Modal Sandboxes
Modal LabsClosed-source serverless platform that lets you run Python and shell code (including GPU workloads) in seconds-startup containers, with a dedicated Sandbox primitive for executing untrusted agent-generated code. Picked when AI teams need GPU-capable sandboxes with Pythonic ergonomics. Raised $355M Series C in May 2026 at a $4.65B valuation; $300M annualized revenue driven largely by coding-agent demand.
Modal Sandboxes - 'secure containers for executing untrusted user or agent code' on the Modal platform; gVisor-based isolation. Open Python/JS SDK + proprietary managed cloud (pay-per-CPU-cycle, $30/mo free credits on Starter). Docs verified live June 2026.
Openness
1 high confidence- license
- Proprietary
- source
- closed
- service
- proprietary Modal managed cloud (no self-host of the gVisor execution plane)
- open-part
- client SDK only (modal Python/JS client libraries)
- pricing
- pay-as-you-go usage, free starter credits
Closed managed service. The client SDK is open, but the execution substrate is a proprietary managed cloud with no self-host; an open client over a closed runtime is not open_core. Corrects a prior mis-calibration that grouped Modal with the genuinely self-hostable E2B (E2B ships self-hostable infra; Modal does not).
- https://modal.com/pricing recorded 2026-06-04
Modal is a managed proprietary cloud platform, pay-per-CPU-cycle, $30/mo free credits
- https://modal.com/docs/guide/sandbox recorded 2026-06-04
Sandboxes = secure containers for untrusted agent code, driven via Modal SDK
Adoption
3 low confidenceNo disclosed Modal Sandboxes user/usage count on primary pages; Modal is a well-known managed AI-compute platform with broad developer use and a documented free tier. Placed at 3 on reported multi-customer traction, not a measured usage_volume figure (kept conservative absent a hard number).
- https://modal.com/docs/guide/sandbox recorded 2026-06-04
documented production sandbox feature on a widely-used managed platform
Capability
4 medium confidenceStrong, purpose-built agent sandbox: gVisor isolation + arbitrary images + high concurrency. Sits just below the Firecracker-microVM frontier (Lambda/Vercel) on isolation strength; scored 4, level with the Ray/Ollama capability anchors. Independent ComputeSDK TTI benchmarks measure ~470ms median cold-start (13th of 19 sandbox providers), consistent with the fast-container-stack claim.
- https://modal.com/docs/guide/sandbox recorded 2026-06-04
sandbox lifecycle, custom images, timeouts up to 24h, untrusted-code execution
- https://modal.com/resources/best-code-execution-sandboxes-ai-agents recorded 2026-06-04
gVisor user-space kernel isolation, 50,000+ concurrent sessions (corroborating)
- https://www.computesdk.com/benchmarks/sandboxes/ recorded 2026-07-09
ComputeSDK TTI leaderboard (independent, 100 iters/day, 2026-07-09 run): median time-to-interactive ~470ms sequential / ~570ms burst @100 concurrent; 13th of 19 providers
Unchanged since 2026-07-30 (last edited, not re-checked)