Why the Sandbox exists
One-line version: so Claude Code can read your real files without those files touching your laptop.
The problem
Claude Code is most useful when it reads your real work — specs, CSVs, source code, configs. But at NBG, “real” files often contain:
- Customer-level data that can’t leave NBG’s perimeter.
- Source code for systems whose architecture is itself sensitive.
- Configs that name internal hostnames, queues, endpoints.
Run claude on your laptop and drop any of those into the session folder — and the file goes to the model provider as part of the prompt. That’s a DLP failure on day one, no matter how careful you are.
The Sandbox makes that failure mode structurally impossible. The files live on a VM in NBG’s cloud. Your Mac is just a terminal window pointed at the VM.
How the model call actually flows
This is the part that surprises people.
You (Mac) ──SSH──> Sandbox VM ──HTTPS──> Vertex AI ──> Claude (your personal GCP project)On the VM, claude does not call the public Anthropic API. It calls Anthropic models hosted on Google Vertex AI, in a per-user GCP project NBG provisions for you. Why:
- Per-user billing. Vertex metering rolls up to your GCP project; NBG can see who spends what.
- Regional data residency. Vertex calls stay in a chosen region (EU).
- Centralised audit. Cloud Logging captures the call metadata in NBG’s GCP tenant.
- Procurement. NBG already has a Google Cloud contract; Vertex falls under it.
The model behaviour is identical — same Claude. What changes is who routes the call and bills for it.
Two cert layers (what the enrollment dance was about)
Layer 1 — device cert (24h, auto-renewed every 12h): Your laptop ──mTLS──> Portal
Layer 2 — SSH cert (per-session, minutes-to-hours): Your laptop ──SSH cert──> Your VM ^ portal acts as SSH CALayer 1 locks the portal so only enrolled laptops can manage VMs. Enrollment proved two things at once: you signed in, and the certificate request came from the program on your laptop (it holds a one-time secret the portal checks), not from someone else on the network.
Layer 2 means there are no long-lived SSH keys lying around. Every Connect mints a brand-new short-lived SSH cert. If your laptop is lost, you revoke the device on the portal — within seconds, layer 1 is invalid and the laptop loses access. No keys to chase.
Read next
- Sandbox vs. alternatives — when to pick which.
- Trust & what gets logged — exactly what NBG sees.
- Set it up — get going.