Accessibility Adjustments

Use these optional tools to adjust reading and display preferences. These tools cannot resolve every accessibility barrier. Please contact the website owner if you need assistance.

  • Text adjustments
  • Content scaling 100%
  • Font size 100%
  • Line height 100%
  • Letter spacing 100%
  • Colour adjustments
  • Orientation adjustments

Perplexity launches SPACE to isolate persistent computer agents

Listen to this article

Long-running agents need a place to work that is not your laptop and not a shared container with your keys in the guest. Perplexity says that place is now SPACE โ€” Sandboxed Platform for Agentic Code Execution โ€” the sandbox layer under every Perplexity Computer session.

Off-the-shelf sandboxes forced a pick-two among security, functionality, and efficiency. Computer needed all three. SPACE is the bet that agent runtime is infrastructure, not a side feature bolted onto chat.

Why Firecracker microVMs for agents

Each task runs inside a Firecracker microVM with its own Linux kernel and a minimal device model. That is hardware isolation, not process niceness on a shared host kernel. If the guest is compromised, the blast radius is meant to stop at the VM boundary instead of hopping tenants.

Sandboxes are ephemeral. They live only as long as the task needs code execution or file work, then the sandbox and everything in it are destroyed. SPACE wraps the untrusted workload with network controls, tenant separation, and encrypted storage. A space daemon inside the guest is the only process that talks to Perplexity’s control plane, carrying start, pause, and snapshot signals on an auditable channel.

Perplexity says engineers ran SPACE internally for two months before launch. Over the launch week it supported millions of sandbox creations and tens of millions of reconnects. An early NVIDIA Vera CPU test, per company materials: Computer-style workflows about 1.5x faster than the current production reference, concurrent sandbox starts up to 1.9x faster. Treat that as a backend signal, not a general SLA.

Pause, resume, and fork semantics

Agents do not finish in one chat turn. They accumulate context, files, and processes across minutes or hours. SPACE wraps each sandbox in a session that can pause, resume, or branch into multiple sandboxes. Rolling snapshots carry context with the work even though no single sandbox persists forever.

Perplexity says SPACE can snapshot full session state โ€” live memory plus files โ€” as often as every minute, and resume a week later from where the agent paused. Forking lets a session branch; rollback undoes a bad step without a cold restart. Against the prior provider on the same traffic, median create latency fell from 185ms to 60ms, with p90 dropping from 447ms to 89ms. Those are vendor benches on its own production load.

Credential handling inside SPACE

Credentials stay outside the sandbox. Node-level services inject them only when needed โ€” at the network layer or via a controlled sign-in flow โ€” so a compromised agent has no default path to platform-managed secrets. Outbound traffic is gated the same way: the agent cannot reach destinations outside its permitted scope.

Enterprise customers can bring their own encryption keys. Revoke the key and new sandboxes cannot boot, while existing customer-encrypted data becomes undecryptable. Perplexity also pitches on-prem and offline modes for sensitive workloads. The architecture goal is clear: powerful agents without parking API keys on the guest disk.

What this changes for Computer users

If you use Computer today, you are already on SPACE. Perplexity says 100% of Computer sessions run on it. The practical shift is less “new button” and more “the agent can stay stateful without leaving keys on the floor.” Pause mid-task, come back later, fork a risky branch, keep secrets off the guest.

Analysis: this is Perplexity admitting that chat sandboxes were never enough for agents that edit files and call APIs for hours. Firecracker plus external credentials is the right architecture shape. The open question is whether operators get enough visibility into egress policy and injection scope when something goes wrong โ€” and whether “live for all users” holds under the next wave of adversarial agent demos.

Jordan Reid
Jordan Reid

Jordan Reid is focused on AI tools, agents, developer products, and the way technology changes everyday work. Jordan approaches a launch from the userโ€™s side of the screen. What can it actually help someone finish? The voice is practical, conversational, and skeptical of products that turn a simple job into five new settings. Coverage follows coding assistants, creative software, browser agents, and the workflows around them, with attention to pricing, permissions, setup, and the human work that remains.

Leave a Reply

Your email address will not be published. Required fields are marked *

Gravatar profile