The Mu computer is built from scratch without dependencies. Every part of the stack tracks its dependencies. There are no side-effects, only effects. As a result, sandboxing computations is safe and rigorous.
Main project page: https://github.com/akkartik/mu