NemoClaw — NVIDIA Security Stack for AI Agents

NemoClaw

AI 代理,安全至上。NVIDIA 出品。

一行指令,部署完整的 AI 代理安全堆疊。OpenShell 核心沙盒 + Nemotron 本地推論 + Privacy Router——為 OpenClaw 代理提供企業級安全。

快速開始

ALPHA
# One-liner install for NemoClaw secure stack (Ubuntu 22.04+ recommended)
$ curl -fsSL https://www.nvidia.com/nemoclaw.sh | bash

Auto-installs Node.js, OpenShell runtime, and the NemoClaw CLI. Runs nemoclaw onboard after install.

核心能力

shield

OpenShell 安全沙盒

核心層級的 AI 代理隔離。策略驅動的沙盒環境,檔案系統、網路、程序三個維度精細管控。

route

Privacy Router

本地 Nemotron 和雲端模型之間智慧切換。敏感資料不出裝置,安全的請求才走雲端。

memory

Nemotron 本地推論

在本機執行 Nemotron 3 Super 120B MoE。零 Token 開銷、零資料外洩,NVIDIA GPU 上完全離線。

security

網路策略引擎

對外流量預設全部拒絕。每個外部連線都需要管理員核准,所有網路行為完整記錄在稽核日誌裡。

devices

跨平台部署

GeForce RTX、RTX PRO、DGX Station、DGX Spark 都能跑。從開發工作站到企業資料中心,全面涵蓋。

terminal

一鍵安裝

一行指令把 OpenShell、Nemotron、Privacy Router、NemoClaw CLI 全部就位。

眼見為實

NemoClaw 實戰

GTC 2026 發表會、架構展示、部署全流程,影片裡都有。

menu_book 看完整文件 arrow_forward

大家怎麼說

查看全部 arrow_forward
@secops_maria avatar

"Default-deny networking was the killer feature for us. Every outbound request our agents make is logged and requires approval. Exactly what our compliance team needed."

@secops_maria
@devops_mike avatar

"Ran 'nemoclaw onboard' and had a fully sandboxed agent environment in under 5 minutes. OpenShell isolation gives us confidence to deploy AI agents in production."

@devops_mike
@ai_sarah avatar

"The Privacy Router is genius. Customer PII never leaves our infrastructure — only safe, anonymized queries hit the cloud models. Zero code changes from our existing agents."

@ai_sarah
@ciso_tom avatar

"Showed the OpenShell audit logs to our SOC 2 auditor. First time they've seen AI agent activity tracked at this level of detail. Passed with flying colors."

@ciso_tom
@mleng_jenny avatar

"Running Nemotron locally means zero token cost for internal queries. We cut our cloud AI spend by 70% while actually improving data privacy. Win-win."

@mleng_jenny
@platform_raj avatar

"Deployed NemoClaw on DGX Spark and it just works. Auto-detected the hardware, configured optimal model settings. One command to production-ready AI security."

@platform_raj
@secops_maria avatar

"Default-deny networking was the killer feature for us. Every outbound request our agents make is logged and requires approval. Exactly what our compliance team needed."

@secops_maria
@devops_mike avatar

"Ran 'nemoclaw onboard' and had a fully sandboxed agent environment in under 5 minutes. OpenShell isolation gives us confidence to deploy AI agents in production."

@devops_mike
@ai_sarah avatar

"The Privacy Router is genius. Customer PII never leaves our infrastructure — only safe, anonymized queries hit the cloud models. Zero code changes from our existing agents."

@ai_sarah
@ciso_tom avatar

"Showed the OpenShell audit logs to our SOC 2 auditor. First time they've seen AI agent activity tracked at this level of detail. Passed with flying colors."

@ciso_tom
@mleng_jenny avatar

"Running Nemotron locally means zero token cost for internal queries. We cut our cloud AI spend by 70% while actually improving data privacy. Win-win."

@mleng_jenny
@platform_raj avatar

"Deployed NemoClaw on DGX Spark and it just works. Auto-detected the hardware, configured optimal model settings. One command to production-ready AI security."

@platform_raj
@infra_alex avatar

"OpenShell's sandbox isolation caught a rogue agent trying to access /etc/passwd. In production. Without NemoClaw, that would have been a security incident."

@infra_alex
@devsec_lisa avatar

"Blueprints make repeatable secure deployments trivial. Define once, deploy everywhere. Every new agent gets the same security posture automatically."

@devsec_lisa
@security_emma avatar

"The network policy engine is exactly what we needed. Our agents can only reach pre-approved APIs. Everything else is blocked by default. Simple and effective."

@security_emma
@cloud_chris avatar

"Migrated 30 OpenClaw agents to NemoClaw. Zero code changes — just wrapped them in OpenShell sandboxes. Now we have full audit trails for every agent action."

@cloud_chris
@startup_nina avatar

"As a startup handling healthcare data, NemoClaw's Privacy Router was non-negotiable. Patient data stays on our GPUs, period. HIPAA compliance out of the box."

@startup_nina
@backend_kai avatar

"The OpenShell TUI is addictive. Watching agent actions in real-time, seeing network requests get approved or blocked — it's like Wireshark for AI agents."

@backend_kai
@infra_alex avatar

"OpenShell's sandbox isolation caught a rogue agent trying to access /etc/passwd. In production. Without NemoClaw, that would have been a security incident."

@infra_alex
@devsec_lisa avatar

"Blueprints make repeatable secure deployments trivial. Define once, deploy everywhere. Every new agent gets the same security posture automatically."

@devsec_lisa
@security_emma avatar

"The network policy engine is exactly what we needed. Our agents can only reach pre-approved APIs. Everything else is blocked by default. Simple and effective."

@security_emma
@cloud_chris avatar

"Migrated 30 OpenClaw agents to NemoClaw. Zero code changes — just wrapped them in OpenShell sandboxes. Now we have full audit trails for every agent action."

@cloud_chris
@startup_nina avatar

"As a startup handling healthcare data, NemoClaw's Privacy Router was non-negotiable. Patient data stays on our GPUs, period. HIPAA compliance out of the box."

@startup_nina
@backend_kai avatar

"The OpenShell TUI is addictive. Watching agent actions in real-time, seeing network requests get approved or blocked — it's like Wireshark for AI agents."

@backend_kai

常見問題

關於 NemoClaw,你可能想問的。

掌握最新動態

接收 NemoClaw 新版本、安全公告和生態系消息。不發垃圾信,隨時退訂。