Skip to content
Home

Ash

Restricts AI coding agents on macOS with system-level security, limiting access to files, networks, processes, IO devices, and environment variables.

A macOS sandbox that restricts AI coding agents with system-level security, limiting access to files, networks, processes, IO devices, and environment variables. It is designed for developers and IT teams in enterprises who need to control the resources that AI agents can access. The sandbox uses macOS Endpoint Security and Network Extension frameworks to enforce fine-grained policies, distinguishing it from less restrictive alternatives.

Key features

  • Filesystem restrictions: read, write, create, delete, rename
  • Network restrictions by host and port
  • Process restrictions with argument control
  • IO device blocking: USB, camera, microphone
  • Environment variable control
  • Policy file initialization and editing
  • Sandboxed agent execution
  • No social media activity within the last 30 days
GTM channels
  • Docs
  • Changelog
ICP
  • Software developers
  • IT teams
  • Enterprises