For builders

Ship agents you'd
let near prod.

You want to give an AI agent real tools — your repo, your shell, your APIs. P1 Halo is the layer that lets you do it without handing over your keys or your blast radius. Sandbox it, cap it, kill it, and keep a signed receipt.

0
Keys in the container
1
Broker · one door
0%
Actions signed
signed run · sandboxedEd25519
$ halo run agent "refactor auth"
container up · net none · key vaulted
broker → provider · policy ok
spend $6.40 of $50.00 cap · kill-switch armed
18 events signed · re-verified 18/18 offline
sig  3f9a·b27e·c4d1·…·e21 — key pinned
The agent never holds a key No route off the sandbox Every action signed Kill any run on demand
What you get

Guardrails that don't get in the way.

The containment lives at the platform layer, so your agent code stays simple — and the things that would keep you up at night are already handled.

Tenant-isolated runs

Each customer's agents run in their own no-route sandbox and can't read each other's files or keys. Container-level isolation with no path to the internet — containment, not vibes.

PER-TENANT · NO EGRESS

BYOK, any model

Bring your own key for any supported provider, including OpenAI-compatible endpoints. Switch model per agent without touching app code. The key stays sealed in a libsodium vault and never enters the container.

BYOK VAULT

A signed receipt

Every run produces a tamper-evident, Ed25519-signed audit chain. When a customer asks "what did the agent do?", you hand them evidence they can re-verify offline — proof, not a screenshot.

TAMPER-EVIDENT
The same governance plane behind P1 Halo now wraps your customers’ agents — per-run policy, a hard cost cap, a kill switch, and a signed audit chain — so you can hand power to an agent without handing over the keys to the kingdom.
— Governance as a platform layer

Give your agent
real tools. Safely.

Spin up a sandbox, point an agent at a real task, and watch it run behind the broker — then export the proof you can re-verify yourself.