Deno Sandbox is a new feature that allows users to run untrusted code in secure Linux VMs, providing defense-in-depth security and controlling network egress and protecting secrets from exfiltration. This is particularly useful for platforms where users generate code with LLMs that runs immediately without review. Deno Sandbox provides a way to sandbox the compute and control network access, and also allows for secrets to be protected from exfiltration. The feature is included in Deno Deploy plans with competitive, usage-based pricing.