← Back to Blog
Header image for blog post: Northflank vs Modal Sandboxes: which platform fits your requirements?
Deborah Emeni
Published 31st August 2026

Northflank vs Modal Sandboxes: which platform fits your requirements?

Northflank and Modal Sandboxes both provide isolated CPU and GPU environments for running code and AI workloads, but they use different application and infrastructure models.

Modal offers code-first sandbox execution within its managed serverless AI platform, while Northflank provides production-grade secure sandboxes using Kata Containers with Cloud Hypervisor as its primary microVM approach, with Firecracker and gVisor where supported and appropriate. Northflank also runs the surrounding application stack, including APIs, workers, jobs, managed data, preview environments, and workflows.

The decision is whether to define sandbox execution through application code on managed infrastructure or operate it with the production architecture through one control plane.

This comparison covers lifecycle, isolation, persistence, startup and scaling, GPUs, networking, developer experience, infrastructure control, data residency, pricing, and operations.

TL;DR: Northflank vs Modal Sandboxes

Modal Sandboxes fit code-first serverless execution within Modal's managed AI platform, while Northflank fits teams that need secure sandboxes alongside production applications and customer-controlled infrastructure in one control plane.

  • Modal Sandboxes fit teams that need code-first serverless execution. Python and Beta JavaScript/TypeScript and Go SDKs create gVisor-isolated CPU or GPU environments from Modal Images.
  • Northflank fits teams that need production-grade isolated CPU or GPU execution and the complete architecture supporting it. It combines Kata Containers with Cloud Hypervisor, plus Firecracker and gVisor where supported and appropriate, with services, workers, jobs, managed data, persistent volumes, automatic full-stack previews, workflows, and no fixed sandbox-session duration.
  • Their infrastructure boundaries differ. Modal uses managed multi-cloud capacity with region pinning. Northflank supports Northflank Cloud, self-service BYOC, and eligible BYOK, including on-premises and bare metal.
  • Their pricing models reflect different product boundaries. Modal offers Starter with included compute, Team at $250 per month plus usage, and custom Enterprise pricing. Northflank offers an always-on free Sandbox tier, self-service Pay-as-you-go without seat fees, and custom Enterprise plans. Northflank BYOC combines platform fees with direct cloud-provider billing.

If your team or organisation needs isolated CPU or GPU execution alongside its production services, Northflank provides one control plane for the architecture. Developers get governed self-service while platform teams control networking, security, observability, clusters, and deployment targets across Northflank Cloud, production BYOC, or eligible BYOK.

Northflank has supported self-service production BYOC since 2019. Northflank Skills help Codex, Claude Code, Cursor, and compatible agents deploy and troubleshoot through the API and CLI. Agents authenticate with API tokens, inherit the token's RBAC permissions, and have their API or CLI actions recorded in audit logs.

Get started with Northflank self-serve, or book a demo to discuss architecture, security, compliance, data residency, or migration requirements.

Northflank vs Modal Sandboxes comparison table

The key differences are platform scope, lifecycle, interfaces, and infrastructure ownership.

RequirementNorthflankModal Sandboxes
Best forEnterprises, platform teams, AI engineering teams, and startups that need production-grade CPU or GPU sandboxes, complete application stacks, governed developer self-service, and control over cloud or Kubernetes infrastructureAI engineering, machine learning, and application development teams that need code-first CPU or GPU sandboxes alongside serverless Functions, batch jobs, inference, and training on Modal-managed multi-cloud infrastructure
Product scopeProduction-grade isolated CPU and GPU sandboxes plus services, workers, jobs, managed databases and queues, volumes, workflows, automatic full-stack previews, and supporting infrastructureCode-first sandboxes within managed serverless AI compute for Functions, jobs, inference, and training
IsolationKata Containers with Cloud Hypervisor, plus Firecracker and gVisor where supported; BYOC availability depends on its configuration; Cloud GPUs use gVisor by defaultgVisor for standard Sandboxes; Beta full-VM runtime with a conventional Linux kernel
LifecycleScale to zero, scale back up, restart, or delete; attached volumes and service configuration persist; no fixed sandbox-session durationFive-minute default timeout and 24-hour maximum per Sandbox; idle timeout and explicit termination are also supported
Environment creationGit, Dockerfiles, Buildpacks, images, Templates, API, CLI, volumes, backups, and clonesModal Images defined in code, from Dockerfiles, or from registries
Compute and GPUs0.1–32 vCPU, 256 MB–256 GB memory, GPU plans, scaling, and custom BYOC node poolsBurstable CPU and memory plus GPU Sandboxes on the standard runtime; Beta V2 and VM Sandboxes do not currently support GPUs
PersistenceEphemeral root with persistent volumes across restarts and scale-to-zero; volume backups and clones support reuseFilesystem and directory snapshots, Alpha memory snapshots, Modal Volumes, and cloud bucket mounts
NetworkingPrivate discovery, public and private ports, network policies, multi-project access, static egress, and BYOC VPC routingOutbound blocking, CIDR allowlists, Beta domain allowlists, tunnels, connect tokens, and same-region private networking on V2
InterfacesUI, API, CLI, JavaScript client, Git, images, Templates, GitOps, Workflows, and Skills for coding agentsPython-first SDK plus Beta JavaScript/TypeScript and Go SDKs and CLI tooling
Supporting workloadsServices, workers, jobs, managed data, previews, workflows, and GPUsFunctions, batch jobs, inference, training, Notebooks, storage, and GPUs
Preview environmentsPreview Blueprints automate full-stack applications, data, jobs, volumes, networking, seed workflows, and URLsNo native support for automatic full-stack preview environments
InfrastructureNorthflank Cloud, self-service BYOC since 2019, and eligible cloud, on-premises, or bare-metal BYOKModal-managed AWS, GCP, and OCI capacity with region selection
Observability and governanceLogs, metrics, health checks, alerts, audit logs, log sinks, RBAC, scoped access, directory integrations, policies, and cluster contextSandbox logs and metrics, paid-plan RBAC, and Enterprise workspace audit logs
PricingAlways-on free Sandbox tier; self-service Pay-as-you-go with per-second compute and no seat fees; custom Enterprise; BYOC platform fees with direct cloud-provider billingStarter with included compute; Team at $250 per month plus usage with included compute; custom Enterprise; per-second CPU, memory, and GPU charges
OperationsNorthflank operates its managed cloud, provisions and manages BYOC clusters, and manages the Northflank platform on BYOK clustersModal operates its managed platform and underlying multi-cloud infrastructure

Who are Northflank and Modal Sandboxes designed for?

Modal serves AI engineering, machine learning, and application development teams that prefer code-first isolated CPU or GPU execution on managed serverless infrastructure. Developers configure Modal Sandboxes through Python or the Beta JavaScript/TypeScript and Go SDKs, including images, compute resources, networking, timeouts, and persistence.

Modal Sandboxes operate alongside Modal Functions, endpoints, batch jobs, inference, training, Notebooks, Queues, Volumes, and cloud bucket mounts. Standard Modal Sandboxes use gVisor and run on Modal-managed multi-cloud infrastructure with optional region selection.

Northflank serves enterprises, platform organisations, AI teams, and startups that need secure sandboxes and supporting production workloads under one deployment, networking, governance, and observability model. Compatible images can run as sandboxes, APIs, persistent workers, or jobs with persistent volumes and CPU or GPU resources. Managed databases, queues, and object storage share the same control plane.

For isolation, Northflank uses Kata Containers with Cloud Hypervisor as its primary microVM approach, with Firecracker and gVisor where supported and appropriate. In BYOC, runtime availability depends on the provider, region, and node-pool configuration, while Northflank Cloud GPU workloads use gVisor by default.

How do Northflank and Modal Sandboxes compare on lifecycle and persistence?

Each Modal Sandbox runs for five minutes by default and can be configured for a maximum lifetime of 24 hours. An idle timeout can end inactive sessions earlier. Applications can continue by creating replacement Sandboxes and restoring persisted state, but commands cannot run inside a Sandbox after it finishes.

Modal filesystem and directory snapshots default to 30-day retention but can use another retention period or no expiry. Alpha memory snapshots expire after seven days and terminate the source Sandbox. Volumes provide shared storage, while cloud bucket mounts connect to S3, Cloudflare R2, or Google Cloud Storage.

Northflank sandboxes use a service lifecycle rather than a time-boxed session. Teams can execute commands, expose ports, restart, scale to zero, scale back up, or delete them through several interfaces. Northflank does not impose a fixed sandbox-session duration.

Northflank's root filesystem is ephemeral, while persistent volumes preserve repositories, datasets, models, notebooks, and agent state across restarts and scale-to-zero. Scaling back up starts new compute and reattaches the volume; it does not preserve RAM or running processes. Templates and Workflows can reproduce the surrounding application topology.

How do Northflank and Modal Sandboxes compare on environments, startup, and scale?

Modal Images use Python definitions, Dockerfile commands, or registry images. Modal containers boot in about one second, although initialization can extend the time until a container is ready; teams can keep initialized Sandboxes warm when latency is critical.

Modal's V2 Sandbox backend is in Beta and recommended above 20 creates per second or 10,000 concurrent Sandboxes. It currently has a separate feature matrix and does not yet support GPUs.

Northflank accepts images or Git builds using Dockerfiles and Buildpacks. Northflank's microVM-backed sandboxes boot in under one second. Templates, horizontal autoscaling, scale-to-zero, and BYOC node-pool controls manage topology and capacity.

In the ComputeSDK 2026 Scale Invitational, Northflank reached 100,000 concurrent sandboxes in 24 seconds, compared with 32 seconds for Modal. Northflank used 0.5-CPU sandboxes, while Modal used 0.125-CPU burst sandboxes, so the result demonstrates fleet-scaling performance under the tested configurations rather than a controlled per-sandbox comparison.

Which compute and GPU workloads do Northflank and Modal Sandboxes support?

Modal Sandboxes request physical CPU cores and memory, can burst when capacity exists, and support upper limits. Standard Sandboxes can request NVIDIA GPUs but are subject to preemption. Modal's Beta VM Sandboxes currently support CPU workloads only, and the V2 Beta backend does not yet support GPUs.

Northflank runs compatible images as isolated sandboxes, persistent services and workers, or one-off, scheduled, and API-triggered jobs. GPU-backed sandboxes, model-serving services, and jobs can run in GPU-enabled Northflank Cloud regions or on compatible BYOC node pools.

If an agent needs isolated execution and persistent GPU inference, Northflank can place the sandbox, model endpoint, API, queue, database, and workers in one control plane. Teams can separate CPU and GPU pools and apply placement rules.

How do Northflank and Modal Sandboxes compare on networking, security, and observability?

Standard Modal Sandboxes run on gVisor. By default, they cannot accept inbound traffic or access other workspace resources. Outbound access can be blocked or restricted by CIDR; domain allowlists are Beta and live policy changes are Alpha. Tunnels and connect tokens expose applications.

Beta Modal VM Sandboxes provide a conventional Linux kernel. Sandbox output and resource data appear in logs and metrics. Team and Enterprise plans add RBAC; Enterprise audit logs cover control-plane changes rather than individual exec commands.

Northflank uses Kata Containers with Cloud Hypervisor as its primary microVM approach, with Firecracker and gVisor where supported and appropriate. In BYOC, runtime availability and selection depend on the provider, region, and node-pool configuration. Northflank Cloud GPU workloads use gVisor by default.

Private networking connects Northflank sandboxes with internal services. Teams can add network policies, multi-project access, public ports, and configurable egress. Logs and metrics, health checks, alerts, audit logs, log sinks, and BYOC monitoring span the stack.

How do Northflank and Modal Sandboxes compare on developer experience?

Modal provides a code-first workflow, while Northflank combines governed developer self-service with platform automation across the sandbox and its supporting stack.

Python is Modal's primary language. Its Beta JavaScript/TypeScript and Go SDKs also create Sandboxes, run commands, manage files, and expose ports.

Northflank supports Dockerfiles, Buildpacks, Workflows, Templates, GitOps, API, CLI, and a JavaScript client. Skills for coding agents help compatible agents deploy and troubleshoot through the API and CLI. Agents authenticate with API tokens, inherit the token's RBAC permissions, and have their API or CLI actions recorded in audit logs.

Northflank Preview Blueprints automatically create full-stack branch or pull-request environments with applications, data, jobs, volumes, networking, seed workflows, and URLs. Modal provides Functions, endpoints, storage, Queues, and batch execution that developers can assemble around a Sandbox.

How do infrastructure control and data residency differ?

Modal runs its public Sandbox service on managed AWS, GCP, and OCI infrastructure with optional region selection. Northflank offers Northflank Cloud; self-service production BYOC across AWS, GCP, Azure, Oracle Cloud, Civo, CoreWeave, and Nebius; and eligible BYOK for public-cloud, on-premises, or bare-metal Kubernetes clusters.

Broad or narrow Modal region pinning adds a 1.5x or 1.75x multiplier. Data-plane requests go to the selected region, lifecycle requests use Modal's US-east control plane, and Modal-managed logs, storage, Secrets, Queues, and snapshots remain in the United States.

Northflank Cloud provides the managed path. With production BYOC, workloads run in the customer's account and VPC while Northflank manages the platform layer. The customer retains the account, network, capacity choices, policies, and cloud bill.

Northflank has supported self-service production BYOC since 2019. Eligible Northflank BYOK connects cloud, on-premises, or bare-metal Kubernetes. BYOC requires at least one node and BYOK three, with at least 12 vCPU and 24 GB per cluster.

How do Northflank and Modal Sandboxes compare on pricing?

Modal uses Sandbox-specific rates; Northflank uses Cloud compute rates or BYOC platform plus infrastructure billing.

  • Modal Sandboxes: Modal's Starter plan has no platform fee and includes $30 of monthly compute. Team costs $250 per month plus usage and includes $100 of monthly compute; Enterprise is custom. CPU costs $0.1419 per physical core-hour, with one physical core equivalent to 2 vCPUs. Memory costs $0.0240 per GiB-hour. Billing uses the higher of requested or actual usage, while region pinning and non-preemptible execution add multipliers.
  • Northflank: Northflank offers an always-on free Sandbox tier, self-service Pay-as-you-go, and custom Enterprise plans. The free tier includes two services, one database, and two cron jobs. Northflank Cloud pricing is billed per second without Pay-as-you-go seat fees, starting at $0.01667 per vCPU-hour and $0.00833 per GB-hour. Persistent storage costs $0.15 per GB-month, and network egress costs $0.06 per GB. In BYOC, Northflank charges platform fees while the cloud provider bills infrastructure directly.

Compare total workload costs, including storage, transfer, GPUs, plan fees, and supporting services.

When do Modal Sandboxes fit your requirements?

Modal Sandboxes fit teams that want serverless isolated execution expressed through application code and operated on Modal-managed infrastructure.

  • Your application uses Modal Functions, inference, training, batch jobs, Notebooks, or storage.
  • Python-first definitions and programmatic Sandbox creation match the team's workflow.
  • A 24-hour per-Sandbox maximum works with replacement Sandboxes backed by filesystem snapshots, Volumes, or cloud bucket mounts.
  • gVisor, network controls, burstable CPU or GPU resources, and Modal-managed infrastructure fit; Beta V2 supports high creation rates or concurrency.

When does Northflank fit your requirements?

Northflank fits teams that need production-grade isolated CPU or GPU sandboxes alongside the supporting application stack, with control over deployment location, networking, Kubernetes infrastructure, security, and observability.

  • Sandboxes need no fixed session limit and must run beside persistent services, workers, jobs, and data.
  • Automatic previews must reproduce applications, data, networking, and seed workflows.
  • Developers need self-service while platform teams control networking, resources, node pools, policies, and deployment location.
  • Self-service production BYOC, eligible BYOK, or direct cloud-provider billing is required.

Northflank vs Modal Sandboxes: final decision

Modal fits teams that want code-first sandbox and AI-compute workloads on Modal-managed serverless infrastructure. Northflank fits teams building production architectures in which secure CPU or GPU sandboxes, APIs, workers, jobs, managed data, private networking, previews, observability, and customer-controlled infrastructure operate as one governed system.

Choose based on the operating model: Modal for application-defined serverless compute on a managed platform, or Northflank for one control plane spanning isolated execution and the production architecture.

Run secure sandboxes and their supporting production architecture on Northflank.

Kata Containers with Cloud Hypervisor is the primary microVM approach, with Firecracker and gVisor where supported and appropriate. One control plane spans applications, data, workflows, previews, and CPU or GPU workloads across Northflank Cloud, production BYOC, or eligible BYOK.

Northflank has supported self-service production BYOC since 2019. Northflank Skills help compatible coding agents deploy and troubleshoot through the API and CLI. Agents authenticate with API tokens, inherit the token's RBAC permissions, and have their API or CLI actions recorded in audit logs.

Get started with Northflank self-serve, or book a demo to discuss architecture, security, compliance, data residency, or migration requirements.

Frequently asked questions about Northflank vs Modal Sandboxes

These answers summarise the main differences.

What is the main difference between Northflank and Modal Sandboxes?

Both provide isolated CPU and GPU execution. Modal delivers it through a code-first serverless AI platform on Modal-managed infrastructure. Northflank delivers production-grade sandboxes through an application and infrastructure control plane that also runs services, workers, jobs, managed data, previews, and customer-cloud deployments.

Is Northflank a Modal Sandboxes alternative?

Yes. Northflank provides programmatically controlled, isolated CPU or GPU sandboxes and also runs the APIs, workers, jobs, managed data, networking, previews, and infrastructure supporting them.

Is Northflank or Modal better for AI-agent sandboxes?

Modal fits agents beside other Modal AI workloads. Northflank fits agents sharing production networking, data, governance, or customer-cloud infrastructure.

How do Northflank and Modal Sandboxes preserve state?

Modal uses filesystem and directory snapshots, Volumes, and bucket mounts; memory snapshots are Alpha. Northflank volumes preserve data across restarts and scale-to-zero, while Templates and Workflows reproduce the surrounding topology.

Can Modal Sandboxes run in your own cloud account?

No. Modal Sandboxes run on Modal-managed multi-cloud infrastructure with optional region selection. Northflank offers self-service BYOC for customer cloud accounts and eligible BYOK for existing Kubernetes infrastructure

Do Northflank and Modal Sandboxes support GPUs?

Yes. Northflank supports GPU sandboxes in GPU-enabled Northflank Cloud regions and on compatible BYOC GPU node pools. Modal supports GPU sandboxes on its standard runtime, but its V2 Beta backend does not yet support GPUs and its Beta VM Sandboxes currently support CPU workloads only.

How do Northflank and Modal Sandboxes isolate code execution?

Standard Modal Sandboxes use gVisor; Beta VM Sandboxes provide a conventional Linux kernel. Northflank uses Kata Containers with Cloud Hypervisor as its primary microVM approach, with Firecracker and gVisor where supported and appropriate.

Is Northflank or Modal Sandboxes cheaper?

Modal can fit intermittent serverless execution, but plan fees, physical-core pricing, GPUs, and regional multipliers affect cost. Northflank combines a free Sandbox tier, Pay-as-you-go without seat fees, and Enterprise plans with per-second Cloud compute or direct BYOC infrastructure billing.

Share this article with your network
X