Lightweight hosted runtime
No machine attached
Bounded JavaScript, bounded public HTTP where enabled, and granted capability calls. No general shell, filesystem, git, or browser.
Agent loop versus execution
When you choose an ExecWarden-hosted loop, ExecWarden keeps the transcript and run state. The execution choice decides whether the task gets only lightweight hosted tools or a customer-configured machine.
Lightweight hosted runtime
Bounded JavaScript, bounded public HTTP where enabled, and granted capability calls. No general shell, filesystem, git, or browser.
Connected execution environment
A VM, Docker environment, or local machine provides the files, shell, processes, git, browser, tests, containers, and network access configured for the task.
Connect it deliberately
A connected environment is a place to execute, not a blanket of ExecWarden policy. Decide what the machine exposes locally, attach it to the run that needs it, and keep external credentials behind mediated capabilities where possible.
Customer configuration
The customer configures the VM, Docker host, or local machine, including its files, network reachability, installed software, and local secrets.
Run attachment
A hosted session can bind to a sandbox volume on configured capacity. External clients use their existing environment and connect to governed tools through MCP.
Credential boundary
A GitHub or SaaS credential held by ExecWarden follows grants and approvals. A separate token placed on the machine can be used outside that path.
Examples
Get started during beta
Use the app during beta, or open the docs and choose the first agent task you want to govern.