Docker is not isolation.
Containers share one Linux kernel. Your neighbour's bug becomes your bug. The container escapes are documented, public, and exploited in the wild.
The secure managed agent platform. One Firecracker microVM per agent — your keys never leave it. From $25/mo with a 30-day money-back.
Firecracker · KVM boundary
Lives only in your VM
No questions asked
Nine open-source agent runtimes — Hermes, OpenClaw, Paperclip, Claude Code, Codex, OpenCode, Goose, Grok, Pi — each in its own KVM-isolated microVM with your own keys. Pick one to start; add more later, each in its own VM, billed at its plan's rate.
The category default for managed AI agents is a Docker container with a friendlier dashboard. That stops being acceptable the moment your agent has the keys.
Containers share one Linux kernel. Your neighbour's bug becomes your bug. The container escapes are documented, public, and exploited in the wild.
Most platforms proxy your model spend through their account. Lock-in by design + vendor markup on every token. You don't own the relationship with your provider.
DIY agent infra is renting a box, opening firewall ports, wiring TLS, persistent volumes, systemd units, log forwarding — and then you've earned the right to install Hermes. A managed agent shouldn't ask you to be a sysadmin first.
Multi-tenant bare metal in Frankfurt. One Firecracker microVM per tenant. Same KVM hardware boundary AWS uses for Lambda.
KVM hardware boundary per tenant. The same primitive AWS uses for Lambda. 124ms boot.
OpenRouter, OpenAI, Anthropic, Nous Portal. Paste once, lives only inside your VM.
Cancel within 30 days for a full refund. Manual processing within one business day.
you.jurniti.com with valid TLS, ready when the VM boots. Pro and Max plans.
We ship uv and the upstream install script; you control which Hermes version lands.
/var/lib/jurniti/persist survives restarts and re-provisions. Daily snapshot on Max.
Run inside the microVM you provisioned. We don't pre-install Hermes — you control the version, the upstream installer is one curl away.
# Boot one tenant microVM
$ hermes config set OPENROUTER_API_KEY sk-or-v1-...
$ hermes dashboard --host 0.0.0.0 --port 9119
# 124ms later …
→ tenant.you.jurniti.com · KVM-isolated
Pay monthly, or go annual and get 2 months free. 30-day money-back guarantee.
Annual · $250/yr (2 months free)
Annual · $490/yr (2 months free)
Annual · $990/yr (2 months free)
From $25/mo. BYOK. 30-day refund. Boots in 124ms.
Annual plans get 2 months free. Every plan ships a 30-day money-back guarantee.
Fork any of these to spin up a new microVM seeded with the creator's configuration. New $25+/mo subscription per fork.
OpenClaw · starter
dogfood factory openclaw (public)
Hermes Agent · starter
dogfood factory hermes (public)
Claude Code · starter
Fork @affaan's grand-prize Everything Claude Code — 64 agents, 261 skills, hooks & rules — onto your own isolated microVM. Your Claude login, your keys, live in ~3 min.
Claude Code · pro
A Claude Code agent pre-loaded with the HyperFrames video toolkit. Turn a short design.md or a one-line prompt into a finished promo or product-launch video, then preview it online. Fork it, add your HyperFrames key, and ship your first reel in minutes.
DeepAgents Code · starter
A ready-to-run DeepAgents Code (dcode) coding agent pre-wired to GLM-5.2 on OpenRouter. Bring your OpenRouter key and code with an open-weight model for cents — shell tool enabled, GLM-5.2 set as the default model.
Hermes Agent · starter
A Hermes agent preloaded with the open-source newsjack.sh PR-team skills — angle generation, headline writing, fact-check, journalist-fit, newsworthiness, and more. Add your model key and it is a PR team in your terminal.