Skip to content

Why the Sandbox exists

One-line version: so Claude Code can read your real files without those files touching your laptop.

The problem

Claude Code is most useful when it reads your real work — specs, CSVs, source code, configs. But at NBG, “real” files often contain:

  • Customer-level data that can’t leave NBG’s perimeter.
  • Source code for systems whose architecture is itself sensitive.
  • Configs that name internal hostnames, queues, endpoints.

Run claude on your laptop and drop any of those into the session folder — and the file goes to the model provider as part of the prompt. That’s a DLP failure on day one, no matter how careful you are.

The Sandbox makes that failure mode structurally impossible. The files live on a VM in NBG’s cloud. Your Mac is just a terminal window pointed at the VM.

How the model call actually flows

This is the part that surprises people.

You (Mac) ──SSH──> Sandbox VM ──HTTPS──> Vertex AI ──> Claude
(your personal GCP project)

On the VM, claude does not call the public Anthropic API. It calls Anthropic models hosted on Google Vertex AI, in a per-user GCP project NBG provisions for you. Why:

  • Per-user billing. Vertex metering rolls up to your GCP project; NBG can see who spends what.
  • Regional data residency. Vertex calls stay in a chosen region (EU).
  • Centralised audit. Cloud Logging captures the call metadata in NBG’s GCP tenant.
  • Procurement. NBG already has a Google Cloud contract; Vertex falls under it.

The model behaviour is identical — same Claude. What changes is who routes the call and bills for it.

Two cert layers (what the enrollment dance was about)

Layer 1 — device cert (24h, auto-renewed every 12h):
Your laptop ──mTLS──> Portal
Layer 2 — SSH cert (per-session, minutes-to-hours):
Your laptop ──SSH cert──> Your VM
^ portal acts as SSH CA

Layer 1 locks the portal so only enrolled laptops can manage VMs. Enrollment proved two things at once: you signed in, and the certificate request came from the program on your laptop (it holds a one-time secret the portal checks), not from someone else on the network.

Layer 2 means there are no long-lived SSH keys lying around. Every Connect mints a brand-new short-lived SSH cert. If your laptop is lost, you revoke the device on the portal — within seconds, layer 1 is invalid and the laptop loses access. No keys to chase.