Baseten Buys Blaxel, Whose 'Keeps Running' Pledge Has No End Date

Blaxel says its agent sandboxes keep running under Baseten, but the promise has no end date, and its standard terms allow assignment without consent, renewal repricing and data deletion 90 days after termination.

By Rajesh Beri·September 23, 2026·9 min read
Share:
A row of server blades in a data-centre rack with one blade half pulled out and a paper shipping tag tied to its handle, the tag blank, under cool blue aisle lighting.

Illustration generated using AI

If your agents execute code in Blaxel sandboxes, your contract now belongs to Baseten, and nothing you have in writing says for how long the product you bought will exist in its current form. Blaxel's customer note promises that "the Blaxel platform keeps running" and that API keys, credits and support contacts are unchanged. It names no end date, no SLA, and no price hold. Blaxel's own standard terms let it assign your agreement to an acquirer without your consent and reprice renewals at "then-current rates". The time to fix that is before your next renewal or credit top-up, not after the migration notice arrives.

Baseten, the inference company valued at $13 billion after its Series F, announced the deal on September 10, 2026. Terms were not disclosed. Blaxel had raised a $7.3 million seed before the deal.


What Did Baseten Actually Buy?

Baseten bought an agent runtime: microVM sandboxes that suspend and resume in about 25 milliseconds and sit idle for months at near-zero cost. That persistence model is the product, and it is the thing that is hardest to move.

An agent sandbox is an isolated execution environment where a model's generated code, tool calls and shell commands run, walled off from your production systems. Blaxel gives each one its own microVM. It pairs that with Agent Drive, a shared distributed filesystem, and a networking layer that connects agents to tools, MCP servers and APIs. Blaxel claims its sandboxes spin up and resume up to 5x faster than competing products. That is a vendor claim, and nobody has published an independent benchmark of it.

The reference customer in Blaxel's note, Sapiom, ran 2.5 million sandboxes on Blaxel over three months. Before the deal, Blaxel reported running agent requests across 16 regions.

Baseten's reason for buying is plain. Its CTO, Amir Haghighat, said "AI applications have moved from models that generate answers to agents that actually do things." Baseten wants to own the loop between a model's output and the agent's next action. Its customers include Cursor, Clay, Lovable and Abridge. This is Baseten's second deal after Parsed, a reinforcement learning startup.

What Does the Continuity Promise Cover, and What Does It Leave Out?

The promise covers today: your keys, your credits, your support contacts. It says nothing about duration, price, SLA, compliance scope or where your data runs.

Here is the full scope, from the two posts. Blaxel's post says access, credits and "the people you talk to are unchanged" and that no action is required. It also says that if anything about your setup needs to move, "you'll hear it from us first with plenty of notice", without defining plenty. Baseten's own post goes a bit further: "The product doesn't change, and features will keep shipping." It then adds the sentence that matters most: "Over time, Baseten will add new products based on Blaxel's primitives, starting with Sandboxes."

In plain terms, Baseten will ship a sandbox product of its own. The press release says the long-term plan is deeper integration with Baseten's inference, storage, observability and enterprise infrastructure. No timeline covers Agent Drive or the networking layer.

Give Baseten the fair reading. Keeping the acquired team on the acquired product is the correct first move. Baseten has strong reasons not to spook Blaxel's customers, and many deals like this one really do run the old product for years. The problem is not that the promise is false. The problem is that it is a blog post, and blog posts are not contracts.

This site has watched that gap play out repeatedly. Stilla promised continuity, then Meta bought it for WhatsApp. Klaviyo bought Agency and set a shutdown date. Guardrails AI's Hub went dark on August 25 after Harvey hired the team. None of those buyers broke a written promise, because none of them had made one.

What Do Blaxel's Standard Terms Actually Let the New Owner Do?

Blaxel's standard terms (last amended December 10, 2025) let it hand your contract to Baseten, reprice you at renewal, and delete your data within 90 days of termination. Unless you signed an order that overrides them, these are your terms today.

Here is what the published Standard Terms and Conditions say:

  • Assignment (§21.1). Neither party may assign without consent, "except that either party may assign this Agreement in connection with a merger, reorganization, acquisition" or sale of substantially all assets. Your consent is not needed for the Baseten transfer.
  • Renewal pricing (§10.1). Renewal fees "are at Blaxel's then-current rates, regardless of any discounted pricing in a prior Order." A launch discount does not survive the next term.
  • Term changes (§13). Blaxel may amend the standard terms by posting them. Without an active subscription order, revisions take effect "upon Customer's next purchase of Service Credits." With one, they take effect at renewal. For a usage-based account, every top-up is a chance for new terms to take effect.
  • Credits (§10.2). Unused credits expire one year after purchase and are non-refundable. "Your credits are unchanged" does not change the expiry date.
  • No uptime SLA. Support is "commercially reasonable efforts" (§3). The warranty (§11.1) only promises Blaxel will not "materially decrease the overall functionality" during the term, and the remedy is a refund of prepaid fees.
  • Data after termination (§12.4). Blaxel has no obligation to retain customer data and "may delete" it at any time, with nothing kept beyond 90 days.
  • Liability cap (§15.2). Twelve months of fees.

None of this is unusual for a seed-stage infrastructure vendor. It becomes a problem when the vendor has a new owner with its own sandbox product on the way.


Why Is Sandbox Lock-In Different From Inference Lock-In?

List prices for a basic sandbox are almost identical across providers, so price is not the lock-in. The lock-in is the persistence model your agents were built around.

Compare list prices as of September 24, 2026, for a 2 vCPU / 4 GB sandbox, the default size at E2B:

Provider Published rate ~Hourly, 2 vCPU / 4 GB active Idle/persistence model
Blaxel $0.0000115 per GB-second active ~$0.17 (4 GB) Standby is free of compute; snapshot storage $0.20/GB-month; ~25ms resume
E2B $0.000014/vCPU-s + $0.0000045/GiB-s ~$0.17 24 hours continuous running on Pro ($150/month); pause keeps memory and files with no expiry, ~1s resume
Daytona $0.0504/vCPU-hr + $0.0162/GiB-hr ~$0.17 Per-second billing; enterprise BYOC

The hourly figures are my arithmetic on each vendor's published rate card. They are not quotes, and real bills will depend on how each vendor meters idle time.

At about 17 cents an hour, switching vendors is not expensive. Switching behaviour is. Parking a sandbox with memory intact is not unique to Blaxel: E2B also pauses sandboxes indefinitely, and its 24-hour cap resets on each pause. But E2B's documented resume is about a second, not 25 milliseconds, and each provider's pause, resume and snapshot APIs differ. Code that writes to Agent Drive has no drop-in equivalent elsewhere. If your agents depend on sub-second resume or Agent Drive, your exit cost is engineering time, and you will not see it until you test a second provider.

Compliance is the second trap. Blaxel lists SOC 2 Type II and ISO 27001 and offers a HIPAA BAA, and says its deployment policies restrict workloads to US and EU regions. All of those attach to Blaxel's current environment. When workloads move onto Baseten's infrastructure, the audit scope, subprocessors and region list could change. A new product built on "Blaxel's primitives" has its own SOC 2 scope to earn.

What Should Platform Teams Running on Blaxel Do Now?

Turn the blog post into contract language, and prove you can run your sandboxes on a second provider, before your next renewal or top-up.

This Week:

  1. Find your governing document. Did you sign an order form, or did you click through the standard terms? Under §21.13, order terms override the standard terms. If you only have the click-through, every clause above applies to you.
  2. Inventory what depends on persistence. List every agent workflow that parks and resumes a sandbox on a latency-sensitive path, resumes a snapshot, or writes to Agent Drive. That list is your real migration cost.
  3. Check your credit balance against the one-year expiry. Do not prepay a large top-up until you have the terms below. A top-up is also the event that triggers any amended terms (§13).

This Month:

  1. Ask Baseten for a dated continuity letter. Turn "plenty of notice" into a number. It should cover: a minimum run period for the current Blaxel product, 12 months' notice of any migration or end-of-life, a price hold through your next renewal, confirmation that SOC 2 Type II and ISO 27001 scope carries over to any successor environment, your region commitments, and a data-export window longer than the 90 days in §12.4.
  2. Put a thin interface in front of sandbox execution. Route create, exec, snapshot and destroy through your own wrapper, so the provider is a configuration value rather than a rewrite. Our coverage of the eval sandbox that gave up its keys explains why that wrapper is also where egress and credential controls belong.
  3. Run one real workload on a second provider. Pick your highest-volume agent task and run it on E2B, Daytona or Modal for a week. Measure cold-start, resume and failure rates. Then you will know whether 25 milliseconds is a requirement or a convenience.

Before Renewal:

  1. Negotiate the successor clause. If Baseten's own sandbox product is where Blaxel is headed, get the migration terms now, while you still have leverage: pricing parity, a migration credit, and no forced move during a quarter-end freeze.

The Bottom Line

This deal is a sensible move by Baseten, and it is still a change-of-control event on the most security-sensitive part of your agent stack. Sandboxes are where model-written code touches real systems. Supply-chain incidents have already come through build and docs pipelines, so the execution layer is the last place to accept an undated promise.

Treat it the way you would treat any core platform vendor changing hands before your renewal window. The pattern from every vendor exit this year is the same: teams with a second provider already tested move on their own schedule, and everyone else moves on the vendor's.

"Keeps running" is a status. Get the end date on paper.

Continue Reading

Share:

Frequently Asked Questions

Did Baseten acquire Blaxel?

Yes. Baseten, the AI inference company valued at $13 billion after its Series F, announced the acquisition of agent-sandbox startup Blaxel on September 10, 2026. Financial terms were not disclosed.

Will Blaxel keep running after the Baseten acquisition?

Blaxel and Baseten say the platform keeps running, features keep shipping, and API keys, credits and support contacts are unchanged. Neither post gives a duration, SLA or price commitment, and Baseten says it will add new products built on Blaxel's primitives, starting with Sandboxes.

Can Blaxel transfer my contract to Baseten without my consent?

Under Blaxel's standard terms (amended December 10, 2025), section 21.1 lets either party assign the agreement in connection with a merger or acquisition without the other party's consent. A signed order form with different language would override that.

What happens to my data if I leave Blaxel?

Section 12.4 of Blaxel's standard terms says Blaxel has no obligation to retain customer data after termination, may delete it at any time, and keeps none for more than 90 days. Export before you terminate.

What are the alternatives to Blaxel for AI agent sandboxes?

E2B, Daytona and Modal all offer sandboxed code execution for agents. For a 2 vCPU / 4 GB sandbox their list rates work out to roughly $0.17 per active hour, similar to Blaxel; the real difference is persistence behaviour, such as resume latency (Blaxel claims ~25ms; E2B documents ~1 second) and Blaxel's Agent Drive filesystem, which has no drop-in equivalent.

Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe

Latest Articles

View All →