or "the following programs will be the only programs that can run in this sandbox"...
That should work - except for webpage script loggers.
In the case of webpage script loggers the only thing that can
potentially block logging is a encryption - like HitmanPro.Alert, SpyShelter or KeyScrambler.
However, I think the likelihood that they will protect against webpage script logging is low.
Something like NoScript or equivalent might do a better job of it.