you about AI Governance. Brig is already available.