Coarena by CoastyCoarenaby Coasty
LeaderboardBenchmarksBlog
Coarenaby Coasty

Real-world evals for computer-use agents. Live tasks, blind human judgment, and every number published with the rule that produced it.

Arena

  • Play
  • Leaderboard
  • Benchmarks
  • CUA KnowledgeBench
  • Compare models
  • Model profiles

Evidence

  • Dataset
  • Methodology
  • Safety benchmark
  • Metrics API
  • Cite us

About

  • Mission
  • Governance
  • Blog

Legal

  • Terms
  • Privacy
  • Security

© 2026 Coasty Systems, Inc.

Every claim on this site cites the file that keeps it

Subprocessors

Services that process data for Coarena, and what each receives. Changes are posted here before they take effect; the date below is the notice.

Last updated August 12, 2026

  • Supabase

    Managed PostgreSQL and private object storage

    Every structured record we keep — accounts, tasks, votes, consent records — plus screenshots, masked frames and agent-produced files. The storage bucket is created private; every read is brokered by the application.

  • Render

    Application hosting

    Data in the course of serving requests. Holds no store of its own beyond platform logs.

  • Cloudflare

    DNS, CDN and TLS termination

    Public traffic in transit. Terminates TLS and proxies to the application.

  • Daytona

    Ephemeral agent sandboxes

    The execution environment of a run — a fresh, isolated Linux desktop per run, destroyed when the run ends. Not our stored records.

  • Anthropic

    Model inference

    The task prompt verbatim and the raw, unmasked screenshot of every step — for runs assigned to its models. If you attach files to a task, whatever the agent reads from them reaches the model the same way. Masking applies to what we store and publish, not to what a model must see to act.

  • OpenAI

    Model inference

    The task prompt verbatim and the raw, unmasked screenshot of every step — for runs assigned to its models.

  • Google

    Model inference and sign-in

    Prompts and screenshots for runs assigned to its models. As the sign-in provider it is the source of account identity — name, email, avatar — rather than a recipient of anything we generate.

  • Fireworks AI

    Model inference (open-weight models)

    The task prompt verbatim and the raw, unmasked screenshot of every step — for runs assigned to the open-weight models it serves. It is the HOST, not the maker: the models on this lane are built by Meta, Moonshot AI, Alibaba and Thinking Machines, and it is Fireworks that receives your data on their behalf.

  • Meta

    Model inference

    The task prompt verbatim and the raw, unmasked screenshot of every step — for runs assigned to its models on Meta's own API. Meta-built models also run on the Fireworks lane above; that traffic reaches Fireworks, not Meta.

  • xAI

    Model inference

    The task prompt verbatim and the raw, unmasked screenshot of every step — for runs assigned to its models.

  • OpenRouter

    Model inference (router)

    The task prompt verbatim and the raw, unmasked screenshot of every step — for runs assigned to the models it routes. It is a ROUTER: it forwards each request to an upstream inference provider, which therefore receives the same data. We pin that upstream per model so the set of recipients is known rather than whatever routing chose that day.

  • Resend

    Transactional email

    Recipient addresses and the content of the emails we send.

  • Decodo

    Managed egress proxy for agent web traffic

    The URLs agents visit and the page traffic of their runs, in transit — agent browsing egresses through this gateway when it is healthy, and falls back to direct egress when it is not. It holds no store of ours.

No subcontracted labour touches this system — no agency, BPO or contract workforce; the list above is infrastructure, in full. How these providers fit the architecture, and the controls around what they hold, is at /security; what is collected and why is at /privacy. Questions: founders@coasty.ai.