June 29, 2026·By Stride Techworks·11 min readRun the agent, keep the data: self-hosted sandboxes and MCP tunnels, explained for small teamsThe thing blocking your agent from production usually isn't the model — it's that the data can't leave the building. Anthropic's May 19 release splits the agent loop from tool execution and reaches private systems through an outbound-only tunnel. Here's what each piece actually is, whether you need it, and what to do if you don't have an enterprise contract.agent-systemsinfrastructureoperatorssecuritymcpon-prem