You're about to let strangers run code on your computer to earn money. That's a fair thing to be nervous about. Here is exactly what a buyer can and cannot do — no hand-waving.
Buyer code runs inside an OS-level sandbox. It can read and write one folder — its own scratch space — and nothing else. We didn't just claim this; we ran the six attacks a malicious buyer would try, from inside the exact sandbox:
| Attack we ran | Result |
|---|---|
| Read your Documents folder | 🛡 Blocked |
| Steal SSH keys / saved passwords (Keychain) | 🛡 Blocked |
| Write a file to your Desktop | 🛡 Blocked |
| Read GridShare's own config (holds your API key) | 🛡 Blocked |
| List your home folder's contents | 🛡 Blocked |
| Reach another buyer's instance data | 🛡 Blocked |
The buyer can only touch ~/.gridshare/native/<their-instance>/work. Your personal data is invisible to them — they can't see it, copy it, damage it, or plant anything on your machine.
On a Mac it's Apple's built-in sandbox-exec (the same isolation technology macOS uses for App Store apps). On Linux/NVIDIA nodes it's Docker container isolation. Either way the workload runs as a jailed process: it gets the CPU/GPU you're renting out, and nothing else.
…but jailed. Think of it like a locked room inside your house: they can use the workbench (GPU/CPU) we put in that room, but every door to the rest of the house is bolted. They never get your login, your shell, or your files.
Workloads need the internet (to download models and datasets), so the sandbox allows outbound traffic. The risk is a buyer abusing your connection — mining crypto, scanning, or flooding. Our abuse monitor runs every 30 seconds on your node and watches for exactly that, using only connection metadata (never your traffic contents):
Every kill is logged and the buyer's account is flagged. Repeat offenders are banned.
Sustained compute means heat and electricity, like running a game for a few hours.
Your machine is yours first — pause it from your dashboard any time, and if a rental is running, message us and we will end it. Every workload is sandboxed away from your files and watched around the clock. We deliberately layer these protections so no single safeguard has to be perfect — that's how serious infrastructure is built. Earn from your idle GPU with peace of mind.
Your files are walled off, the network is watched, and your hardware is protected.
Add your machine — sign up / sign in → Provider Portal →