Engineering·4 min read
Why every generated app gets its own container
AI-written code is untrusted code. MoboStudio AI treats it that way — from the kernel up.
When software writes software, you have to assume the output can do anything — including things nobody asked for. So in MoboStudio AI, generated code never runs next to the platform. It runs in a project runtime built to contain it.
The production runtime
- One container per project, running as a non-root user.
- All Linux capabilities dropped, with no-new-privileges set.
- CPU, memory and process limits, plus a size-limited disk.
- An isolated network with inter-container traffic disabled — apps can’t reach each other.
- A host firewall that blocks new connections from app containers to private ranges.
Previews without leaking sessions
Live previews are served through a gateway on their own domain, so the MoboStudio AI session cookie never reaches generated code. A preview can’t impersonate the person looking at it.
Secrets never enter the prompt
The agent sees the names of a project’s environment variables — never their values. Values are encrypted at rest with AES-256-GCM, each bound to its row through additional authenticated data, so an encrypted value can’t be moved to another project and decrypted there. Logs are masked before they’re written anywhere.
Isolation isn’t a feature anyone notices. It is the reason you can let an AI run code at all.