Is this a hard sandbox (enforced outside the LLM)?