E2B, which builds isolated virtual machines where AI agents can run code, has released a version of its stack that a software vendor can install on a single machine inside a customer’s own network. The product is called E2B Embed, and the company announced it on 30 September in a post by Vasek Mlejnsky.

The pitch targets a specific sales problem. E2B’s own post says many buyers, especially government bodies and regulated sectors such as finance and healthcare, require that their data never leave their environment. Agent companies selling to them cannot rely on a hosted service. A sandbox that lives in the customer’s server room can meet that requirement.

Under the hood, Embed is built on E2B Runtime, the open-source engine behind E2B’s hosted sandboxes. Each sandbox is a Firecracker microVM, a stripped-down virtual machine built to start fast, and E2B says the isolation matches what it offers in its hosted cloud. The databases, custom templates and sandbox logs all sit on the host’s disk rather than anywhere E2B can see them.

Developers keep the tooling they already know. The Python and JavaScript SDKs work against the local install using its own team API key, and custom templates are built with the same Template.build call. A dashboard gives an operator a view of what is running and what has been built, and each sandbox gets its own terminal and file browser. A single setting forwards metrics, traces and logs to whatever OpenTelemetry collector the customer already runs.

Installation has four routes. The simplest is Docker Compose on a dedicated Linux host with KVM, the Linux virtualization layer, which E2B describes as two files and one command. Terraform recipes cover both Google Cloud and AWS, and a Kubernetes option expects a cluster node prepared in advance. Whichever route a team picks, the full stack ends up on a single machine. On first launch the installer checks and sets up the host, fetches the Firecracker components, runs the database migrations and builds a base template. It reports success only after that template is ready.

The gaps are stated plainly. Embed has no workload identity and no bring-your-own proxy, and it ships without built-in secrets handling or volumes. It serves plain HTTP inside the network, so operators must lock down access to the API and dashboard themselves. Scaling past one machine, or having E2B run the deployment in a customer’s cloud account, falls to a separate offering called Bring Your Own Cloud.

Embed is licensed under Apache-2.0, and E2B says no account or license key is required. The post does not explain how the company earns money from it, which leaves open whether the revenue sits in the cloud and managed tiers instead. Embed reads less like a standalone product and more like a way to be present in deals that the hosted service could never enter.

E2B’s argument for the release is that an agent able to run code and touch files needs firm limits, and that no company should bet its business on the agent always behaving. The same post concedes that isolation is only one layer, next to network and access controls. That candor matters for buyers: the virtual machine contains the agent, but the customer’s security team will still ask who can reach the machine itself.

For agent vendors stuck in procurement with a regulated customer, the practical change is that the sandbox question now has a self-hosted answer. The single-machine ceiling suggests pilots and departmental deployments first, with larger rollouts waiting on the missing pieces.

Reported by E2B (post by Vasek Mlejnsky) on 30 September 2026.