Agents, contained.
A distributed, stateful runtime for agents and the apps they run in. Sandboxed, policy-checked, and safe for agents to change.
No tool sprawl.
Your app and its agents share one runtime.
The routes, queues, workflows, and storage your app uses are the same functions agents call as tools.
Boundaries, built in.
Deny by default
Every call is checked. No matching policy, no access.
Code stays in its box
Lua and WASM import only what their entry declares. Agent containers run locked down.
Network per process
Every dial and request is checked. Route each process direct, through a proxy, or over a tailnet.
Nodes prove who they are
Signed handshakes on every connection; gossip is encrypted.
Agents that ship, safely.
Claude Code or Codex change the running system through a scoped surface.
Every change is versioned. Roll back in one call.
Every agent is an actor.
Private state, one mailbox, nothing shared.
No locks, no races between agents. A crash stays contained, and a supervisor restarts it.
The same actor runs on one node or across the cluster. Durable ones can run on Temporal.
local funcs = require("funcs") local function main() local asks = process.listen("ask", { message = true }) local history = {} -- private state, no locks while true do local msg = asks:receive() table.insert(history, msg:payload():data()) local answer = funcs.call("app:think", history) process.send(msg:from(), "reply", answer) end end
Scale your way.
Same code, one node or many.
- ClusterAdd a node, it joins. Processes are addressed by name.
- QueuesIn-memory, RabbitMQ, or SQS behind one consumer API.
- TemporalRun durable work on your Temporal cluster.
- MeshReach across networks over Tailscale or SOCKS5.
The whole stack, built in.
Browse the Hub → Shared modules and apps you compose from.
Your control plane.



Run it on your infrastructure.
One binary. Your agents and data stay on hardware you control.