NemoClaw — NVIDIA Security Stack for AI Agents

NemoClaw

Безопасный ИИ. Сила NVIDIA.

Одна команда разворачивает полный защищённый стек для ИИ-агентов. Песочница OpenShell + локальный инференс Nemotron + Privacy Router -- безопасность корпоративного уровня для агентов OpenClaw.

Быстрый старт

ALPHA
# One-liner install for NemoClaw secure stack (Ubuntu 22.04+ recommended)
$ curl -fsSL https://www.nvidia.com/nemoclaw.sh | bash

Auto-installs Node.js, OpenShell runtime, and the NemoClaw CLI. Runs nemoclaw onboard after install.

Основные возможности

shield

Песочница OpenShell

Изоляция процессов ИИ-агентов на уровне ядра. Гибкие политики доступа к файловой системе, сети и процессам.

route

Privacy Router

Интеллектуальная маршрутизация между локальными моделями Nemotron и облачными провайдерами. Конфиденциальные данные остаются на устройстве -- в облако уходят только безопасные запросы.

memory

Локальный инференс Nemotron

Запускайте Nemotron 3 Super 120B MoE на своём железе. Нулевые затраты на токены, нулевой риск утечки данных, полноценная офлайн-работа на GPU NVIDIA.

security

Движок сетевых политик

Исходящие соединения заблокированы по умолчанию. Любое внешнее подключение требует явного разрешения оператора. Полная история всей сетевой активности.

devices

Кроссплатформенное развёртывание

Работает на GeForce RTX, RTX PRO, DGX Station и DGX Spark. От рабочего места разработчика до корпоративного дата-центра.

terminal

Установка одной командой

Единственная команда разворачивает весь стек: OpenShell, Nemotron, Privacy Router и NemoClaw CLI.

Смотреть в деле

NemoClaw на практике

Анонс на GTC 2026, демонстрации архитектуры и пошаговые руководства по развёртыванию.

menu_book Перейти к официальной документации arrow_forward

Свежие публикации

Все статьи arrow_forward
@secops_maria avatar

"Default-deny networking was the killer feature for us. Every outbound request our agents make is logged and requires approval. Exactly what our compliance team needed."

@secops_maria
@devops_mike avatar

"Ran 'nemoclaw onboard' and had a fully sandboxed agent environment in under 5 minutes. OpenShell isolation gives us confidence to deploy AI agents in production."

@devops_mike
@ai_sarah avatar

"The Privacy Router is genius. Customer PII never leaves our infrastructure — only safe, anonymized queries hit the cloud models. Zero code changes from our existing agents."

@ai_sarah
@ciso_tom avatar

"Showed the OpenShell audit logs to our SOC 2 auditor. First time they've seen AI agent activity tracked at this level of detail. Passed with flying colors."

@ciso_tom
@mleng_jenny avatar

"Running Nemotron locally means zero token cost for internal queries. We cut our cloud AI spend by 70% while actually improving data privacy. Win-win."

@mleng_jenny
@platform_raj avatar

"Deployed NemoClaw on DGX Spark and it just works. Auto-detected the hardware, configured optimal model settings. One command to production-ready AI security."

@platform_raj
@secops_maria avatar

"Default-deny networking was the killer feature for us. Every outbound request our agents make is logged and requires approval. Exactly what our compliance team needed."

@secops_maria
@devops_mike avatar

"Ran 'nemoclaw onboard' and had a fully sandboxed agent environment in under 5 minutes. OpenShell isolation gives us confidence to deploy AI agents in production."

@devops_mike
@ai_sarah avatar

"The Privacy Router is genius. Customer PII never leaves our infrastructure — only safe, anonymized queries hit the cloud models. Zero code changes from our existing agents."

@ai_sarah
@ciso_tom avatar

"Showed the OpenShell audit logs to our SOC 2 auditor. First time they've seen AI agent activity tracked at this level of detail. Passed with flying colors."

@ciso_tom
@mleng_jenny avatar

"Running Nemotron locally means zero token cost for internal queries. We cut our cloud AI spend by 70% while actually improving data privacy. Win-win."

@mleng_jenny
@platform_raj avatar

"Deployed NemoClaw on DGX Spark and it just works. Auto-detected the hardware, configured optimal model settings. One command to production-ready AI security."

@platform_raj
@infra_alex avatar

"OpenShell's sandbox isolation caught a rogue agent trying to access /etc/passwd. In production. Without NemoClaw, that would have been a security incident."

@infra_alex
@devsec_lisa avatar

"Blueprints make repeatable secure deployments trivial. Define once, deploy everywhere. Every new agent gets the same security posture automatically."

@devsec_lisa
@security_emma avatar

"The network policy engine is exactly what we needed. Our agents can only reach pre-approved APIs. Everything else is blocked by default. Simple and effective."

@security_emma
@cloud_chris avatar

"Migrated 30 OpenClaw agents to NemoClaw. Zero code changes — just wrapped them in OpenShell sandboxes. Now we have full audit trails for every agent action."

@cloud_chris
@startup_nina avatar

"As a startup handling healthcare data, NemoClaw's Privacy Router was non-negotiable. Patient data stays on our GPUs, period. HIPAA compliance out of the box."

@startup_nina
@backend_kai avatar

"The OpenShell TUI is addictive. Watching agent actions in real-time, seeing network requests get approved or blocked — it's like Wireshark for AI agents."

@backend_kai
@infra_alex avatar

"OpenShell's sandbox isolation caught a rogue agent trying to access /etc/passwd. In production. Without NemoClaw, that would have been a security incident."

@infra_alex
@devsec_lisa avatar

"Blueprints make repeatable secure deployments trivial. Define once, deploy everywhere. Every new agent gets the same security posture automatically."

@devsec_lisa
@security_emma avatar

"The network policy engine is exactly what we needed. Our agents can only reach pre-approved APIs. Everything else is blocked by default. Simple and effective."

@security_emma
@cloud_chris avatar

"Migrated 30 OpenClaw agents to NemoClaw. Zero code changes — just wrapped them in OpenShell sandboxes. Now we have full audit trails for every agent action."

@cloud_chris
@startup_nina avatar

"As a startup handling healthcare data, NemoClaw's Privacy Router was non-negotiable. Patient data stays on our GPUs, period. HIPAA compliance out of the box."

@startup_nina
@backend_kai avatar

"The OpenShell TUI is addictive. Watching agent actions in real-time, seeing network requests get approved or blocked — it's like Wireshark for AI agents."

@backend_kai

Частые вопросы

Ответы на типичные вопросы о NemoClaw и принципах его работы.

Оставайтесь в курсе

Получайте уведомления о новых релизах NemoClaw, бюллетени безопасности и новости экосистемы. Никакого спама, отписка в любой момент.