NEWS
Boxd Raises $2 Million to Give Agents Real Machines
BlueYard leads Boxd’s $2 million pre-seed for persistent KVM machines that AI coding agents live inside, forked in 100 to 200ms, not disposable sandboxes.
Dutch startup Boxd has raised $2 million in a pre-seed round led by BlueYard Capital to run AI coding agents on persistent KVM machines. OVNI Capital, Antler, S20 and Script Capital joined, as did business angels from General Intuition.
The cheque, announced on 15 September 2026, is small by the standards of the agent-sandbox category. It is aimed at a harder claim: that an unsupervised coding agent needs a whole computer it can live in, fork, and come back to, not a disposable sandbox reached through a tool API.
BlueYard Leads a $2 Million Pre-Seed for Boxd
Boxd was founded by Michiel Voortman, Laurentiu Ciobanu and Hidde Kehrer. Voortman, a co-founder whose public profile lists earlier stints at Microsoft and Booking, has been the product voice. Ciobanu, co-founder and CTO since May 2025, previously founded deadlock.sh and spent September to December 2025 as an Antler entrepreneur in residence in Berlin. Kehrer writes the architecture notes.
BlueYard, the Berlin firm founded in 2016, says it manages $500 million and writes cheques from $500K to $5 million. Its own essay on the building blocks of a resilient world puts computation in the fabric layer most people never see. A persistent computer for an agent that writes untrusted code sits in that layer, which is why a $2 million pre-seed from that firm is a thesis cheque, not a growth round.
Boxd said it will spend the money on hiring and on its custom virtualisation engine. The public writing came first.
THE PUBLIC BUILD BEFORE THE CHEQUE
- May 2025: Ciobanu lists himself as co-founder and CTO of Boxd.
- 8 April 2026: Kehrer publishes the manifesto that the agent belongs inside the VM, not outside it.
- 14 August 2026: Voortman, Kehrer and Ciobanu publish Billions of Machines, the nine requirements they say an agent has of a computer.
- 15 August 2026: Voortman turns those requirements into Boxd 101, each one as a command.
- 14 September 2026: Ciobanu publishes the fork-identity deep dive, and the company account posts a demo of live app URLs.
- 15 September 2026: the $2 million pre-seed is announced.
That sequence is the point of the round. The investors are paying for an engine and a team that have already been arguing, in public, that the sandbox model is a temporary crutch.
The Agent Belongs Inside the Machine
Kehrer’s April note is blunt. Most agent platforms keep the model on one host and reach into a sandbox through typed tools such as file.read, file.edit and shell.exec. The sandbox is passive. The brain lives elsewhere. He calls that a reasonable way to ship, and the wrong primitive to build on.
boxd is built on a single architectural bet: the agent belongs inside the machine, not outside it.
Hidde Kehrer, co-founder, Boxd manifesto, 8 April 2026
The cost of the split, as he tells it, is a keyhole. An agent outside the VM serialises intent into command strings, waits on the network, and parses text back. An agent inside the VM is a process on an OS. It reads files at disk speed, tails logs as they stream, and talks to local services over localhost. Forking only clones the environment if the agent sits outside; the copy does not inherit what the agent was thinking. Put the agent in the VM, and a fork captures environment, agent state and in-progress work together.
That is the sentence the product hangs from: the agent belongs inside the machine. Kehrer is honest about the other side. If models plateau and still need heavy scaffolding, the separated architecture wins, because it is more controllable and easier to audit. If they keep improving, agents with full computers will beat agents that work through keyholes. Boxd is betting on the second world.
On the funding day Kehrer put the same idea in operational language. Every AI coding agent, he said, needs a real computer rather than a disposable sandbox, because container alternatives pick up security holes and drop state when processes finish. Boxd’s answer is a hardware-isolated persistent VM that can be live-forked in milliseconds.
Billions of Machines, the August manifesto from all three founders, lists what that computer has to provide. Isolation, speed, branches, a whole computer, composition, memory, handoff, an API, and idle that costs nothing. The docs homepage goes further and says 99.9% of code will soon be written and maintained by agents, who will need billions of these machines. That figure is Boxd’s claim, not a measured share of the world’s commits.
What a Default Boxd Machine Includes
A Boxd machine is a KVM virtual machine with its own kernel, not a container sharing the host’s. It boots in about 6 milliseconds, according to the company’s docs, and it is on the internet the moment it exists, at its own HTTPS address with a certificate already issued. The guest is unminimised Ubuntu 24.04 with systemd, passwordless sudo and the docker group.
THE DEFAULT MACHINE
| Item | What ships |
|---|---|
| Compute | 2 vCPU, 8 GB RAM, 100 GB persistent disk, root |
| Isolation | KVM, dedicated kernel, hardware boundary |
| Cold start | About 6 milliseconds (company figure) |
| Live fork | 100 to 200ms, memory and disk |
| Sleep | Hibernates when idle; resume under a millisecond |
| Agents on the image | Claude Code, Codex, OpenCode |
| Also preinstalled | Docker, Python 3, Go, git, headless Chrome, ffmpeg, nginx |
| Not preinstalled | Node.js (apt or nvm) |
| Host region | EU hardware by default; a US region is coming |
Boxd says it skipped emulating extra hardware such as audio devices, webcams and USB ports, which shrinks the software attack surface for an agent that already has root inside its own guest. Isolation, in the FAQ, is the hardware boundary: a CVE in one guest kernel is not a path to the host or to a neighbour. Agents get root inside the box and still cannot touch anything outside it.
Claude Code, Codex and OpenCode ship on every machine. Claude Code is keyed to the Boxd account, so a sign-in follows the user across forks, resets and new VMs, with the credential stored encrypted and injected at boot. Codex and OpenCode need a one-time login per machine, and that login persists on disk into forks. The in-VM Boxd CLI is pre-authenticated, so any of the three can create sibling machines, exec into them, and publish ports without a fresh token.
SSH is the interface. There is a gRPC API under the CLI, and every command takes –json, but the pitch is that a person and an agent use the same computer. Voortman said the same in a reply under the company demo: the gain for him is how easily a full-stack app can be shared.
share full stack apps with your team
build whatever you want with your favorite coding agent, and it's live. every boxd machine ships with a url, open to the internet or kept inside your company networkhttps://t.co/wUsrbhpKWp pic.twitter.com/MZIS5DatPf
— Boxd.sh (@boxd_sh) September 14, 2026
The demo, posted on 14 September 2026 by @boxd_sh, is a running app at a URL, open to the internet or held inside a company network. That is the artefact people actually argued about the day before the round, more than the fundraise itself.
A Fork Wakes Up Mid-Thought
A fork copies a running machine, not the disk alone. Memory and processes come too, so the copy wakes up mid-thought with the database already seeded and the server already listening. Boxd’s docs put that copy at 100 to 200ms. The company’s comparison table calls fork impossible on serverless functions, a snapshot-and-restore job on a classic VM, and an image rebuild on a container.
That speed is what makes parallel work cheap enough to attempt. Fork once per task and each agent gets a database to itself, a port 3000 to itself, and an address of its own. Nothing collides. Each result is live and clickable before anyone decides which branch to keep. Snapshots are the other primitive: save memory and disk under a name, then stamp out new machines from that golden image days later. Checkpoints are the undo button, ten per machine, so an agent can attempt a risky migration and rewind without changing the URL.
The ugly residue of a live fork showed up the day before the money. Ciobanu’s 14 September note, Every Clone Wakes Up Confused, is about the first milliseconds after a fork. The copy inherits beliefs that are no longer true: its clock, its timer, its address, its randomness. Repairing that, he writes, takes an NMI, two pointless register writes and a real-time signal. If the product thesis is that agents will fan out into ten copies of a running stack, this is the kind of bug that thesis creates. It is also the kind of bug a $2 million engine budget is for.
Sleep is the other half of fan-out. A machine with no traffic drops to standby on its own. CPU and memory go to zero, the disk and the address stay, and the first packet wakes it in under a millisecond. What comes back is the same process list, the same warmed cache, the same open connections. Boxd’s argument is that agents leave far more machines running than people ever would, so idle has to cost close to nothing or the swarm never gets tried.
The Sandbox Vendors Got There First
The category Boxd is walking into is not empty. Its own FAQ sets the contrast in product terms, not in fundraising.
HOW BOXD DRAWS THE LINE
- E2B: Ephemeral Firecracker sandboxes driven by an SDK; Boxd calls that a retrofit of persistence onto a short-lived primitive, and says pick E2B for stateless code execution with no persistence.
- Daytona: Container-based dev environments on a Postgres, Redis and Harbor stack; Boxd says pick it if you want that model and will operate those services.
- GitHub Codespaces: GitHub-hosted devcontainers that bill while idle and live inside GitHub; Boxd says pick them if the team is already in that browser editor.
- Modal: A serverless Python runtime on gVisor; Boxd says pick it for a function that fans out, runs and exits.
The honest reading of that list is that Boxd is late to a lane other products already sold. Firecracker sandboxes, container workspaces and gVisor functions are in production. Pause, resume and snapshot are no longer exotic. What Boxd is selling as the difference is where the agent process sits, how you reach it (SSH, not only an SDK), whether fork copies live memory, and whether the whole control plane is one Rust binary you can drop in a VPC.
Kehrer’s own caveat still applies. If the models stay unreliable enough that every action must be a typed tool call with an approval trail, the keyhole architecture is the product. Boxd only wins the bet if the models are trusted with a raw computer, and if teams want that computer to be a persistent, forkable Linux box with a public URL.
Self-host is the European edge in that comparison. Managed Boxd runs on EU hardware with no US cloud dependency, GDPR by default, and worker nodes on a private OVH vRack with no public IP. The same binary can sit in a customer’s datacenter or country. The FAQ pitches that install at a two-person startup and at a bank’s DORA and NIS2 review, because the external-services answer is none: no Kubernetes, no external Postgres, no Redis.
You Pay for Disk While It Sleeps
Billing is credit-based. There is no monthly plan and no per-seat fee. An organisation’s machines draw down credits on a published rate card.
THE RATE CARD
- CPU: credit rates of €0.049 per vCPU-hour, billed only while the machine is actually running.
- Memory: €0.015 per GiB-hour of RAM, charged on a running box and on an optional warm suspend that keeps memory resident.
- Disk: €0.0001 per GiB-hour, and a hibernated machine pays only for space actually used, not the 100 GB provisioned.
- Default box: 2 vCPU and 8 GB is about €0.22 per hour while it runs. New accounts get €30 of credits after adding a card, then auto top-up in €20 steps.
Each organisation starts with a quota of 50 machines. Larger shapes than 2 vCPU and 8 GB are a conversation with the company. That quota is the practical limit on the “billions of machines” line: the architecture wants a swarm, the default account does not.
For a team that already burns cloud VMs all day, €0.22 an hour is ordinary. For a coding agent that forks ten copies of a stack, tries them, and lets nine hibernate, the sleep rule is the product. vCPU drops off the bill the moment the box is not running. If hibernation fails to fire, or if warm suspend is left on, the RAM line keeps ticking. The rate card is simple. The operational trap is leaving memory warm.
$2 Million Goes Into the Virtualisation Engine
The FAQ names the layer under the product. Self-hosted Boxd can sit on the open-source microVM engine Ignition, a Rust project at lttle-cloud that aims to boot a microVM and serve traffic in under 10 milliseconds, as a single binary, with no vendor lock-in. Boxd’s round language is that the pre-seed will further develop a custom virtualisation engine. Those are compatible facts: a named open engine underneath, and paid work on the VMM the agents actually sit in.
The self-host binary is nine Rust crates compiled together: control plane, worker, proxy, DNS, Raft, CLI, per-VM VMM, in-VM agent, and a single-node combined build. Raft is the coordination layer. RocksDB holds the log. Embedded SQLite holds materialised state. Each VM is its own OS process, so a supervisor crash does not take the guests with it. That is the simplicity Kehrer has been selling since April as the moat: no Postgres, no Redis, no Kubernetes, drop it on a KVM host.
A $2 million pre-seed does not buy a region fleet. The docs still warn that US traffic to the EU host crosses the Atlantic, and that a US region is coming. The homepage still had a layout bug the day before the announcement, which the company account said it was fixing. The public conversation under the demo was “cool if it works properly,” which is the right scepticism for a live-fork of a running kernel, a database and an agent session in 100 to 200ms.
What the cheque does buy is time on that engine, and people to run it, while the founders keep the bet they already wrote down. If the models stay behind a tool API, the money is a small European VM host with a nice sleep story. If the models take the raw computer, the scarce thing is a machine that can be forked mid-thought and left idle for close to nothing, and Boxd is now paid to build that machine in the open.
-
LIFESTYLE3 years agoWhere Can I Cash a Comcheck – What Are My Options?
-
BUSINESS4 weeks agoThe Yen Rally Was Funded by a Record Reserve Sale
-
BUSINESS1 month agoOpenAI Turns ChatGPT Into a $1 Billion Ad Auction
-
NEWS4 weeks agoCoremail Pitches AI-Native Email Security at LEAP 2026
-
NEWS3 weeks agoGottheimer’s AI LABS Act Enters an Already Crowded Field
-
TECHNOLOGY3 years agoHow Many Cards in a Uno Deck – What’s the Exact Number?
-
LIFESTYLE3 years agoThings to Do with a Teenager Near Me – What Are Some Fun Ideas?
-
NEWS4 weeks agoArm Bets Compute Subsystems Will Reach Physical AI
