Skip to content

Trust & what gets logged

Two questions everyone asks before using the Sandbox in earnest:

  1. Can NBG read my prompts and Claude’s responses? No.
  2. Can NBG see the files I drop into the VM? Only if you upload them via File Manager (DLP-scanned). Files created inside the VM — no.

The detail follows.

Where the prompts go

[your laptop]
│ keypair lives in macOS Keychain, never leaves
│
mTLS device cert (24h, renewed every 12h)
│
[ NBG portal ]
│
SSH cert (per-session, minutes)
│
[ your Sandbox VM ]
│
HTTPS to Vertex AI (your GCP project)
│
[ Vertex AI ] ──> [ Claude model ]

Critical: the portal is not in the model-call path. It manages devices and VMs. Once you’re SSH’d in, your prompts go VM → Vertex → Claude directly. NBG can see that a call happened (Vertex metadata) but not its contents.

What NBG captures

WhatWhere storedWhy
Login / logoutPortal audit logCompliance
Device enrollment + revocationPortal audit logLost-laptop kill switch
Certificate issuance + renewalPortal audit log”Who connected when”
VM lifecycleCloud control planeCost attribution
File uploads via File ManagerDLP-scanned + storedData-loss prevention
Network metadata (source IP, timing)Standard SIEMThreat detection

What NBG does not capture

WhatWhy
Your promptsVM → Vertex direct. Portal isn’t in the path.
Claude’s responsesSame reason.
Your private SSH keysGenerated on your laptop, locked in Keychain.
Your Google credentialsOAuth happens inside the VM; tokens stay there.
Files you create on the VMThey never travel through DLP — DLP only sees laptop → VM uploads.

”DLP-scanned” in practice

When you drag a file from your laptop into the VM via File Manager, the file goes through NBG’s DLP pipeline first:

  • Contents inspected against a policy (customer-data patterns, secrets).
  • Stored in an audit-trail bucket with metadata (who, when, target VM, hash).
  • Allowed through, or quarantined with a page to security.

This is the only channel that exposes file contents to NBG. Files generated inside the VM don’t touch DLP.

Don't use File Manager as a casual "let me drop this file to check something". Every drop is an audited event. Prefer git clone or having Claude generate the file on the VM.

Practical implications

  • Long Claude conversations about internal architecture — fine. Prompts go to Vertex; NBG doesn’t see them.
  • Cloning an NBG repo on the VM — fine. The clone happens VM-side, no DLP entry.
  • Pasting a secret into a Claude prompt — it goes to Vertex. NBG doesn’t see it. But you still pasted a secret; rotate it.
  • VM has outbound internet (so it can git clone, npm install) but no inbound — only your SSH tunnel reaches it.