Features / Hosted in Germany

Your sandboxes stay in Germany.

pols runs on dedicated servers in Hetzner data centres in Falkenstein and Nuremberg, set up and operated by us. Disks, templates, the API and the vault all live there, and requests reach them without a CDN in between.

curl -fsSL https://pols.so/install.sh | sh
Vault encryption, key kept outside the database
AES-256-GCM
Network modes per sandbox: open, allowlist, none
3
Trackers, cookies or third-party scripts on this site
0

Secrets by name, network by choice

Keep API keys and passwords in your organization's vault on my.pols.so. A sandbox gets them as environment variables; API keys can list the names but never read a value.

Choose each sandbox's outbound network when you create it: the open internet, only the addresses you allow, or nothing. A fork keeps its source's choice.

pols CLI
# names and kinds, never values
$ pols vault ls
# arrives as the environment variable ANTHROPIC_API_KEY
$ pols new --name agent --secret ANTHROPIC_API_KEY
# code you have not read: no network at all
$ pols new --name untrusted --egress none
# or only the addresses you allow
$ pols new --name ci --egress allowlist --allow 203.0.113.10/32

What is kept where

Sandbox disks, snapshots and templatesZFS on our servers in Germany
Accounts, sandboxes, usage and the vaultPostgres on the same servers; vault values encrypted
API keys, login links and sessionsOnly a SHA-256 hash
Login emailsLettermint, processed in the EU
DNSCloudflare, DNS only: traffic never passes through it

pols is run by PEWEO Sàrl in Luxembourg, so your contract partner and the law that applies are European. What we process and why is in the privacy policy.

More of pols

Start with one machine.

Install the CLI, sign up, and give your agent somewhere to work.

curl -fsSL https://pols.so/install.sh | sh