We have exactly the same issues for the cloud and ended up securing everything through nsjail and the deno run sandboxing. I admire that you're willing to allow unauthentified users to run computations. Do you guys have timeout ? How do you ensure resource isolation? We use kubernetes for resource isolation, and we use both timeouts and quotas where each second a background process will kill the job if the user/job is over it. Let me know if you guys are up to chat at some point and congrats on the very nice UX.