Trust & what gets logged
Two questions everyone asks before using the Sandbox in earnest:
- Can NBG read my prompts and Claude’s responses? No.
- Can NBG see the files I drop into the VM? Only if you upload them via File Manager (DLP-scanned). Files created inside the VM — no.
The detail follows.
Where the prompts go
[your laptop] │ keypair lives in macOS Keychain, never leaves │ mTLS device cert (24h, renewed every 12h) │[ NBG portal ] │ SSH cert (per-session, minutes) │[ your Sandbox VM ] │ HTTPS to Vertex AI (your GCP project) │[ Vertex AI ] ──> [ Claude model ]Critical: the portal is not in the model-call path. It manages devices and VMs. Once you’re SSH’d in, your prompts go VM → Vertex → Claude directly. NBG can see that a call happened (Vertex metadata) but not its contents.
What NBG captures
| What | Where stored | Why |
|---|---|---|
| Login / logout | Portal audit log | Compliance |
| Device enrollment + revocation | Portal audit log | Lost-laptop kill switch |
| Certificate issuance + renewal | Portal audit log | ”Who connected when” |
| VM lifecycle | Cloud control plane | Cost attribution |
| File uploads via File Manager | DLP-scanned + stored | Data-loss prevention |
| Network metadata (source IP, timing) | Standard SIEM | Threat detection |
What NBG does not capture
| What | Why |
|---|---|
| Your prompts | VM → Vertex direct. Portal isn’t in the path. |
| Claude’s responses | Same reason. |
| Your private SSH keys | Generated on your laptop, locked in Keychain. |
| Your Google credentials | OAuth happens inside the VM; tokens stay there. |
| Files you create on the VM | They never travel through DLP — DLP only sees laptop → VM uploads. |
”DLP-scanned” in practice
When you drag a file from your laptop into the VM via File Manager, the file goes through NBG’s DLP pipeline first:
- Contents inspected against a policy (customer-data patterns, secrets).
- Stored in an audit-trail bucket with metadata (who, when, target VM, hash).
- Allowed through, or quarantined with a page to security.
This is the only channel that exposes file contents to NBG. Files generated inside the VM don’t touch DLP.
Don't use File Manager as a casual "let me drop this file to check something". Every drop is an audited event. Prefer
git clone or having Claude generate the file on the VM.Practical implications
- Long Claude conversations about internal architecture — fine. Prompts go to Vertex; NBG doesn’t see them.
- Cloning an NBG repo on the VM — fine. The clone happens VM-side, no DLP entry.
- Pasting a secret into a Claude prompt — it goes to Vertex. NBG doesn’t see it. But you still pasted a secret; rotate it.
- VM has outbound internet (so it can
git clone,npm install) but no inbound — only your SSH tunnel reaches it.