{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "agent37",
    "name": "Agent 37 Cloud",
    "vendor": "Agent 37 Inc.",
    "vendorUrl": "https://www.agent37.com/cloud",
    "kind": "http-api",
    "category": "code-sandboxes",
    "summary": "Agent 37 Cloud hosts persistent Linux sandboxes for agent harnesses such as Hermes, OpenClaw, Claude Code and Codex, or a custom Docker image. A REST API creates instances, runs commands, manages files and sends messages to the agent inside.",
    "url": "https://www.anchorterminal.com/tools/agent37",
    "markdownUrl": "https://www.anchorterminal.com/tools/agent37.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/agent37.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/agent37.json",
    "repo": "https://github.com/agent37-platform/templates",
    "license": "Proprietary service under Agent 37's terms of service. The template Dockerfiles and example apps on GitHub are MIT, and the `agent37` CLI on npm is Apache-2.0",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.agent37.com/v1",
    "packages": [
      {
        "registry": "npm",
        "name": "agent37"
      }
    ],
    "auth": "api-key",
    "authNotes": "Self-serve. A person signs up, adds a card and creates an `sk_live_` key in the dashboard, where the full key is shown once. The key is workspace-wide and goes in `Authorization: Bearer` on https://api.agent37.com/v1 and in the `X-Agent37-Key` header on each instance URL. A key can carry an IP allowlist of up to 20 addresses or CIDR ranges. No scopes, read-only keys or key-creation API were found. Browsers reach an instance port through a signed URL that lasts 60 seconds to seven days and can't be revoked.",
    "pricing": "usage",
    "pricingNotes": "Prepaid balance, metered per minute. $0.80 a vCPU-month, $0.70 a GB-month of memory and $0.09 a GB-month of disk on a 730-hour month, so 2 vCPU and 4 GB with a 4 GB disk is $4.76 a month running and $0.36 a month asleep or stopped. Performance instances on dedicated cores cost four times the compute rate. Adding a card grants a one-time $5 credit with nothing charged, limited to one 2 vCPU, 4 GB instance until the first top-up. Top-ups are $5 to $10,000 through Stripe, and automatic top-up is on by default after the first one. Managed model, search and integration calls bill at cost from the same balance (https://www.agent37.com/docs/agents-api/billing, checked 2026-10-08).",
    "priceSummary": "$0.0011 / vCPU-hr",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs (llms-full.txt), the pricing page or the terms (checked 2026-10-08). The wallet is topped up by card through Stripe in the dashboard.",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 74,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://www.agent37.com/docs",
    "llmsTxt": "https://www.agent37.com/docs/llms.txt",
    "capabilities": [
      "sandbox.persist",
      "sandbox.code",
      "sandbox.fs",
      "sandbox.browser"
    ],
    "tags": [
      "hosted",
      "usage",
      "llms-txt",
      "cli",
      "docker",
      "yc",
      "new"
    ],
    "lastRelease": "2026-10-05",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 46.1,
      "grade": "D",
      "agentReady": false,
      "rank": 564,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 10,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 60,
        "maintenance": 65,
        "payments": 20,
        "reliability": 27,
        "schema": 57,
        "security": 49,
        "transparency": 56
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 27,
          "points": 5.4,
          "reason": "Graded as a hosted service. No status page found, status.agent37.com returns 404 and neither the site nor the docs link one (0). No readable incident history (5). No request rate limits are published. The only numbers found are one on-demand backup per instance every 15 minutes and three concurrent template builds (0). Retry guidance is written per code, with backoff for `try_again`, `no_capacity` and 429, a Retry-After header on the backup limit, an idempotency key on budget top-ups and a warning that a timed-out exec keeps running, but instance create and exec take no idempotency key (12 of 15). The terms promise no uptime level unless agreed in writing (0). The Cloud API carries no beta label, though it launched on 29 September 2026 (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 57,
          "points": 9.26,
          "reason": "No OpenAPI or other machine-readable contract found. The paths we tried return 404 and the 637 KB llms-full.txt never mentions one (0). llms.txt with 49 pages, llms-full.txt and a Markdown copy of every page (10). Pages say what each call is for and when to choose another, such as stop against delete, resize against fork and exec for anything unwrapped (17). Parameters are documented with types, ranges, defaults and patterns in prose, with no schema to validate against (10). Curl, Python and JavaScript examples with responses on each page, and an error reference listing 18 Hosting API codes, 13 transport codes and 16 Agent API codes (15). The path is versioned at /v1, template images carry immutable dated tags and the gateway reports a semver, but no public changelog was found (5)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 60,
          "points": 9.75,
          "reason": "Exec output is capped at 512 KB a stream with a `truncated` flag, logs take a `tail` and chat can return one JSON body instead of a stream, but there is no field selection and `GET /v1/instances` returns every full object (12). No pagination or filters were found on the instance, session or file lists. Usage and metrics take date or hour windows (8). Errors carry stable codes, with `param`, `hint` and `response_id` on the Agent API and a remedy per code (20). An idempotency key on budget top-ups, `X-Expected-Mtime` and `overwrite=false` on file writes and documented safe retries, with none on create or exec (12). An empty create body works and every field is optional, but there is no SDK library, only a CLI and raw HTTP examples (8)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 49,
          "points": 8.57,
          "reason": "One workspace-wide `sk_live_` key, revocable, stored as a one-way hash per the privacy policy, with an optional IP allowlist of up to 20 addresses or ranges. No scopes were found (20). Signed URLs carry an expiring token in the query string for browser access. We don't deduct for that, as with presigned URLs elsewhere, but the token can't be revoked and can last seven days. No read-only keys and no confirmation on delete or restore. Exec runs as the image user unless root is requested, each instance has a managed-spend cap, and an agent has no route to open a public port (8). The agent returns untrusted content. The docs warn about serving agent-written files inline and about empty channel allowlists, and the vendor says sandboxes run under gVisor with egress limited to the public internet (10). A usage endpoint breaks spend down by instance and model, and container logs are readable, but no audit log of API calls was found (5). The vendor says a SOC 2 Type I report is available under NDA. The trust centre refused our reader, and no security.txt, disclosure policy or bug bounty was found (6)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 20,
          "points": 2.5,
          "reason": "No x402, MPP or L402 on the API (0). Per-unit prices for vCPU, memory and disk are published without login (20). The one-time $5 credit is granted only after a card is added, so there is no free tier without a card (0). A person signs up, adds the card and creates the key in the dashboard, and the docs say there are no balance or billing endpoints (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 65,
          "points": 5.69,
          "reason": "Scored on the closed-service scale. The newest template images are tagged 2026.10.05a, three days before the check (30). Hermes image tags on 27 September and 2, 3 and 5 October 2026, and CLI releases 0.3.0, 0.3.1 and 0.4.0 between 3 August and 11 September (20). No public changelog. Support is by email, a dashboard chat and a founder's booking link, and we couldn't read GitHub issues (5 of 15). No SDK library. The `agent37` CLI on npm is current at 0.4.0 (5 of 15). The templates repository has a test workflow, whose results we couldn't read (5 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 56,
          "points": 4.9,
          "note": "editorial 56, provenance 56",
          "reason": "Closed service with dated terms (4 August 2026). Template Dockerfiles and example apps are MIT and the CLI is Apache-2.0 (15). The privacy policy (1 September 2026) gives retention by category, seven days for a deleted instance's recovery copy, up to 30 days for request logs and about seven years for billing records, and the docs repeat the seven-day window. No DPA was found (22). One deprecation is documented, the Bearer header on instance URLs, with an email promised before removal and no date. No written policy (5). The policy names 12 kinds of third-party service and the docs say instances run on dedicated servers in the United States. The hosting providers aren't named (14)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Exec output is capped at 512 KB a stream with a `truncated` flag, logs take a `tail` and chat can return one JSON body instead of a stream, but there is no field selection and `GET /v1/instances` returns every full object (12). No pagination or filters were found on the instance, session or file lists. Usage and metrics take date or hour windows (8). Errors carry stable codes, with `param`, `hint` and `response_id` on the Agent API and a remedy per code (20). An idempotency key on budget top-ups, `X-Expected-Mtime` and `overwrite=false` on file writes and documented safe retries, with none on create or exec (12). An empty create body works and every field is optional, but there is no SDK library, only a CLI and raw HTTP examples (8).",
          "maintenance": "Scored on the closed-service scale. The newest template images are tagged 2026.10.05a, three days before the check (30). Hermes image tags on 27 September and 2, 3 and 5 October 2026, and CLI releases 0.3.0, 0.3.1 and 0.4.0 between 3 August and 11 September (20). No public changelog. Support is by email, a dashboard chat and a founder's booking link, and we couldn't read GitHub issues (5 of 15). No SDK library. The `agent37` CLI on npm is current at 0.4.0 (5 of 15). The templates repository has a test workflow, whose results we couldn't read (5 of 10).",
          "payments": "No x402, MPP or L402 on the API (0). Per-unit prices for vCPU, memory and disk are published without login (20). The one-time $5 credit is granted only after a card is added, so there is no free tier without a card (0). A person signs up, adds the card and creates the key in the dashboard, and the docs say there are no balance or billing endpoints (0).",
          "reliability": "Graded as a hosted service. No status page found, status.agent37.com returns 404 and neither the site nor the docs link one (0). No readable incident history (5). No request rate limits are published. The only numbers found are one on-demand backup per instance every 15 minutes and three concurrent template builds (0). Retry guidance is written per code, with backoff for `try_again`, `no_capacity` and 429, a Retry-After header on the backup limit, an idempotency key on budget top-ups and a warning that a timed-out exec keeps running, but instance create and exec take no idempotency key (12 of 15). The terms promise no uptime level unless agreed in writing (0). The Cloud API carries no beta label, though it launched on 29 September 2026 (10).",
          "schema": "No OpenAPI or other machine-readable contract found. The paths we tried return 404 and the 637 KB llms-full.txt never mentions one (0). llms.txt with 49 pages, llms-full.txt and a Markdown copy of every page (10). Pages say what each call is for and when to choose another, such as stop against delete, resize against fork and exec for anything unwrapped (17). Parameters are documented with types, ranges, defaults and patterns in prose, with no schema to validate against (10). Curl, Python and JavaScript examples with responses on each page, and an error reference listing 18 Hosting API codes, 13 transport codes and 16 Agent API codes (15). The path is versioned at /v1, template images carry immutable dated tags and the gateway reports a semver, but no public changelog was found (5).",
          "security": "One workspace-wide `sk_live_` key, revocable, stored as a one-way hash per the privacy policy, with an optional IP allowlist of up to 20 addresses or ranges. No scopes were found (20). Signed URLs carry an expiring token in the query string for browser access. We don't deduct for that, as with presigned URLs elsewhere, but the token can't be revoked and can last seven days. No read-only keys and no confirmation on delete or restore. Exec runs as the image user unless root is requested, each instance has a managed-spend cap, and an agent has no route to open a public port (8). The agent returns untrusted content. The docs warn about serving agent-written files inline and about empty channel allowlists, and the vendor says sandboxes run under gVisor with egress limited to the public internet (10). A usage endpoint breaks spend down by instance and model, and container logs are readable, but no audit log of API calls was found (5). The vendor says a SOC 2 Type I report is available under NDA. The trust centre refused our reader, and no security.txt, disclosure policy or bug bounty was found (6).",
          "transparency": "Closed service with dated terms (4 August 2026). Template Dockerfiles and example apps are MIT and the CLI is Apache-2.0 (15). The privacy policy (1 September 2026) gives retention by category, seven days for a deleted instance's recovery copy, up to 30 days for request logs and about seven years for billing records, and the docs repeat the seven-day window. No DPA was found (22). One deprecation is documented, the Bearer header on instance URLs, with an email promised before removal and no date. No written policy (5). The policy names 12 kinds of third-party service and the docs say instances run on dedicated servers in the United States. The hosting providers aren't named (14)."
        },
        "sources": [
          {
            "what": "docs index",
            "url": "https://www.agent37.com/docs/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "full docs in one file",
            "url": "https://www.agent37.com/docs/llms-full.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "core concepts, keys and IP allowlist",
            "url": "https://www.agent37.com/docs/agents-api/concepts.md",
            "seen": "2026-10-08"
          },
          {
            "what": "instances, auto-sleep, backups, fork",
            "url": "https://www.agent37.com/docs/agents-api/instances.md",
            "seen": "2026-10-08"
          },
          {
            "what": "billing and prices",
            "url": "https://www.agent37.com/docs/agents-api/billing.md",
            "seen": "2026-10-08"
          },
          {
            "what": "error reference",
            "url": "https://www.agent37.com/docs/agents-api/errors.md",
            "seen": "2026-10-08"
          },
          {
            "what": "exec",
            "url": "https://www.agent37.com/docs/agents-api/exec.md",
            "seen": "2026-10-08"
          },
          {
            "what": "instance URLs and signed URLs",
            "url": "https://www.agent37.com/docs/agents-api/urls.md",
            "seen": "2026-10-08"
          },
          {
            "what": "browser and desktop",
            "url": "https://www.agent37.com/docs/agents-api/desktop.md",
            "seen": "2026-10-08"
          },
          {
            "what": "templates",
            "url": "https://www.agent37.com/docs/agents-api/templates.md",
            "seen": "2026-10-08"
          },
          {
            "what": "product page, security claims",
            "url": "https://www.agent37.com/cloud",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing page",
            "url": "https://www.agent37.com/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of service",
            "url": "https://www.agent37.com/terms",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.agent37.com/privacy",
            "seen": "2026-10-08"
          },
          {
            "what": "unauthenticated API response (401 invalid_api_key)",
            "url": "https://api.agent37.com/v1/instances",
            "seen": "2026-10-08"
          },
          {
            "what": "status host, 404",
            "url": "https://status.agent37.com",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt, 404",
            "url": "https://www.agent37.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "npm registry, agent37 CLI",
            "url": "https://registry.npmjs.org/agent37",
            "seen": "2026-10-08"
          },
          {
            "what": "templates repository, tags and licence",
            "url": "https://github.com/agent37-platform/templates",
            "seen": "2026-10-08"
          },
          {
            "what": "examples repository",
            "url": "https://github.com/agent37-platform/examples",
            "seen": "2026-10-08"
          },
          {
            "what": "YC directory",
            "url": "https://www.ycombinator.com/companies/agent-37",
            "seen": "2026-10-08"
          },
          {
            "what": "YC launch post",
            "url": "https://www.ycombinator.com/launches/UTg-agent37-host-any-agent-harness",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for agent37.com",
            "url": "https://rdap.org/domain/agent37.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the trust centre at trust.agent37.com answered 403, so the SOC 2 Type I report, subprocessor list and any disclosure policy there are unread",
          "unchecked: GitHub star counts and open issues for agent37-platform/templates and examples. The GitHub API rate-limited our address, so `githubStars` is null",
          "unchecked: no account was opened and no instance created, so isolation, wake times, key revocation in the dashboard and whether keys can be limited beyond the IP allowlist are from the docs only",
          "Whether request rate limits exist. None are published",
          "Whether the first release date of the Cloud API is earlier than the npm CLI's first version of 16 July 2026. `firstReleased` is left null",
          "The legal entity is written Agent 37 Inc. in the terms and Agent37.com Inc in the privacy policy's representative section",
          "The scout's entry held up on every fact we rechecked. The launch post's $2,500 of credits is an offer to YC readers and isn't on the pricing page, where the public credit is $5"
        ]
      },
      "negative": 0,
      "verdict": "Instances keep their disk until deleted, sleep when idle and wake on the next request, with compute published at $0.80 a vCPU-month and stable error codes on both APIs. The product launched on 29 September 2026. No status page, OpenAPI file, SDK library or published rate limits were found, and the starter credit needs a card.",
      "bestFor": "A product that gives each end user a long-lived agent machine that is idle most of the day and needs a harness preinstalled.",
      "strengths": [
        "Disk persists until delete, and auto-sleep checkpoints an idle instance so that only disk bills ($0.09 a GB-month)",
        "Per-unit prices are public. A 2 vCPU, 4 GB instance running all month is $4.76, metered per minute",
        "Stable error codes on both APIs, with `param` and `hint` fields and written retry guidance for each transient code",
        "llms.txt, a 637 KB llms-full.txt and a Markdown copy of each of the 49 docs pages",
        "API keys take an IP allowlist of up to 20 addresses or ranges, and each instance has its own managed-spend cap"
      ],
      "weaknesses": [
        "No status page was found. status.agent37.com returns 404, and the terms promise no uptime level",
        "No OpenAPI file, SDK library or public changelog was found. The npm package `agent37` is a CLI",
        "No API rate limits are published beyond one on-demand backup per instance every 15 minutes",
        "One workspace-wide key controls every instance. No scopes or read-only keys were found",
        "The $5 starter credit needs a card on file, and keys and top-ups exist only in the dashboard",
        "The launch is dated 29 September 2026 and the public templates repository starts on 2 October 2026"
      ],
      "agentNotes": [
        "Send the key as `Authorization: Bearer` to api.agent37.com and as `X-Agent37-Key` to the instance URL. The Bearer form on instance URLs is deprecated",
        "Poll `GET /v1/health` on the instance URL for `\"healthy\": true` before the first message. `status: running` only means the machine is up",
        "Check whether `error` is a string before reading `error.code`. Transport errors are flat strings, and a failed turn returns 200 with `status: \"failed\"`",
        "Don't blindly retry an exec that timed out after 13 minutes. The command keeps running, so a retry starts a second copy",
        "Set `auto_sleep: true`, keep anything that must survive a sleep in a file, and allow a first-byte timeout of three minutes for wakes"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "D",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 46.1
        }
      ],
      "editorialScores": {
        "ergonomics": 60,
        "maintenance": 65,
        "payments": 20,
        "reliability": 27,
        "schema": 57,
        "security": 49,
        "transparency": 56
      },
      "provenanceScore": 56
    },
    "connect": {
      "http": "curl -X POST https://api.agent37.com/v1/instances \\\n  -H \"Authorization: Bearer sk_live_...\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{ \"budget\": { \"credit_micros\": 1000000 } }'"
    },
    "letme": {
      "capability": "https://letme.dev/sandbox.persist",
      "tool": "https://letme.dev/agent37"
    },
    "notable": [
      "Launched on Y Combinator on 29 September 2026 as part of the Fall 2026 batch, with one founder listed (https://www.ycombinator.com/companies/agent-37)",
      "Compute is $0.80 a vCPU-month, $0.70 a GB-month of memory and $0.09 a GB-month of disk, metered per minute, with disk alone billed while an instance sleeps or is stopped (https://www.agent37.com/docs/agents-api/billing)",
      "Auto-sleep checkpoints an idle instance and any request to its URLs wakes it. A wake that has to rebuild the instance takes about two minutes and loses processes and memory, per the docs (https://www.agent37.com/docs/agents-api/instances)",
      "Every system template is built from a public Dockerfile, MIT licensed, with a git tag per published image. The newest tags are dated 2026.10.05a (https://github.com/agent37-platform/templates)",
      "The vendor says sandboxes are isolated with gVisor, with egress limited to the public internet (https://www.agent37.com/cloud)",
      "The pricing page compares Agent37 with 30 other providers at rates the vendor compiled. We didn't check that comparison (https://www.agent37.com/pricing)",
      "status.agent37.com returns 404, and no status page, changelog or OpenAPI file is linked from the site or the 49-page docs index (https://www.agent37.com/docs/llms.txt)"
    ],
    "area": "agent-runtime",
    "details": [
      {
        "label": "APIs",
        "value": "Hosting API at https://api.agent37.com/v1 (instances, templates and cloud builds, exec, budgets, backups, fork, signed URLs, public ports, crons, SSH keys, logs, metrics, usage). Agent API on each instance at https://{instanceId}.agent37.app (`/v1/responses`, sessions, files, models, health, version)"
      },
      {
        "label": "Templates",
        "value": "Eight system templates (agent37-hermes, the default, agent37-openclaw, agent37-claude-code, agent37-codex, agent37-grok, agent37-opencode, agent37-pi, agent37-n8n), or a workspace template built from a Dockerfile or imported image of up to 8 GB"
      },
      {
        "label": "Shapes",
        "value": "2 vCPU and 4 GB, 4 and 8, 8 and 16, 16 and 32, with 2 to 80 GB of disk by shape. Default or Performance (dedicated cores). Burstable is experimental and by application"
      },
      {
        "label": "Persistence",
        "value": "Disk kept until delete. Auto-sleep after 300 to 86,400 idle seconds (default 900) checkpoints the instance, and any request wakes it in a few seconds, or about two minutes with a fresh boot when it has to be rebuilt. Memory usually survives a wake but isn't guaranteed"
      },
      {
        "label": "Backups",
        "value": "Nightly into seven rotating slots plus one on-demand slot, free, crash-consistent. Restore replaces data in place. Fork copies the disk into a new instance"
      },
      {
        "label": "Exec",
        "value": "`POST /v1/instances/{id}/exec` runs through `sh -c` as the image user or root, waits up to 780 seconds, and caps stdout and stderr at 512 KB each with a `truncated` flag"
      },
      {
        "label": "Browser",
        "value": "agent37-hermes and agent37-openclaw ship a headless Chromium the agent drives. A desktop template with noVNC on port 6901 is a separate cloud build from the examples repository"
      },
      {
        "label": "Isolation",
        "value": "The vendor says each sandbox runs under gVisor with its own filesystem and disk quota, that egress reaches only the public internet, and that hosts have no public hostname (https://www.agent37.com/cloud)"
      },
      {
        "label": "Limits",
        "value": "One instance before the first top-up, 10 after it, 50 at $100 of total top-ups and 200 at $250. Three concurrent template builds. One on-demand backup per instance every 15 minutes. No request rate limits published"
      },
      {
        "label": "Errors",
        "value": "`{error: {code, message}}` on the Hosting API, with `param`, `hint` and `response_id` added on the Agent API, and flat `{error: \"code\"}` strings for transport failures. 18 Hosting API codes, 13 transport codes and 16 Agent API codes are listed"
      },
      {
        "label": "Tooling",
        "value": "`agent37` CLI on npm, version 0.4.0 of 11 September 2026, Apache-2.0. Docs examples in curl, Python requests and JavaScript fetch. No SDK library or OpenAPI file found"
      },
      {
        "label": "Data",
        "value": "Instances run on dedicated servers in the United States. A deleted instance's data stays in backup storage for seven days. Request logs are kept up to 30 days. The privacy policy names 12 kinds of third-party service"
      },
      {
        "label": "Certifications",
        "value": "The vendor says a SOC 2 Type I report is available on request under NDA and that Type II is in progress. The trust centre refused our reader"
      }
    ],
    "unitPrices": [
      {
        "item": "vCPU",
        "unit": "vcpu-hour",
        "usd": 0.001096,
        "note": "$0.80 a vCPU-month over 730 hours. Memory extra at $0.70 a GB-month, and Performance instances cost four times the compute rate"
      },
      {
        "item": "Default instance (2 vCPU, 4 GB, 4 GB disk)",
        "unit": "session-hour",
        "usd": 0.00652,
        "note": "$4.76 a month running, metered per minute. $0.36 a month asleep or stopped"
      },
      {
        "item": "Disk",
        "unit": "gb-month",
        "usd": 0.09,
        "note": "Billed until the instance is deleted. $0.03 a GB-month on compressed bytes once parked in cold storage"
      }
    ],
    "provenance": {
      "legalEntity": "Agent 37 Inc.",
      "domain": "agent37.com",
      "domainRegistered": "2025-04-29",
      "endpointOnVendorDomain": true,
      "terms": "https://www.agent37.com/terms",
      "privacy": "https://www.agent37.com/privacy",
      "statusPage": "",
      "changelog": "",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The terms (last updated 4 August 2026) name Agent 37 Inc. under New York law. The privacy policy (last updated 1 September 2026) names Agent 37 Inc. and, in its representative section, Agent37.com Inc.",
        "The Hosting API answers at api.agent37.com and instances at {id}.agent37.app, a second domain the docs describe as the vendor's.",
        "www.agent37.com/.well-known/security.txt returns 404. The site footer has a Report abuse link and no disclosure policy was found.",
        "status.agent37.com returns 404 (deployment not found) and no status page is linked from the site or docs. No changelog page was found.",
        "RDAP for agent37.com gives a registration date of 2025-04-29 and NameCheap, Inc. as registrar.",
        "trust.agent37.com answered 403 to our reader, so the trust centre is unread."
      ],
      "score": 56,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Agent 37 Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "agent37.com, registered 2025-04-29 (1 year)",
          "points": 3,
          "max": 15,
          "state": "part"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.agent37.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects",
          "points": 9.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.agent37.com/terms",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-08-04",
          "words": 1484,
          "points": 9.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: August 4, 2026",
              "says": "Last updated 2026-08-04"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These Terms are governed by the laws of the State of New York, without regard to its conflict of law rules.",
              "says": "The law of the State of New York"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "Our total liability for all claims arising out of the Service is limited to the amounts you paid us in the twelve months before the event giving rise to the claim, or one hundred US dollars if you have paid us nothing.",
              "says": "Capped at the fees paid in the 12 months before the claim or one hundred US dollars"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "We may suspend or terminate your access if you materially violate these Terms, if your account is past due, if your workload puts the platform or others at risk, or if the law requires it."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "distribute malware, phish, spam, defraud, harass, or generate content designed to harm others;"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "We work hard to keep the Service up, but we do not promise a specific uptime level unless we have agreed to one with you in writing."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The customer is responsible for what its hosted agents do and produce, including on messaging platforms and third-party services.",
              "quote": "You are responsible for what your agents do and produce, including on messaging platforms and third-party services they touch."
            },
            {
              "date": "2026-10-08",
              "text": "Automatic top-up of the prepaid balance is switched on by default after the first top-up and charges the saved payment method.",
              "quote": "Auto top-up is on by default after your first top-up: when your balance falls below the configured threshold, we charge your saved payment method for the configured amount."
            },
            {
              "date": "2026-10-08",
              "text": "Agent 37 may use the customer name and logo to identify the customer on its website and in marketing materials.",
              "quote": "You grant us the right to use your name and logo to identify you as a customer on our website and in our marketing materials."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.agent37.com/privacy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-09-01",
          "words": 1809,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: September 1, 2026",
              "says": "Last updated 2026-09-01"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This Privacy Policy explains how we collect, use, store, and protect your data when you use our platform."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Kept while your account is active, then deleted within 30 days of an account deletion request.",
              "says": "Names a period of 30 days"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "We do not sell, rent, or share your personal data with third parties for marketing purposes."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We do not sell, rent, or share your personal data with third parties for marketing purposes.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Our service is not intended for children under 13."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have questions about this Privacy Policy or how we handle your data, contact us at info@agent37.com.",
              "says": "info@agent37.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": false
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Deleting a dashboard hosting instance keeps its data so support can restore it, unless the customer emails to have it removed sooner.",
              "quote": "Deleting a dashboard hosting instance keeps its data so support can restore it; email us to have it removed sooner."
            },
            {
              "date": "2026-10-08",
              "text": "Model requests made with starter credentials issued by Agent 37 pass through its managed proxy for metering.",
              "quote": "If you use starter credentials we issue instead of your own provider keys, model requests route through our managed proxy so we can meter them."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/agent37.json",
    "live": {
      "slug": "agent37",
      "probe": {
        "target": "https://api.agent37.com/v1",
        "method": "get",
        "lastAt": "2026-10-08T19:08:38.44558727Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 129,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 78,
        "p95ms24h": 215,
        "samples24h": 42,
        "samples30d": 42,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 42,
            "ok": 42
          }
        ]
      },
      "versions": [
        {
          "registry": "npm",
          "name": "agent37",
          "version": "0.4.0",
          "seenAt": "2026-10-08T15:56:42.792052264Z"
        }
      ],
      "githubStars": 0,
      "npmWeekly": 74,
      "securityTxt": {
        "url": "https://agent37.com/.well-known/security.txt",
        "state": "none",
        "checkedAt": "2026-10-08T15:38:33.079951688Z"
      },
      "pages": [
        {
          "url": "https://www.agent37.com/privacy",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-08T18:25:56.672603778Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "b53eb275b6a4"
        },
        {
          "url": "https://www.agent37.com/terms",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:25:58.868645647Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "7eac1e3b26de"
        }
      ],
      "updatedAt": "2026-10-08T19:08:38.44558727Z"
    }
  }
}
