Cone of Silence
Cone of Silence is our agent-pod service: your own always-on AI agent — Claude, working for you around the clock — running inside a hardened sandbox on a dedicated pod, reachable from your phone over Telegram. Message it like a person; it reads, researches, codes, and runs real tools — while everything it touches stays inside a security boundary we built and operate.
Always-on agents are the most exciting — and most exposed — thing happening in computing right now. Internet-wide scans this year found tens of thousands of personal AI agents running openly exposed, unsandboxed, with full access to their owners’ machines and credentials. The ecosystem’s defaults are convenience-first. Ours are not.
Security is the product
Each agent pod is built on Claudette, our open-source hardened agent sandbox, plus the same layered controls we deploy in our AI security engagements:
- Sandboxed by default. The agent runs in OS-level isolation (bubblewrap) — it sees its project workspace, not the system. No “full access” mode, no opt-in security.
- Scoped credentials. Per-project keys generated inside the sandbox; one project’s tokens can never leak into another’s. Your personal credentials never enter the pod.
- Prompt-injection scanning. Everything the agent reads — web pages, files, command output, messages — is screened for injection patterns before it reaches the model.
- Paired-device Telegram access. Your pod answers you, not whoever finds the bot. Pairing is explicit, allowlisted, and fail-closed — and access changes are never approved over the channel itself.
- Default-deny egress and an audit trail — the same philosophy as everything we build.
And unlike the original cone, ours actually works — the mechanism is open source, so you can check.
Managed, not abandoned
We provision the pod, harden it, pair your devices, and keep it patched and monitored. You get a monthly security review of what your agent did, what it touched, and what we tightened. When you outgrow one pod, we scale the same model to a fleet.
An honest threat model
Like Claudette itself, a pod defends an honest agent against hostile inputs — injection, credential theft, runaway tool use. It is not a magic box that makes AI output trustworthy, and we won’t pretend otherwise. Knowing exactly what a control does and doesn’t cover is the whole job.
Engagement & pricing
- Pod onboarding — $1,500 one-time. Provisioning, hardening, Telegram pairing, credential scoping, and a working-session handover. Your scoping call is credited toward it.
- Managed agent pod — from $195/month. Dedicated hardened pod, monitoring, patching, and the monthly security review. Bring your own Anthropic API key — your usage stays on your account, at cost.
- Fleets & teams — by proposal.
Early-access pricing for our first cohort of design partners; indicative, finalized at scoping.
Book a scoping call Request early access