Compliance starts with
where the code runs.

OmniRun runs AI agent workloads in VM-isolated microVMs in the EU, inside your perimeter, with the egress posture you choose. Here is what we can and cannot claim — stated plainly.

EU data residency

Sandboxes run in Hetzner data centers in Germany. Your code and files stay in the EU -- or on your own hardware if you self-host. Data residency is a property of where the VM runs, which you control.

VM-grade isolation

Every workload runs in its own Firecracker microVM with a dedicated Linux kernel -- the isolation model behind AWS Lambda. A kernel exploit in one sandbox cannot reach another; there is no shared kernel to cross.

Egress you control

No internet by default. internet: false is a genuine L3 air-gap. For workloads that need outbound, an opt-in SNI proxy restricts a sandbox to an allow-list of hosts -- it forwards only TLS connections whose server name matches, and drops the rest.

Scoped access

File upload/download URLs expire and are scoped to a single sandbox. Sandboxes are scoped to the creating user. Optional end-to-end payload encryption (AES-256-GCM with ECDH P-256) protects commands and files in transit.

Programs & certifications

  • Anthropic ZDR & HIPAA-BAA eligible. With Claude Managed Agents, Anthropic runs the model, so the prompt and conversation are governed by your Anthropic data agreement. That side is eligible for Anthropic's Zero-Data-Retention and HIPAA-BAA programs. Self-hosting keeps the tool-call files and repos in your perimeter.
  • SOC 2 Type II in progress. Our audit is underway. We do not claim to be SOC 2 certified yet — ask us for current status and we'll be straight with you.
  • EU-hosted (Hetzner). Infrastructure is in Germany; data stays in the EU. For full control, run the same stack on your own hardware.

One honest caveat: Anthropic runs the model, so prompts and the conversation flow through Anthropic's API in every case. Self-hosting moves the tool execution into your perimeter; it does not move inference.

Run agents where the rules require.

VM isolation, EU residency, and egress control — on your box or ours.