Found via "Some random thoughts on improving self-hosting of software at home"
http://notes.whatthefuck.computer/1493081100.0-note.html
We claim that Sandstorm mitigates most security bugs in apps, by default. We also claim that Sandstorm is the easiest way ever to deploy small-scale (personal, or corporate-internal) web services.
Understandably, people used to the status quo find these claims hard to believe. It sounds like magic.
On this page, we will explain the two main pieces of "magic" that make it all work:
Fine-grained Containerization
Capability-based Security