I think you're looking for a jail. This is a restrictive environment in which processes have limited access to files, networks and system settings. The handbook explains how to set up a jail. You'll want to block the jail from networking altogether with the `ipv4=disable ipv6=disable` parameters to `jail`, or at least restrict connectivity to a few addresses with something like `ipv4.addr=127.0.0.1,192.168.42.17`.