This discussion examines agentic runtime and secure agent infrastructure for enterprise. Ivan Burazin of Daytona, co-founder and chief executive officer, presents Daytona's agentic runtime and sandbox product designed to run autonomous agents securely. Burazin explains how sandboxed, composable computers provide agents with isolated accounts, graphical user interface access to legacy systems and post-training workflows that enable agents to act as productive digital knowledge workers across enterprises; they emphasize the role of these features in supporting safe deployment of artificial intelligence.
In conversation with John Furrier of theCUBE Research and Dave Vellante of theCUBE Research, Burazin emphasizes that agents should run in isolated sandboxes with dedicated accounts to ensure security, visibility and auditability. They caution against running non-isolated agents locally. The hosts and analysts note the rise of specialized agent infrastructure—an emerging agent cloud or CPU-focused runtime—and argue that simplified purpose-built platforms can accelerate enterprise adoption compared to general Kubernetes deployments.
Topics include agentic runtime, agent sandbox design, secure sandboxes, agent cloud architectures, composable computers, GUI integration with legacy systems, post-training workflows and enterprise deployment considerations for AI.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
theCUBE + NYSE Wired: Mixture of Experts Series. If you don’t think you received an email check your
spam folder.
Sign in to theCUBE + NYSE Wired: Mixture of Experts Series.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Register For theCUBE + NYSE Wired: Mixture of Experts Series
Please fill out the information below. You will recieve an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for theCUBE + NYSE Wired: Mixture of Experts Series.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
theCUBE + NYSE Wired: Mixture of Experts Series. If you don’t think you received an email check your
spam folder.
Sign in to theCUBE + NYSE Wired: Mixture of Experts Series.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Sign in to gain access to theCUBE + NYSE Wired: Mixture of Experts Series
Please sign in with LinkedIn to continue to theCUBE + NYSE Wired: Mixture of Experts Series. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Ivan Burazin, Daytona | Mixture of Experts
This discussion examines agentic runtime and secure agent infrastructure for enterprise. Ivan Burazin of Daytona, co-founder and chief executive officer, presents Daytona's agentic runtime and sandbox product designed to run autonomous agents securely. Burazin explains how sandboxed, composable computers provide agents with isolated accounts, graphical user interface access to legacy systems and post-training workflows that enable agents to act as productive digital knowledge workers across enterprises; they emphasize the role of these features in supporting safe deployment of artificial intelligence.
In conversation with John Furrier of theCUBE Research and Dave Vellante of theCUBE Research, Burazin emphasizes that agents should run in isolated sandboxes with dedicated accounts to ensure security, visibility and auditability. They caution against running non-isolated agents locally. The hosts and analysts note the rise of specialized agent infrastructure—an emerging agent cloud or CPU-focused runtime—and argue that simplified purpose-built platforms can accelerate enterprise adoption compared to general Kubernetes deployments.
Topics include agentic runtime, agent sandbox design, secure sandboxes, agent cloud architectures, composable computers, GUI integration with legacy systems, post-training workflows and enterprise deployment considerations for AI.
This discussion examines agentic runtime and secure agent infrastructure for enterprise. Ivan Burazin of Daytona, co-founder and chief executive officer, presents Daytona's agentic runtime and sandbox product designed to run autonomous agents securely. Burazin explains how sandboxed, composable computers provide agents with isolated accounts, graphical user interface access to legacy systems and post-training workflows that enable agents to act as productive digital knowledge workers across enterprises; they emphasize the role of these features in supporting ...Read more
exploreKeep Exploring
What is Daytona's Sandbox for Agentic Runtime, and what are the main deployment, security, and operational challenges enterprises face when running autonomous agents?add
What does the recent incident in which an autonomous agent escaped containment (e.g., the Hugging Face/OpenAI case) reveal about the nature and risks of such agents, and what are the implications for how we should understand, secure, and deploy them going forward?add
Do you expect everything will converge to being "headless" (accessed only via APIs by agents), or will agents still need to interact with graphical user interfaces and legacy systems?add
How can a newcomer compete with AWS, GCP, and Azure, and what market opportunity are you targeting by building a CPU-focused "Agent Cloud"?add
>> John Furrier with theCUBE. We are here at the New York Stock Exchange theCUBE studios. Of course, we have our Palo Alto studio connecting Silicon Valley to Wall Street. This is part of our NYSE Wired Mixture of Experts series. We talk to leaders who are building, operating, and investing in the future. that's pretty much everyone who's working with AI whether they're a pure investor, pure operator pure builder, everyone's kind of doing the same thing we've got Ivan Burazin here, co-founder and CEO of Daytona, Ivan great to see you, thanks for coming in remotely into the studio you guys are in the middle of it coding assistants turned into autonomous coders, crossing boundaries, automating tasks on our behalf, cloud native set the table for AI native, that's what you're in the middle of, welcome to the program
Ivan Burazin
>> Thanks so much for having me.
John Furrier
>> So set the table. You guys are in the middle of it, as I said, explain what you guys do, why you exist, your mission, and your value proposition.
Ivan Burazin
>> Sure. Daytona is an infrastructure provider that is created specifically for agentic runtime. So enabling agents to be able to run, and we started with it by enabling agents to run code securely. Hence, the product that we offer is actually called the Sandbox, which is a word used quite a bit over the last two weeks. But it's actually become more than that. We think of it as composable computers created for agents so that agents can have access to the same tools and interfaces that humans do to actually be able to get productive work done end to end.
John Furrier
>> The coding piece of it has become a big deal. It's opened up the enterprise. Last year, we saw a lot of pilots kind of get stuck. Some went into production, but they were really deterministic workloads, well-scoped, good governance. but not a tsunami of agents. Then we saw it happen this year. A lot of people were experimenting with stuff on their desktop, running in the enterprise. Now a lot more agents are coming in. This is going to be the real next value proposition tier that's going to happen. What is the blocker? What's the current issues that people are working on? Because it's the most important conversation we're hearing. How fast can I get agents up and running? And then the question is, what are they doing and why? Why and for who?
Ivan Burazin
>> Yeah, actually, agents, there's so many things that I think are not aligned and why we're not all extracting the absolute most we can out of these agents. First of all, agents, ideally, in my opinion, should not be run locally on your machine or non-isolated, at least. So the problem is, and I'll give you an example, if you run an agent on your machine and say, hey, create this report and it needs financial data or data from your bank account, I'm talking about your corporate bank account or whatever, because it's on your machine, it has access to log into your bank account and have your credentials and do what you can do, i .e. it can spend your money, worst case scenario, right? We don't want that. And also, you have no visibility into what it can do and things like that. So first and foremost, agents should be run mostly inside a sandbox, even if it's on a local machine or remotely, it should be in its own sandbox, aka computer. Like a human, it should have its own computer to do its work. But moreover, it should actually have its own accounts, because how can we actually know and give it access and privileges to do things? And if things go wrong, to know who did it and what it did, if we do not do that. So I think just from setting up and kicking off these agents as companies start seeing this more and more, they should be very adamant of saying, hey, you can run as many agents as you want, but here's your account, here's your credentials, and here's where it can run so that we as an organization can actually see what they are doing.
John Furrier
>> We're hearing stories of agents going out there. They can write code on the fly as they reason, solve their own problems. Multi -step reasoning, very great use case for agents. But there's been a lot of things in the news. We saw the Hugging Face containment issue with OpenAI where they go rogue off from the test environments. They actually just took matters into their own hands. What does this mean for agents? obviously, that's a technical thing that happened. but are people thinking about agents in the right way what does that tell us one and two what does it mean going forward
Ivan Burazin
>> i think that people
John Furrier
>> it's anyone that has been following this is it's
Ivan Burazin
>> not a surprise at all first the agent was not malicious that the agent did not have malicious intent right the agent just had the intent to solve the problem what was the easiest way to solve a problem find the solution to the problem instead of thinking about the problem right You have kids in school who've done that. People are like, oh, I can study for the test or I can just cheat on the test. And so the outcome is pass the test. So it is logical that these things would happen. And when I personally think of agents, I think of agents as digital knowledge workers or Elon calls them the human emulator or there's other terms of that. It is much more than we had thought previously. And if you think of it in that example, let's take an example of a bank, any bank in the world, right? you have to protect yourself as a bank from internal threats and external threats. Internal threats are your employees, malicious or non -malicious. Every employee that comes into a bank has a computer, a computer has credentials, they have a key card, they have access cards, they have all these things that allow them to do some things, limit them from doing things that they're not supposed to do. In that same way, you should treat agents as internal actors, but also from external actors. You don't want people to have a cyber attack on your bank account. Do you want them to come in and steal from the bank? So in that same way, the Hugging Face thing was from the internal. OpenAI had something internal that went outwards. And from the Hugging Face perspective, you have an external actor trying to be malicious on you. And so I think we all as a society have to think of them just as another variation of an entity. I can't call it a human in this new paradigm.
John Furrier
>> Ivan, I love that analogy. In fact, we were talking before we came on camera about the world we're moving to should be more aligned with the way we think and work. Agents are working on our behalf. They're knowledge workers. And so it seems like there's two things going on here. I'd love to get your thoughts on this because go back five to eight years ago, the future of work, cloud, mostly a cloud story, self -service, more APIs. APIs. Now you think about it, the graphical user interface era has almost come to an end as the way to do things or the way to evolve your work before it was constrained to the app. Yeah, they do a new design every once in a while, but now the designs are voice activated, natural language. It's evolving too. So now you have a completely different experience and you have a technology underpinning tsunami of change. So you got two things going on. How do you react to that? How do you talk about that when you talk to your friends and customers?
Ivan Burazin
>> Yeah, so we think about that. There's a lot of things that we've thought about and have changed and formed our opinions. And so what I think about, if agents are the number one consumers of these products, information, databases, whatever, it makes sense that they're all headless, aka via an API or MCP or whatnot, right? And so you would think, as did we, that everything will converge to be headless, right? You don't need a graphical user interface outside of an interaction with your agent. The agent goes off and does all these things. I do believe that that's an end state, but there's one big messy state between now and then. And that is that if you give an agent a task and expect it to do end-to-end the entire task, if we can conceive that task can be done digitally, it doesn't have to be physically, it still does need access to a graphical user interface. The agent, not the human. And the reason it needs that is that there's so much data and knowledge and software locked in desktop applications that have no headless access. And so we can either as a society wait for all these systems to be rewritten for agents, or we can give them access to that legacy GUI to get it done. And then if you think for our viewers that know what an AS/400 is, these things still exist. These things still exist today.
John Furrier
>> It's an old mini computer for anyone who doesn't know the history. That was a proprietary mini computer that runs systems, system of records, data.
Ivan Burazin
>> Yep. And so you still have data in those today. And so I don't expect, if that's still alive today, we have to enable agents to access that data today to get their job done. Now that's an extreme example. But just saying that the speed of change of these systems is not in line with the speed of change or evolution of agents. So I think for the mid -term, we will still have to enable agents to have access to graphical interfaces, not necessarily that we humans have to, to be able to get a job done. And I just think that's an interesting thing to think about.
John Furrier
>> one of the things I know you guys talk about and we have on theCUBE a little bit is models versus the underlying technology. It's interesting. NVIDIA doesn't view themselves as a GPU company, although they're really a GPU company. They're an AI infrastructure company. They've got GPUs, CPUs, inference, Omniverse, slew of things, NeMo, you name it, they've got everything. But they're an infrastructure company. We're kind of seeing the agentic become an infrastructure. Explain your thoughts on this and your vision because in the enterprise, you're going to have domain -specific things. You're going to have AS/400s and mainframes and other systems like Workday or Oracle. They're going to be good systems of record but might not be the best systems of intelligence. Kind of a perfect use case for agents to get in there and grind away and do the work, kind of figure it out. Talk about your reaction to that, because now you have this infrastructure position. It's not just, hey, here, buy some agents and let them fly around. You've got to really intentionally think about it. Share your vision on this.
Ivan Burazin
>> Sure, absolutely. I think that if we look at just infrastructure in general, so for the most part, like hyperscalers and clouds, I think that market has been growing at an insane clip year over year, even at the scale that they are. And I think that still does continue to grow. Those infrastructure providers were made without something like agents in mind, and they're amazing at what they do. But what we're actually seeing is that infrastructure in general is becoming much larger and much more specialized. There's different types of infrastructure providers offering different things for agents. And so you have the inference providers, Baseten and Fireworks, they're doing their job. You have net new database providers. You have web search providers. These are all infrastructure primitives that are out there. And us specifically, what we think of ourselves as the agent runtime, or think of it literally as millions and trillions of computers in the cloud for agents to do their work. And so I believe that all these new infrastructure parameters will actually grow faster, which seems shocking, than the growth of the cloud market or the infrastructure market has up until now, which has probably been one of the best markets in the world.
John Furrier
>> Well, I want to use the remaining eight minutes we have left to dig into that, because I think your value proposition speaks to this new cloud wave, because you think about the Amazon Web Services, there was no competition. It was hard to build a cloud. Every company tried one, IBM, HP, OpenStack, they all tried to build clouds, they couldn't do it. Now you see the rise of the Neo clouds, because the enterprise could have full multi -tenancy, okay? You can have multi -tenancy and then provide enterprise -level infrastructure support. So the question for you is, as you look at that opportunity to provide an agentic infrastructure, it feels a lot like the NeoClouds to me where it's like, hey, I got a specialty infrastructure, call it an agentic runtime cloud. I don't know what you call it, but that seems like what's happening. Did I get that right?
Ivan Burazin
>> That is absolutely, absolutely on the nose. Well, first to be clear, it's very hard to compete. So we basically have three hyperscalers, right? You have AWS, GCP, and Microsoft with Azure. And it is very hard for someone else to get in the game when the features are essentially equivalent. And so the only time you have a chance to do that is when there's a seismic shift in the market and there's a net new need, right? And so the NeoClouds were the first, which were like, oh, we need these specialized clouds that run GPU inference and whatnot. And so we actually don't have a name for what we are yet. So we'll just call it Agent Cloud for now. It's not a Neo Cloud as Neo Clouds are mostly geared toward GPU-focused clouds. We are a CPU-focused cloud for the most part. So it's vast, we have all sorts of CPUs, AMD, Intel, NVIDIA soon enough as well with their new CPU product. Basically what we've seen and NVIDIA, Jensen has also mentioned it, is that the number of CPUs that will be needed in the world coming forward will actually high probability the spend of that will be higher than GPUs which sounds insane if you look at just the growth trajectory of these providers because if you think about it the amount of inference just like agents thinking versus how much tool use and compute they will need will be much much higher even we as humans, we have an iPad and a laptop and a cell phone and that's all CPU for the most part. Workloads against the inference in our brains. And so the thing that we are now building is that there was a net new need for this agent runtime cloud. And so we grabbed the opportunity.
John Furrier
>> AWS was one of the best value propositions at that time, go back 15, actually 20 years ago now. You put your credit card down, you're a startup, like Airbnb, no one's ever heard of you. You get three guys in a room, they're coding, they go to the cloud. Easy decision. You're seeing similar simplicity and ease of use now with these new cloud models. Because as you pointed out, I just want to run some agent workloads. It's very bursty. It's got unique requirements. I don't want to go do all the legwork and stand up some EC2. Yeah, they say it's easy, but I just want to get things going. So there's really kind of an appetite. People get addicted to that. Talk about that. Is that factoring into some of your momentum?
Ivan Burazin
>> Absolutely.So I'd say our number one competitor is Kubernetes as a technology. So like an EKS that you can get on AWS or whatnot. And basically, it's great. For those that don't know, it is an amazing technology for what it's built for. And it's an easy way to spin up multiple, let's call it compute instances, but they're not optimized for agents. And it actually is a headache. It takes 30 to 60 minutes to get up and running. There's 12 steps to get a Kubernetes cluster running. It takes you longer to read the steps of how to set up a Kubernetes cluster than spin up a thousand sandboxes on our infrastructure, right? To your point of ease of use. Literally it's faster to get up and running than the steps. And so when people see this, they're like, oh, yes, this makes my life easier. I get it up and running and I just roll with it.
John Furrier
>> Yeah, when you have these phase shifts, that's the opportunity. Transition markets, like I said before, no one could build it, but now they can. And I think this is where the stack and this new era has changed. What was once great middleware just five years ago, call it middleware or higher level services, now is rethought because of the role of compute, storage, and even CPU for inference. And the open weight models, you can mix and match small specialty intelligence with general intelligence and then use those resources kind of like an operating system
Ivan Burazin
>> absolutely
Ivan Burazin
>> and the open weight models have been probably one of the biggest drivers for us and generally the market um
Ivan Burazin
>> whereas you have people not only using them but they would do post-training which we come into play in there they do a bunch of that they do that on a daily basis on a weekly basis then they load up and then they run it on these infrastructure inference providers, sorry. And then they have the usage from that. And so that has all been very, very great in the sense of pushing these new infrastructure players forward as well.
John Furrier
>> Well, Ivan, great to get you on. We'll certainly do more conversations and see each other again. But in the last minute we have left, put a plug in. Who are you targeting? Obviously, devs, enterprise. Give a quick spiel, plug for what you're looking for. You got some growth. You guys had a hard pivot over a year and a half ago. Got some good momentum. Got revenue up and to the right. What are you looking for? You're hiring. What's your target?
Ivan Burazin
>> Yeah, absolutely.Revenue's been great. Average since we've done it has been 50 % month over month, growing over 100 % month over month now. So that part is insane. So hiring across the board here in San Francisco. And we serve customers, everything from startups to literally the five largest companies in the world. And so helping them out with post -training and running their background agents. So, yeah.
John Furrier
>> All right. Well, thanks for coming on. I really appreciate it. Have a good one. Thanks for coming in from SF. All right, I'm John Furrier, this is our Mixture of Experts series where experts share their expertise but also what they're working on, some of the hardest problems the AI generation is upon us. I'm John Furrier, your host of theCUBE, thanks for watching.