Cloudflare open-sourced Cloudflare OS this week, an AI work platform whose pitch is that its sandboxes are safe enough to let non-developers build apps.
Kenton Varda, the lead architect, described the release as a chatbot with connectors wrapped in a vibe coding platform. His claim: security teams can grant non-technical employees permission to vibe code and still sleep at night.
The security model is capability-based. Every document runs as its own app instance inside a separate sandbox, or Gadget, and the platform controls who can reach it. A Gadget cannot leak itself to an attacker, even one holding access to other Gadgets from the same app, though Cloudflare concedes misconfigured capability grants remain a possible risk.
On top of that, teams get connectors to enterprise knowledge, workflow automation with optimized token cost, and the ability to prompt an agent to add features to the software they already use.