Isolation
Your workspace is its own container, not shared with any other user.
No network path to other workspaces
One path out: filtered outbound traffic — see Outbound network
-
Your own workspace
Nobody else's workspace can read your files, see your processes or reach your running services.
-
An extra layer under the container
Where available, ZeroLog runs workspaces on gVisor, a userspace kernel: your workspace's system calls are handled without reaching the host kernel directly. Where it is not available, a restrictive fallback filter applies instead.
-
No path between workspaces
Workspaces cannot reach each other over the network, even when they run on the same machine.
-
Outbound traffic is filtered
A workspace's own internet access goes through ZeroLog's network protections; see Outbound network.
What this does not change
Commands still wait for you
Isolation keeps workspaces apart from each other, not from you. A command the AI wants to run still waits for your approval first — see Command approval.
Secrets go through the vault
Credentials you attach are handled by the vault, not pasted in the clear — see Secrets vault.
Pausing keeps the disk
Pausing a workspace frees its running slot; it does not delete anything. A paused workspace's disk stays until you delete it yourself.