Isolated · Auditable · Claude-native

Give your security team AI — without giving away your secrets.

Enclave is a hardened sandbox where analysts, red teams, and engineers work alongside Claude on real, sensitive systems — inside per-user isolation, with every action scoped to their role, clearance, and license.

No client data leaves the enclave. Ever.
Built for SOC · Red Team · IR · AppSec · GRC Isolation per-session micro-VMs Model Claude via your own CLI / keys Trail immutable, exportable audit log

The problem

Security work is exactly the work you can't paste into a chatbot.

The people who'd benefit most from AI — the ones handling breaches, exploits, and regulated data — are the ones who legally and practically can't use public tools.

Public AI

Sensitive artifacts leave your perimeter. No isolation, no clearance model, no audit trail your auditors will accept.

Locked-down laptops

Air-gapped and safe, but the analyst is on their own. Zero AI leverage on the hardest, most time-critical work.

Enclave

AI leverage and containment. Each session runs isolated, scoped to the operator's role and clearance, fully logged.

The platform

A professional console, not a toy chat window.

Everything a security team needs to actually adopt AI: identity, isolation, and a familiar Claude-native workflow.

🛡️

Per-session isolation

Every workspace spins up in its own disposable micro-VM. Tools, files, and network live and die with the session.

🪪

Identity, roles & clearance

Profiles carry job, team, certifications and clearance. The AI tailors what it surfaces — and the platform enforces what's allowed.

Claude-native, BYO-CLI

Auto-attaches to your Claude CLI or API keys. Your model access, your billing, inside our sandbox.

🚦

Egress control

Deny-all by default. Allowlist targets per workspace. Nothing — not a sample, not a secret — leaves without policy.

📜

Immutable audit trail

Every prompt, tool call, and file touch is hashed and logged. Export for SOC 2, ISO 27001, or an incident review.

🧰

Curated tool shelf

Ship vetted security tooling into the sandbox. Operators get power; you keep the supply chain under control.

Security model

The sandbox is the product. The UI is just the door.

Real security doesn't live in a web page — it lives in isolation, policy, and enforcement that the AI can't talk its way past. Enclave is built in layers, and authorization is enforced below the model, never by it.

Design principle: a user's clearance informs the AI (what to suggest, how to phrase). It never authorizes the AI. Every privileged action is checked server-side against a signed identity — so a prompt, however clever, can't escalate itself.
L1Identity & SSOSigned profile · role · clearance · license
L2Policy engineServer-side authz · every action checked
L3Isolated runtimeDisposable micro-VM per session
L4Egress firewallDeny-all · per-workspace allowlist
L5Audit & ledgerHashed, immutable, exportable
L6AI layer (Claude)Powerful — but least-privileged

How it works

From login to a working AI session in under a minute.

STEP 01

Authenticate & profile

Operator signs in via your SSO. Their role, team, certifications and clearance load from a signed identity — no self-declared access.

STEP 02

Spin up an enclave

A disposable sandbox provisions with egress locked down and the curated toolset for their role. Claude CLI auto-attaches.

STEP 03

Work — fully logged

They collaborate with Claude on real artifacts. Every step is scoped to policy and written to an immutable trail. Tear down when done.

Pricing

Start free. Scale to regulated and on-prem.

Plans map to what the platform actually enforces — isolation strength, identity, and compliance. Prices are indicative.

Community
Free
 
Try the workflow, solo.
  • Single operator
  • Process-tier sandbox (dev isolation)
  • Bring your own Claude key
  • All workspace presets
  • Hash-chained audit (local)
  • Community support
Start free
Enterprise
Contact us
 
Regulated, on-prem, at scale.
  • Everything in Team, plus:
  • Single-tenant / on-prem deployment
  • SOC 2 / ISO 27001 compliance package
  • SD-JWT · DPoP · SPIFFE workload identity
  • WORM + Merkle audit anchoring
  • Red-team scoping + HITL approvals
  • Windows isolation tier · SSO/SCIM · SLA
Talk to us

Early access

Bring AI into the room where the sensitive work happens.

Enclave is in private preview for security teams. Try the live console demo, or request an early-access briefing.