NemoClaw — NVIDIA Security Stack for AI Agents

NemoClaw

AI 代理,安全为先。NVIDIA 出品。

一条命令,部署完整的 AI 代理安全栈。OpenShell 内核沙箱 + Nemotron 本地推理 + Privacy Router——为 OpenClaw 代理提供企业级安全。

快速开始

ALPHA
# 一键安装 NemoClaw 安全栈(推荐 Ubuntu 22.04+)
$ curl -fsSL https://www.nvidia.com/nemoclaw.sh | bash

自动安装 Node.js、OpenShell 运行时和 NemoClaw CLI,安装完成后自动运行 nemoclaw onboard。

核心能力

shield

OpenShell 安全沙箱

内核级 AI 代理隔离。策略驱动的沙箱环境,文件系统、网络、进程三个维度精细管控。

route

Privacy Router

本地 Nemotron 和云端模型之间智能切换。敏感数据不出设备,安全的请求才走云端。

memory

Nemotron 本地推理

本地跑 Nemotron 3 Super 120B MoE。零 token 开销、零数据泄露,NVIDIA GPU 上完全离线。

security

网络策略引擎

出站流量默认全拒。每个外部连接都要运维批准,所有网络行为完整记录在审计日志里。

devices

跨平台部署

GeForce RTX、RTX PRO、DGX Station、DGX Spark 都能跑。从开发工位到企业数据中心,全覆盖。

terminal

一键安装

一条命令把 OpenShell、Nemotron、Privacy Router、NemoClaw CLI 全部就位。

眼见为实

NemoClaw 实战

GTC 2026 发布会、架构演示、部署全流程,视频里都有。

menu_book 看完整文档 arrow_forward

大家怎么说

查看全部 arrow_forward
@secops_maria avatar

"Default-deny networking was the killer feature for us. Every outbound request our agents make is logged and requires approval. Exactly what our compliance team needed."

@secops_maria
@devops_mike avatar

"Ran 'nemoclaw onboard' and had a fully sandboxed agent environment in under 5 minutes. OpenShell isolation gives us confidence to deploy AI agents in production."

@devops_mike
@ai_sarah avatar

"The Privacy Router is genius. Customer PII never leaves our infrastructure — only safe, anonymized queries hit the cloud models. Zero code changes from our existing agents."

@ai_sarah
@ciso_tom avatar

"Showed the OpenShell audit logs to our SOC 2 auditor. First time they've seen AI agent activity tracked at this level of detail. Passed with flying colors."

@ciso_tom
@mleng_jenny avatar

"Running Nemotron locally means zero token cost for internal queries. We cut our cloud AI spend by 70% while actually improving data privacy. Win-win."

@mleng_jenny
@platform_raj avatar

"Deployed NemoClaw on DGX Spark and it just works. Auto-detected the hardware, configured optimal model settings. One command to production-ready AI security."

@platform_raj
@secops_maria avatar

"Default-deny networking was the killer feature for us. Every outbound request our agents make is logged and requires approval. Exactly what our compliance team needed."

@secops_maria
@devops_mike avatar

"Ran 'nemoclaw onboard' and had a fully sandboxed agent environment in under 5 minutes. OpenShell isolation gives us confidence to deploy AI agents in production."

@devops_mike
@ai_sarah avatar

"The Privacy Router is genius. Customer PII never leaves our infrastructure — only safe, anonymized queries hit the cloud models. Zero code changes from our existing agents."

@ai_sarah
@ciso_tom avatar

"Showed the OpenShell audit logs to our SOC 2 auditor. First time they've seen AI agent activity tracked at this level of detail. Passed with flying colors."

@ciso_tom
@mleng_jenny avatar

"Running Nemotron locally means zero token cost for internal queries. We cut our cloud AI spend by 70% while actually improving data privacy. Win-win."

@mleng_jenny
@platform_raj avatar

"Deployed NemoClaw on DGX Spark and it just works. Auto-detected the hardware, configured optimal model settings. One command to production-ready AI security."

@platform_raj
@infra_alex avatar

"OpenShell's sandbox isolation caught a rogue agent trying to access /etc/passwd. In production. Without NemoClaw, that would have been a security incident."

@infra_alex
@devsec_lisa avatar

"Blueprints make repeatable secure deployments trivial. Define once, deploy everywhere. Every new agent gets the same security posture automatically."

@devsec_lisa
@security_emma avatar

"The network policy engine is exactly what we needed. Our agents can only reach pre-approved APIs. Everything else is blocked by default. Simple and effective."

@security_emma
@cloud_chris avatar

"Migrated 30 OpenClaw agents to NemoClaw. Zero code changes — just wrapped them in OpenShell sandboxes. Now we have full audit trails for every agent action."

@cloud_chris
@startup_nina avatar

"As a startup handling healthcare data, NemoClaw's Privacy Router was non-negotiable. Patient data stays on our GPUs, period. HIPAA compliance out of the box."

@startup_nina
@backend_kai avatar

"The OpenShell TUI is addictive. Watching agent actions in real-time, seeing network requests get approved or blocked — it's like Wireshark for AI agents."

@backend_kai
@infra_alex avatar

"OpenShell's sandbox isolation caught a rogue agent trying to access /etc/passwd. In production. Without NemoClaw, that would have been a security incident."

@infra_alex
@devsec_lisa avatar

"Blueprints make repeatable secure deployments trivial. Define once, deploy everywhere. Every new agent gets the same security posture automatically."

@devsec_lisa
@security_emma avatar

"The network policy engine is exactly what we needed. Our agents can only reach pre-approved APIs. Everything else is blocked by default. Simple and effective."

@security_emma
@cloud_chris avatar

"Migrated 30 OpenClaw agents to NemoClaw. Zero code changes — just wrapped them in OpenShell sandboxes. Now we have full audit trails for every agent action."

@cloud_chris
@startup_nina avatar

"As a startup handling healthcare data, NemoClaw's Privacy Router was non-negotiable. Patient data stays on our GPUs, period. HIPAA compliance out of the box."

@startup_nina
@backend_kai avatar

"The OpenShell TUI is addictive. Watching agent actions in real-time, seeing network requests get approved or blocked — it's like Wireshark for AI agents."

@backend_kai

常见问题

关于 NemoClaw,你可能想问的。

保持关注

获取 NemoClaw 新版本、安全公告和生态动态。不发垃圾邮件,随时退订。