NemoClaw
Secure AI Agents. Powered by NVIDIA.
One command to deploy a secure AI agent stack. OpenShell sandbox + Nemotron local inference + Privacy Router — enterprise-grade security for OpenClaw agents.
Quick Start
curl -fsSL https://www.nvidia.com/nemoclaw.sh | bash Auto-installs Node.js, OpenShell runtime, and the NemoClaw CLI. Runs nemoclaw onboard after install.
Core Capabilities
OpenShell Secure Sandbox
Kernel-level isolation for AI agent execution. Policy-driven sandboxes with configurable filesystem, network, and process controls.
Privacy Router
Intelligent routing between local Nemotron models and cloud providers. Sensitive data stays on-device, only safe queries go to the cloud.
Nemotron Local Inference
Run Nemotron 3 Super 120B MoE model locally. Zero token cost, zero data leakage, full offline capability on NVIDIA GPUs.
Network Policy Engine
Default-deny outbound networking. Every external connection requires operator approval. Full audit trail of all network activity.
Multi-Platform Deployment
Run on GeForce RTX, RTX PRO, DGX Station, or DGX Spark. From developer workstation to enterprise datacenter.
One-Click Install
Single command deploys the complete security stack: OpenShell, Nemotron, Privacy Router, and the NemoClaw CLI.
NemoClaw In Action
Watch the GTC 2026 announcement, architecture demos, and deployment walkthroughs.
menu_book View official documentation arrow_forwardLatest Updates
From OpenClaw to NemoClaw: The Security Story
How OpenClaw's explosive growth to 300,000+ GitHub stars exposed critical enterprise security gaps, leading to NVIDIA's collaboration and the birth of NemoClaw. Peter Steinberger tells the story.
NemoClaw Ecosystem: Partners Building the Future
Adobe, Salesforce, SAP, Dell, Cisco, and LangChain are building on NemoClaw. A look at the growing ecosystem of integrations, partner commitments, and the roadmap for the open agent security platform.
Enterprise Use Cases for NemoClaw
How enterprises are deploying NemoClaw for customer support automation, sales operations, security operations, and infrastructure management. Real-world scenarios with security policy examples.
What People Say
"Default-deny networking was the killer feature for us. Every outbound request our agents make is logged and requires approval. Exactly what our compliance team needed."
@secops_maria"Ran 'nemoclaw onboard' and had a fully sandboxed agent environment in under 5 minutes. OpenShell isolation gives us confidence to deploy AI agents in production."
@devops_mike"The Privacy Router is genius. Customer PII never leaves our infrastructure — only safe, anonymized queries hit the cloud models. Zero code changes from our existing agents."
@ai_sarah"Showed the OpenShell audit logs to our SOC 2 auditor. First time they've seen AI agent activity tracked at this level of detail. Passed with flying colors."
@ciso_tom"Running Nemotron locally means zero token cost for internal queries. We cut our cloud AI spend by 70% while actually improving data privacy. Win-win."
@mleng_jenny"Deployed NemoClaw on DGX Spark and it just works. Auto-detected the hardware, configured optimal model settings. One command to production-ready AI security."
@platform_raj"Default-deny networking was the killer feature for us. Every outbound request our agents make is logged and requires approval. Exactly what our compliance team needed."
@secops_maria"Ran 'nemoclaw onboard' and had a fully sandboxed agent environment in under 5 minutes. OpenShell isolation gives us confidence to deploy AI agents in production."
@devops_mike"The Privacy Router is genius. Customer PII never leaves our infrastructure — only safe, anonymized queries hit the cloud models. Zero code changes from our existing agents."
@ai_sarah"Showed the OpenShell audit logs to our SOC 2 auditor. First time they've seen AI agent activity tracked at this level of detail. Passed with flying colors."
@ciso_tom"Running Nemotron locally means zero token cost for internal queries. We cut our cloud AI spend by 70% while actually improving data privacy. Win-win."
@mleng_jenny"Deployed NemoClaw on DGX Spark and it just works. Auto-detected the hardware, configured optimal model settings. One command to production-ready AI security."
@platform_raj"OpenShell's sandbox isolation caught a rogue agent trying to access /etc/passwd. In production. Without NemoClaw, that would have been a security incident."
@infra_alex"Blueprints make repeatable secure deployments trivial. Define once, deploy everywhere. Every new agent gets the same security posture automatically."
@devsec_lisa"The network policy engine is exactly what we needed. Our agents can only reach pre-approved APIs. Everything else is blocked by default. Simple and effective."
@security_emma"Migrated 30 OpenClaw agents to NemoClaw. Zero code changes — just wrapped them in OpenShell sandboxes. Now we have full audit trails for every agent action."
@cloud_chris"As a startup handling healthcare data, NemoClaw's Privacy Router was non-negotiable. Patient data stays on our GPUs, period. HIPAA compliance out of the box."
@startup_nina"The OpenShell TUI is addictive. Watching agent actions in real-time, seeing network requests get approved or blocked — it's like Wireshark for AI agents."
@backend_kai"OpenShell's sandbox isolation caught a rogue agent trying to access /etc/passwd. In production. Without NemoClaw, that would have been a security incident."
@infra_alex"Blueprints make repeatable secure deployments trivial. Define once, deploy everywhere. Every new agent gets the same security posture automatically."
@devsec_lisa"The network policy engine is exactly what we needed. Our agents can only reach pre-approved APIs. Everything else is blocked by default. Simple and effective."
@security_emma"Migrated 30 OpenClaw agents to NemoClaw. Zero code changes — just wrapped them in OpenShell sandboxes. Now we have full audit trails for every agent action."
@cloud_chris"As a startup handling healthcare data, NemoClaw's Privacy Router was non-negotiable. Patient data stays on our GPUs, period. HIPAA compliance out of the box."
@startup_nina"The OpenShell TUI is addictive. Watching agent actions in real-time, seeing network requests get approved or blocked — it's like Wireshark for AI agents."
@backend_kaiFrequently Asked Questions
Common questions about NemoClaw and how it works.