Isolated environments for coding agents
Govern agents and Claws across every team
Your AI Agent across Docker
Local-first LLM inference made easy
Connect and manage MCP tools
Ship with secure, enterprise-ready images
Simplify the software supply chain
Containerize your applications
Discover and share container images
Break free of local constraints
Find guides for Docker products
Learn the Docker basics
Search a library of helpful materials
Skill up your Docker knowledge
Create and share your own extensions
Connect with other Docker developers
Explore open source projects
Help shape the future of Docker
Get inspired with customer stories
Docker AI Governance
AI governance for every agent
Centralized sandbox, network, and MCP controls for agents and Claws across every team, every tool, every machine. Defined once. Enforced everywhere.
-
-
-
-
-
-
-
- -
Works with every AI tool your team uses
Capabilities
One engine. Three layers of control.
Sandbox, MCP, and network controls: defined once in the admin console, propagated through the auth flow developers already use.
Sandbox Policies
Network and filesystem control. Enforced, not advised.
Define allow and deny rules for domains, IPs, and CIDRs. Set filesystem mount rules with read-only or read-write scope. Enforcement happens at the proxy and mount level.
MCP Tool Governance
Control which tools agents can use. Org-wide, by default.
Admins control which MCP servers and tools are available organization-wide. Unapproved servers are blocked by default and every MCP call flows through the same policy engine.
Audit + Visibility
The proof CISOs need to confidently approve AI.
Every policy evaluation generates a structured event with user identity, timestamp, session context, and triggering rule. Export to your existing SIEM and compliance systems. Get full traceability, zero blind spots.
See it in action
Define once. Propagate everywhere.
A security admin approves an MCP server in the org catalog. Policy pushes through your IdP. Every developer’s next session picks it up, automatically, with zero per-machine setup.
Scope:EngineeringData Science
0/ 2,847
Machines updated
Who it’s built for
AI governance for every stakeholder.
CISO
Approve AI. Not just permit it.
Full auditability and centralized policy gives you the evidence to confidently sign off on agent adoption across the organization.
Platform Teams
Define once. Enforce everywhere.
Policy is set centrally and propagates on developer authentication. No per-machine config. Scales through your existing SAML and SCIM IdP.
Developers
Full speed. Zero friction.
Governance runs in the background. Agents work the way they’re supposed to, autonomously, on the tools you already use.
Why Docker
Most tools cover one slice. Docker covers the whole agent.
| Network | Filesystem | MCP | On the laptop | Vendor neutral | |
|---|---|---|---|---|---|
| ### Docker AI Governance Sandbox + MCP, one console, on the laptop your employees already use. |
Network | Filesystem | MCP | On the laptop | Vendor neutral |
| ### MCP-only gateways Network and filesystem out of scope by design. |
Network – |
Filesystem – |
MCP | On the laptop | Vendor neutral |
| ### Agent mesh Runs in the data plane. Doesn’t reach the laptop. |
Network | Filesystem – |
MCP | On the laptop – |
Vendor neutral – |
| ### Remote dev environments Covers everything — after migrating every dev off their laptop. |
Network | Filesystem | MCP | On the laptop – |
Vendor neutral |
| ### Built-In Guardrails from Frontier Models Basic, vendor-locked controls. |
Network | Filesystem | MCP – |
On the laptop | Vendor neutral – |
One console. Every agent. Every Claw.
Policy propagates automatically from security leaders to every developer. No tickets. No surprises.
See it in action
Get started with Docker AI Governance.
One console to govern AI agents and Claws across your entire organization. Policy propagates automatically from security leaders to every developer.
Sandbox, network, and filesystem controls
Org-wide MCP server and tool governance
Structured audit events to any SIEM
SAML / SCIM via your existing IdP
* First Name:
* Last Name:
* Company:
* Business Email:
* Country:
Select Country...United StatesAfghanistanAland IslandsAlbaniaAlgeriaAndorraAngolaAnguillaAntarcticaAntigua and BarbudaArgentinaArmeniaArubaAustraliaAustriaAzerbaijanBahamasBahrainBangladeshBarbadosBelgiumBelizeBeninBermudaBhutanBoliviaBosnia and HerzegovinaBotswanaBrazilBruneiBulgariaBurkina FasoBurundiCambodiaCameroonCanadaCape VerdeCayman IslandsCentral African RepublicChadChileChinaColombiaComorosCongoCosta RicaCote d'IvoireCroatiaCuraçaoCyprusCzech RepublicDenmarkDjiboutiDominicaDominican RepublicEcuadorEgyptEl SalvadorEquatorial GuineaEritreaEstoniaEthiopiaFaroe IslandsFijiFinlandFranceFrench GuianaGabonGambiaGeorgiaGermanyGhanaGibraltarGreeceGreenlandGrenadaGuatemalaGuineaGuinea-BissauGuyanaHaitiHondurasHungaryIcelandIndiaIndonesiaIraqIrelandIsle of ManIsraelItalyJamaicaJapanJerseyJordanKazakhstanKenyaKiribatiKorea SouthKuwaitKyrgyzstanLaosLatviaLebanonLesothoLiberiaLibyaLiechtensteinLithuaniaLuxembourgMadagascarMalawiMalaysiaMaldivesMaliMaltaMartiniqueMauritaniaMauritiusMexicoMoldovaMonacoMongoliaMontenegroMoroccoMozambiqueMyanmarNamibiaNauruNepalNetherlandsNew ZealandNicaraguaNigerNigeriaNorfolk IslandMacedoniaNorwayOmanPakistanPalestinePanamaPapua New GuineaParaguayPeruPhilippinesPolandPortugalQatarReunionRomaniaRwandaSaint Kitts and NevisSaint LuciaSaint Pierre and MiquelonSaint Vincent and the GrenadinesSamoaSan MarinoSao Tome and PrincipeSaudi ArabiaSenegalSerbiaSeychellesSierra LeoneSingaporeSlovakiaSloveniaSolomon IslandsSomaliaSouth AfricaSouth SudanSpainSri LankaSurinameSwedenSwitzerlandTaiwanTajikistanTanzaniaThailandEast TimorTogoTongaTrinidad and TobagoTunisiaTurkeyTurkmenistanTuvaluUgandaUkraineUnited Arab EmiratesUnited KingdomUnited StatesUruguayUzbekistanVanuatuVenezuelaVietnamVirgin IslandsYemenZambiaZimbabwe
By providing my contact information, I authorize Docker to contact me with communications about Docker's products and services. See our Privacy Policyfor more details or toopt-out.
Contact us
Thank you for your interest. The Docker Team will be in touch.