> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tokenfactory.nebius.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and data handling

> Protect data and credentials across uploads, output, images, networking, and local downloads.

Sandboxes runs workloads in VM-level isolation. Treat the sandbox as a boundary for workload execution, while controlling which data and credentials enter it.

| Where data is stored | Behavior | Requirements to confirm before use |
| - | - | - |
| Uploaded inputs | Attached to an operation and available at specified guest paths | Retention, deletion, encryption at rest, size limits |
| stdout/stderr/stdin records | Capped per stream and returned with operation results/events | Event/log retention and diagnostic-log access |
| Result images | Filesystem continuation point when persistence produces one | Deletion, encryption, region, tagged/reference exceptions |
| Preserved environment | `preserve_env=true` writes merged environment values to image metadata | Retention and deletion behavior |
| Local downloads | Written to the caller's filesystem | Governed by the caller's storage controls |

## Network boundary

`networking.enabled=false` starts the VM without a guest network interface. The setting defaults to true and must be supplied on every relevant spawn. If a workload requires destination allowlists, private networking, ingress, specific DNS controls, or customer network logs, confirm support with the Sandboxes team before deployment.

## Handle credentials

Keep the Sandboxes API token outside guest code. Use short-lived, least-privilege workload credentials, pass them only when needed, and avoid retained files, preserved environment metadata, command lines, and output. Do not place registry passwords in Dockerfile build arguments or source.

A disposable filesystem result only prevents the run's filesystem changes from becoming a continuation image. It does not confirm deletion of uploads, operation records, or platform logs. Contact [contree@nebius.com](mailto:contree@nebius.com) before using data that requires a specific encryption-at-rest, residency, deletion, or retention guarantee.

For support, share operation and image UUIDs, timestamps, client versions, terminal status, and redacted errors. Remove tokens, customer files, environment values, and unredacted output.
