NemoClaw — NVIDIA Security Stack for AI Agents

NemoClaw

AI エージェントを、安全に。NVIDIA の技術で。

コマンド一つでセキュアな AI エージェントスタックを構築。OpenShell サンドボックス + Nemotron ローカル推論 + Privacy Router——OpenClaw にエンタープライズレベルの安全を。

クイックスタート

ALPHA
# One-liner install for NemoClaw secure stack (Ubuntu 22.04+ recommended)
$ curl -fsSL https://www.nvidia.com/nemoclaw.sh | bash

Auto-installs Node.js, OpenShell runtime, and the NemoClaw CLI. Runs nemoclaw onboard after install.

主な機能

shield

OpenShell セキュアサンドボックス

カーネルレベルで AI エージェントの実行を隔離。ファイルシステム・ネットワーク・プロセスの 3 軸でポリシーベースの細かい制御が可能です。

route

Privacy Router

ローカルの Nemotron とクラウドモデルを自動で振り分け。機密データはデバイスから出さず、安全なリクエストだけクラウドに送ります。

memory

Nemotron ローカル推論

Nemotron 3 Super 120B MoE をローカルで実行。トークンコストゼロ、データ漏洩ゼロ。NVIDIA GPU で完全オフライン。

security

ネットワークポリシーエンジン

アウトバウンド通信はデフォルトで全拒否。外部接続にはオペレーターの承認が必要。すべてのネットワーク活動を監査ログに記録。

devices

マルチプラットフォーム対応

GeForce RTX、RTX PRO、DGX Station、DGX Spark で動作。開発用ワークステーションからエンタープライズデータセンターまで。

terminal

ワンコマンドインストール

コマンド一つで OpenShell、Nemotron、Privacy Router、NemoClaw CLI をまとめてデプロイ。

動画で見る

NemoClaw を動画で

GTC 2026 の発表、アーキテクチャデモ、デプロイの全手順を動画で。

menu_book ドキュメント全文を見る arrow_forward
@secops_maria avatar

"Default-deny networking was the killer feature for us. Every outbound request our agents make is logged and requires approval. Exactly what our compliance team needed."

@secops_maria
@devops_mike avatar

"Ran 'nemoclaw onboard' and had a fully sandboxed agent environment in under 5 minutes. OpenShell isolation gives us confidence to deploy AI agents in production."

@devops_mike
@ai_sarah avatar

"The Privacy Router is genius. Customer PII never leaves our infrastructure — only safe, anonymized queries hit the cloud models. Zero code changes from our existing agents."

@ai_sarah
@ciso_tom avatar

"Showed the OpenShell audit logs to our SOC 2 auditor. First time they've seen AI agent activity tracked at this level of detail. Passed with flying colors."

@ciso_tom
@mleng_jenny avatar

"Running Nemotron locally means zero token cost for internal queries. We cut our cloud AI spend by 70% while actually improving data privacy. Win-win."

@mleng_jenny
@platform_raj avatar

"Deployed NemoClaw on DGX Spark and it just works. Auto-detected the hardware, configured optimal model settings. One command to production-ready AI security."

@platform_raj
@secops_maria avatar

"Default-deny networking was the killer feature for us. Every outbound request our agents make is logged and requires approval. Exactly what our compliance team needed."

@secops_maria
@devops_mike avatar

"Ran 'nemoclaw onboard' and had a fully sandboxed agent environment in under 5 minutes. OpenShell isolation gives us confidence to deploy AI agents in production."

@devops_mike
@ai_sarah avatar

"The Privacy Router is genius. Customer PII never leaves our infrastructure — only safe, anonymized queries hit the cloud models. Zero code changes from our existing agents."

@ai_sarah
@ciso_tom avatar

"Showed the OpenShell audit logs to our SOC 2 auditor. First time they've seen AI agent activity tracked at this level of detail. Passed with flying colors."

@ciso_tom
@mleng_jenny avatar

"Running Nemotron locally means zero token cost for internal queries. We cut our cloud AI spend by 70% while actually improving data privacy. Win-win."

@mleng_jenny
@platform_raj avatar

"Deployed NemoClaw on DGX Spark and it just works. Auto-detected the hardware, configured optimal model settings. One command to production-ready AI security."

@platform_raj
@infra_alex avatar

"OpenShell's sandbox isolation caught a rogue agent trying to access /etc/passwd. In production. Without NemoClaw, that would have been a security incident."

@infra_alex
@devsec_lisa avatar

"Blueprints make repeatable secure deployments trivial. Define once, deploy everywhere. Every new agent gets the same security posture automatically."

@devsec_lisa
@security_emma avatar

"The network policy engine is exactly what we needed. Our agents can only reach pre-approved APIs. Everything else is blocked by default. Simple and effective."

@security_emma
@cloud_chris avatar

"Migrated 30 OpenClaw agents to NemoClaw. Zero code changes — just wrapped them in OpenShell sandboxes. Now we have full audit trails for every agent action."

@cloud_chris
@startup_nina avatar

"As a startup handling healthcare data, NemoClaw's Privacy Router was non-negotiable. Patient data stays on our GPUs, period. HIPAA compliance out of the box."

@startup_nina
@backend_kai avatar

"The OpenShell TUI is addictive. Watching agent actions in real-time, seeing network requests get approved or blocked — it's like Wireshark for AI agents."

@backend_kai
@infra_alex avatar

"OpenShell's sandbox isolation caught a rogue agent trying to access /etc/passwd. In production. Without NemoClaw, that would have been a security incident."

@infra_alex
@devsec_lisa avatar

"Blueprints make repeatable secure deployments trivial. Define once, deploy everywhere. Every new agent gets the same security posture automatically."

@devsec_lisa
@security_emma avatar

"The network policy engine is exactly what we needed. Our agents can only reach pre-approved APIs. Everything else is blocked by default. Simple and effective."

@security_emma
@cloud_chris avatar

"Migrated 30 OpenClaw agents to NemoClaw. Zero code changes — just wrapped them in OpenShell sandboxes. Now we have full audit trails for every agent action."

@cloud_chris
@startup_nina avatar

"As a startup handling healthcare data, NemoClaw's Privacy Router was non-negotiable. Patient data stays on our GPUs, period. HIPAA compliance out of the box."

@startup_nina
@backend_kai avatar

"The OpenShell TUI is addictive. Watching agent actions in real-time, seeing network requests get approved or blocked — it's like Wireshark for AI agents."

@backend_kai

よくある質問

NemoClaw について、聞かれることが多い質問をまとめました。

最新情報を受け取る

NemoClaw のリリース、セキュリティアドバイザリ、エコシステムのニュースをお届けします。スパムなし、いつでも解除 OK。