Skip to content

Sandbox vs. alternatives

There are three legitimate paths. They’re not in competition — each fits a different kind of work.

A — Laptop + Claude.ai

Plain npm i -g @anthropic-ai/claude-code. Models run on the public Anthropic API.

Pick when

  • Learning Claude Code on public examples
  • Hackathon / OSS / personal project
  • Zero bank data in the folder

B — Sandbox (default for NBG work)

Portal + Sandbox Connect + per-user VM. Models route through Vertex AI in NBG's GCP. Files live on the VM.

Pick when

  • NBG-confidential code or data
  • You want the team's pre-installed stack
  • You want centralised audit + per-user billing

C — Laptop + Vertex direct (advanced)

CLAUDE_CODE_USE_VERTEX=1 on your laptop pointing at your own GCP project.

Pick when

  • You need laptop-only tools (IDE, USB, GPU)
  • You have your own GCP project with Vertex + billing
  • You accept responsibility for keeping bank data off the laptop

Fast rule

NBG-confidential? B. Otherwise: A. C is for power users with a specific reason.

What changes between A, B, C

ConcernA — Laptop + Claude.aiB — SandboxC — Laptop + Vertex
ModelSame ClaudeSame ClaudeSame Claude
Where prompts goAnthropic public APIVertex AI (NBG GCP)Vertex AI (your GCP)
Where files liveYour laptopNBG VMYour laptop
Risk if laptop lostFiles exposedNothing on laptopFiles exposed
Audit visibilityNone for NBGFull for NBGLogs in your GCP
Network neededInternetNBG VPN (for the VM)Internet
Approved for bank data❌✅❌

The common trap

“If I just promise not to drop bank data into the folder, can I use A for NBG work?”

In principle yes; in practice no. Bank data sneaks in — a config file with internal hostnames, a CSV “just to check the format”, a .zshrc paste mid-debug. The Sandbox removes the chance to make the mistake.