---
title: Islo
slug: islo
url: "https://toolweight.com/options/islo"
homepage: "https://islo.dev"
categories: sandbox-providers
last_verified: 2026-07-23
license: CC-BY-4.0
---

# Islo

> Per-agent isolated cloud sandboxes with enterprise policy controls, from Incredibuild.

Islo gives each coding agent its own isolated cloud environment, governed by policies over what the agent may reach, codebases, infrastructure and connected systems. Its capability cells here are transcribed from a competitor's comparison table, which credits it with BYO repos plus a setup script, SSH, Docker in the guest, 24/7 operation, a dedicated IPv4 and full TCP/UDP with your own domain. Nothing on this row is a toolweight measurement, and the fields that table does not cover are left unknown.

## Identity

|  |  |
| --- | --- |
| Name | Islo |
| Company | Incredibuild |
| One-liner | Per-agent isolated cloud sandboxes with enterprise policy controls, from Incredibuild. |
| Site | https://islo.dev |
| Compared in | 1 |

## Where it is compared

### [Sandbox providers](https://toolweight.com/compare/sandbox-providers)
Ranked **#10 of 20** on default weights.
| Field | Value | Confidence | Verified | Source | Note |
| --- | --- | --- | --- | --- | --- |
| Cold start | - | Unknown | - | - | toolweight has not measured Islo, and the comparison table it appears in publishes no boot figure for it. |
| Cold start (claimed) | - | Unknown | - | - | Absent from the "<500ms time to VM-ready" row of a competitor's table, which is not the same as Islo claiming anything either way. |
| Isolation | - | Unknown | - | - | The table claims Docker inside the VM but names no hypervisor or isolation technology. Islo markets isolation heavily; none of that detail is in this source. |
| Root in guest | ● | Inferred | 2026-07-23 | https://box.ascii.dev/compare | Derived from the "Docker inside the VM" row: a Docker daemon in the guest implies root. The table claims Docker, not root. Transcribed from box's comparison table, a competitor's chart, not Islo's own documentation, and not verified by toolweight. |
| Egress control | - | Unknown | - | - | Not a row in the table, which is the awkward part: policy control over what an agent can reach is Islo's headline pitch, and this source does not test it. |
| Max runtime | - | Unknown | - | - | The "No session cap / runs 24/7" row is a marketing statement in a competitor's chart, not a runtime ceiling Islo publishes. Left unknown rather than awarded this page's 24 h maximum. |
| Persistent FS | - | Unknown | - | - | Not a row in the table. |
| Snapshot & fork | - | Unknown | - | - | Islo is absent from both the "Fast disk snapshots / branching" and "Process fork" rows. A rival declining to tick a box for a competitor is not the table addressing the field, so this is recorded as nothing rather than as a no, the previous "no" scored Islo zero on a weight-8 field on a competitor's say-so. The asymmetry is deliberate: box's and ascii's own absence from the process-fork row is credited, because a vendor conceding a gap in its own product is evidence and a vendor asserting a gap in someone else's is not. |
| Custom images | ◐ | Inferred | 2026-07-23 | https://box.ascii.dev/compare | Derived from "BYO repos + arbitrary setup script", a base extended by a setup script, this field's partial. The mapping is ours. From a competitor's table, unverified. |
| GPU | - | Unknown | - | - | Not a row in the table. |
| Runtimes | - | Unknown | - | - | Not a row in the table. |
| Preview URLs | ◐ | Inferred | 2026-07-23 | https://box.ascii.dev/compare | Derived from two rows that are not about preview URLs, "Dedicated IPv4 per VM" and "Full TCP/UDP + BYO domain": reachable ports on a domain you own rather than a first-party HTTPS URL from the API. The mapping is ours. Competitor's table, unverified. |
| Browser inside | - | Unknown | - | - | Not a row in the table. |
| File up/download | ◐ | Inferred | 2026-07-23 | https://box.ascii.dev/compare | Derived from the "SSH access" row: scp and sftp follow from SSH, and CLI-only access is this field's partial. No first-party file API is described. Competitor's table, unverified. |
| Sydney region | - | Unknown | - | - | The table says nothing about regions. |
| Concurrent limit | - | Unknown | - | - | Absent from the "1000+ concurrent VMs ergonomically" row; no figure is given. |
| MCP server | - | Unknown | - | - | Not a row in the table. |
| SDKs | - | Unknown | - | - | Not a row in the table. |
| Streaming output | - | Unknown | - | - | Not a row in the table. |
| Price / hour | - | Unknown | - | - | No rate for a comparable vCPU/RAM shape has been verified from Islo directly. |
| Meter | - | Unknown | - | - | Islo is absent from the "Flat pricing" row, which implies a meter rather than a flat fee but does not say what the meter is. Left unknown rather than guessed. |
| Idle cost | - | Unknown | - | - | Not a row in the table. |
| GitHub stars | - | Unknown | - | - | - |
| Funding | - | Unknown | - | - | - |
| Shipped | - | Unknown | - | - | - |
| Positioning | An isolated cloud environment per coding agent, with enterprise policy control over what it can reach. | Vendor-claimed | 2026-07-23 | https://islo.dev | Paraphrased from Incredibuild's own launch material. The capability cells on this row, unlike this one, come from a competitor's comparison table. |

**Verdict.** The enterprise-shaped entry in this group and the one this source serves worst. Islo's pitch is governance, an isolated environment per agent, with policy over which repos, systems and secrets it can touch, and the competitor's table it appears in has no column for any of that, so the row shows a capable long-running VM and nothing about the thing Islo is actually sold on. Credited with BYO repos, SSH, Docker, a dedicated IPv4 and full TCP/UDP. Not denied snapshots and forking: the chart simply omits Islo from those rows, which is a competitor declining to tick a box rather than a finding, so those cells are unknown here. Verify from Incredibuild's own documentation before shortlisting.

## Alternatives

- [ascii](https://toolweight.com/options/ascii), Agent orchestration over Telegram, running on box's VM infrastructure.
- [Blaxel](https://toolweight.com/options/blaxel), Agent-first cloud claiming ~25 ms microVM boots from snapshots.
- [box](https://toolweight.com/options/box), Persistent Linux VMs with SSH, per-VM IPv4 and disk-level forking, priced flat.
- [Cloudflare Sandbox](https://toolweight.com/options/cloudflare-sandbox), Container sandboxes driven from a Worker, addressed through Durable Objects.
- [CodeSandbox SDK](https://toolweight.com/options/codesandbox-sdk), Firecracker VMs with memory snapshots, from the online IDE, now owned by Together AI.
- [Daytona](https://toolweight.com/options/daytona), Sub-second container sandboxes for agent workloads, from a team that built a dev-env manager.
- [Self-hosted Firecracker](https://toolweight.com/options/diy-firecracker), The baseline: Firecracker on your own metal, plus every hard part you now own.
- [E2B](https://toolweight.com/options/e2b), Open-source Firecracker sandboxes with Python and TypeScript SDKs for AI agents.
- [exe.dev](https://toolweight.com/options/exe-dev), Persistent VMs you SSH into, with root, apt and systemd, on a flat monthly plan.
- [Fly.io Machines](https://toolweight.com/options/fly-machines), Raw Firecracker microVMs with a REST API, durable volumes and 35+ regions.
- [Freestyle](https://toolweight.com/options/freestyle), Run untrusted JavaScript and full dev servers, with git hosting and domains built in.
- [GitHub Codespaces](https://toolweight.com/options/github-codespaces), Devcontainer-backed cloud VMs built for humans, occasionally repurposed for agents.

## Licence and attribution

Data from toolweight (https://toolweight.com), licensed CC-BY-4.0.

- Licence: [CC-BY-4.0](https://creativecommons.org/licenses/by/4.0/)
- Canonical HTML: https://toolweight.com/options/islo
- Machine-readable: https://toolweight.com/options/islo.md · https://toolweight.com/api/v1 · https://toolweight.com/mcp
- toolweight takes no affiliate revenue and sells no placements. Corrections: https://toolweight.com/suggest
