Our Platform

SMART Workspace

Browser-accessible Linux dev environments with kernel-level isolation, deployable on infrastructure you own.

Modern development means running untrusted code in trusted places. AI-generated scripts. Contractor commits. Customer datasets. Prototypes from a new hire’s first week. Standard container runtimes share the host kernel, so one bad syscall in a workspace can compromise the host.

SMART Workspace gives every workspace a kernel-level isolation boundary. It federates identity with whatever your organization already runs, records every session for audit, and runs entirely on your hardware.

No meterno per-seat or per-vCPU-hour fees
1 hostno Kubernetes to operate
100%on hardware you own

Real isolation, not namespaces

Every workspace runs inside gVisor, the userspace kernel Google built for Cloud Run and App Engine. It is the same sandbox Anthropic uses to safely execute the code Claude generates, and the same one OpenAI runs Code Interpreter on. The boundary sits at the kernel, not at namespace separation alone.

Take copy.fail (CVE-2026-31431), a Linux kernel privilege-escalation chain that turns an unprivileged user into root. Under a standard container runtime, that is a host compromise. Under gVisor, the syscalls the exploit relies on are not even exposed inside the workspace. It dead-ends at the sandbox.

Your hardware. Your data. Your identity.

SMART Workspace runs on infrastructure you own. No code, no data, and no identity flows through a third party.

OIDC federation

Works with the identity provider you already run. Authentik ships bundled and federates to Okta, ADFS, Active Directory, Google, GitHub, and any OIDC or SAML 2.0 provider.

Air-gap deployable

nginx terminates TLS with certificates issued over DNS-01, so the host never needs a public IP or inbound connectivity.

No external telemetry

The platform does not phone home. All state lives on the host.

Audit-ready by default

Every session recorded

Byte-perfect transcripts of what was typed and what the shell printed, written to local disk. Recording survives reconnects, so a dropped connection never fragments the trail.

Signed git audit trail

Each closed session is committed to a per-user repository signed by the host key, with a tamper-evidence ledger line in every commit.

Privileged-action audit log

An append-only record of account, credential, and workspace lifecycle events, browsable from the admin console.

Malware scanning at ingest

ClamAV scans every web upload and blocks plus audits infected files before they reach the shared folder.

Built for federal missions

Helps you meet CMMC Level 1 and FISMA Low: SMART Workspace maps its features to NIST 800-53 controls, so your compliance lead starts from a documented baseline instead of a blank page. A readiness aid, pending assessor validation, not a certification.

FIPS-mode crypto

A FIPS-mode Ubuntu base image runs OpenSSL and OpenSSH with the FIPS provider active inside every workspace, verified under gVisor.

PIV / CAC sign-in

Smart-card login at the edge with Federal Common Policy and DoD Root CA bundles, proven with a real government PIV card.

Compliance evidence pack

Export a signed, OSCAL-based SSP bundle (control coverage plus live audit and session evidence) for your ISSO to drop into a System Security Plan.

SIEM export

Stream the audit log and session-trail metadata to Splunk, ELK, or Sentinel, so your SOC watches the platform with its own tooling. Metadata only, never session content.

Usable today

  • Self-serve workspace provisioning, bounded by admin-set quotas
  • A persistent browser shell that survives closing the tab, plus ssh <workspace>.<domain> with no port to remember and a scriptable CLI
  • Self-service SSH key management and ~/startup.d boot scripts for per-workspace setup
  • Publish a workspace’s HTTP service at a stable subdomain, public or login-gated
  • One-click sidecar services on a private per-workspace network: PostgreSQL, MySQL, Redis, and ActiveMQ Artemis
  • Multi-distro base images (Ubuntu, Fedora, and Arch), plus a FIPS-mode Ubuntu image
  • Self-hosted DNS and a single-file CLI for macOS, Linux, and Windows
  • Self-service encrypted backups to storage you control

Who it is for

Enterprise dev teams, regulated industries, and federal missions that need to give developers real Linux while keeping the blast radius contained. If your people run other people’s code, and shipping it through a SaaS workspace is not an option, SMART Workspace is built for you.

See it work

Watch the demo, or reach us at contact at 76dev.com to talk through a deployment.