Watasu
EU data residency · per-second compute

The infrastructure
behind your AI.

Isolated sandboxes to run agents and untrusted code. Native voice and WebRTC to give them a real-time interface. A push-to-deploy platform to host the rest of your app. Everything an AI product runs on — one API, one bill, hosted entirely in the EU.

Per-second sandboxes EU data residency Voice-agent ready
api.watasu.io · eu-resident
POST /v1/sandboxes
{ "template_id": "agent-base", "timeout": 3600 }
→ 201 · id sbx_5f2a · running in 1.9s
WS /runtime/v1/process
stream python agent_task.py
→ exit 0 · /out/report.md · 18 KB
POST /v1/sandboxes/sbx_5f2a/checkpoints
→ saved · resume anytime, anywhere in the EU
2 vCPU · 1 GiB — metered per second ≈ €0.08 / hour
One platform

Everything your AI product runs on, in one place.

Three things an AI product needs, on one EU-resident stack. Start with sandboxes; add a voice interface and host the rest of your app whenever you're ready — same API key, same bill.

Run agents & untrusted code

Sandboxes

Isolated Linux microVMs behind a simple API. Give every agent its own real computer — a shell, a filesystem, a preview URL — for evals and always-on production runs. Boots in seconds, billed per second.

Explore Sandboxes
Give your agent a voice

Voice & WebRTC

Name a process *-rtc and you get a managed TURN gateway, a public UDP port, and a stable per-replica hostname — TURN_* injected as env vars. Ship voice agents without standing up a separate media stack.

Voice on the platform
Host the rest of your app

PaaS

Push-to-deploy hosting for everything around the agent — your app, APIs, and workers, plus managed PostgreSQL, Valkey, ClickHouse, and more. Git push to a URL with TLS, scale per process, no clusters to babysit.

Explore the platform
Why EU residency matters

If your AI touches EU data, the deadlines have already started.

This isn't a future compliance project. The regime governing where and how AI systems run in Europe is in force now — and most of these dates are already behind you. Running agents on US-controlled compute is the exposure these rules were written to close.

  1. Regulation (EU) 2024/1689 — EU AI Act

    In force Since 2 Feb 2025

    Prohibited AI practices and AI-literacy duties already apply. General-purpose AI model obligations have applied since 2 August 2025. High-risk system obligations land 2 August 2026.

  2. Regulation (EU) 2022/2554 — DORA

    In force Since 17 Jan 2025

    Financial entities must maintain a register of their ICT third-party providers and manage concentration and third-country dependency risk. A US-controlled compute vendor is exactly the dependency this regime scrutinises.

  3. Regulation (EU) 2023/2854 — EU Data Act

    In force Since 12 Sep 2025

    Safeguards against unlawful third-country government access to data, plus a right to switch cloud providers without lock-in. Both cut against compute you cannot move and cannot shield.

  4. Directive (EU) 2022/2555 — NIS2

    In force Since 17 Oct 2024

    Supply-chain and ICT security obligations extend down to the providers you depend on. Your infrastructure choices are now in scope of your own security duties.

  5. GDPR Ch. V · CJEU C-311/18 (Schrems II)

    Standing law Since 16 Jul 2020

    Transfers to US-controlled processors need Standard Contractual Clauses and a documented Transfer Impact Assessment. The EU–US Data Privacy Framework only helps if your provider self-certifies — and it is under live appeal at the Court of Justice.

  6. 18 U.S.C. §2713 — US CLOUD Act

    The reason a region cannot fix it Since 2018

    US authorities can compel any US-controlled provider to produce your data wherever in the world it is stored. A US company opening an EU region does not change who can be served the warrant.

Watasu is where regulated EU teams can actually run this.

Your sandboxes, voice gateways, and databases run in EU data centers and never cross the Atlantic. Watasu is not a US company and is not subject to the US CLOUD Act, so there is no foreign warrant that reaches your data through us. A Data Processing Agreement is on the table from day one. For a team whose own customers or regulator demand EU residency, that is not a nice-to-have — it is the difference between being allowed to ship and not.

EU-only data centers No transatlantic data transfer DPA available Read our security posture
Sandboxes

Evals and production agent runs, same API.

A sandbox is a real Linux machine your agent controls — created on demand, destroyed when done. The same API handles both shapes of the work: the bursty test runs and the long-lived production sessions.

Evals & bursts

Spin up hundreds of short-lived sandboxes for a test suite or a benchmark, run model-written code in parallel, collect the results, tear them all down. You pay for the seconds they ran, nothing for the idle between runs.

Production agent runs

Keep a sandbox alive for the length of a real session — hours of an autonomous agent acting on customer data. Checkpoint to pause and resume, with idle auto-pause and hard spend ceilings so a forgotten agent can never run up an open-ended bill.

Isolated by default — each sandbox walled off from your apps and every other tenant
Checkpoints — snapshot the disk mid-task to pause, branch, or recover a session
Preview URLs — expose a port, get an HTTPS *.sandbox.watasuhost.com address
Reusable templates — build the environment once, every sandbox starts ready
When you're ready to ship the whole product

The platform that runs everything around the agent.

Most teams building agents don't have a DevOps engineer to spare. Once your agent runtime lives in Watasu, the rest of the product can too — hosted on the same EU-resident stack, on the same bill, with no clusters to babysit.

Native voice agents

*-rtc

A dedicated TURN gateway, a public UDP port, and a stable hostname per replica — provisioned from a process name. Run a voice agent in the EU without standing up a separate media stack.

Push-to-deploy hosting

git push to a managed URL with TLS. Cloud Native Buildpacks or your Dockerfile, multi-DC by default, standard containers with no lock-in.

Managed data & observability

PostgreSQL, Valkey, ClickHouse, Redpanda, object storage — one command to attach, Grafana wired in. The state and the dashboards your agent product needs, already managed.

Pricing

Pay for seconds, not servers.

Sandbox runtime is billed per second for the vCPU and memory you request — and because Watasu is prepaid, a runaway agent can only ever spend your balance, never run up an open-ended bill.

Sandbox runtime — billed per second
vCPU €0.000010/vCPU·s
Memory €0.000002/GiB·s

A 2 vCPU / 1 GiB sandbox costs about €0.08 per hour while it runs — a 90-second eval costs a fifth of a cent. Stopped disks and checkpoints are billed per GiB, prorated monthly.

No runaway bills, by design

  • Prepaid balance — top up first, usage draws down against it
  • Hard spend ceilings and idle auto-pause on every sandbox
  • Honest EUR — the price you see is the price your card is charged
  • App hosting and add-ons priced in plain monthly EUR

Give your AI a place to run — in the EU.

Create an API key, spin up your first sandbox, and run code that arrives faster than you can review it — safely.