Sandbox won’t be enough, distroless + “data firewall” + audit

Indeed, but a rock solid sandboxing and isolation strategy is step 0.