Frontier-grade Claude models with agentic workflows, strong coding, and enterprise guardrails delivered via developer console, web app, and cloud partners.
NVIDIA NemoClaw

About NVIDIA NemoClaw
NVIDIA NemoClaw is an open-source security stack designed to secure AI agents running on NVIDIA GPUs. It combines OpenShell kernel sandboxes, a default-deny network policy engine, and a Privacy Router to classify and route data based on sensitivity. The stack keeps sensitive data on local GPUs by default, using Nemotron models for offline inference while allowing non-sensitive queries to be sent to cloud APIs. All agent activity is logged for compliance, with immutable records and operator approvals for outbound requests. The system is installed with a single command and supports deployments ranging from a single RTX workstation to DGX clusters, enabling both offline-only and mixed local/cloud setups. It is particularly valuable for regulated industries such as finance, healthcare, and public sector, where SOC 2 and HIPAA compliance are required. Security and MLOps teams adopting AI agents for customer support, sales operations, SecOps automation, and infrastructure management benefit most from its standardized security posture and auditable controls.
Key features
- OpenShell kernel sandboxes with filesystem, process, and syscall policies
- Default-deny networking with domain allowlists and real-time approvals
- Privacy Router for sensitivity-aware local/cloud model routing
- Nemotron local inference (Nemotron 3 Super 120B MoE or Nano 4B) on NVIDIA GPUs
- Immutable audit logs for compliance and operator approvals
- TUI for managing sandboxes, policies, and approvals
- Support for offline-only or mixed local/cloud deployments
- Configurable filesystem mounts and process limits in sandboxes
- Time-boxed approvals for outbound connections
- Policy files for defining egress allowlists and sensitivity rules
Use cases
- Securing AI agents in regulated industries like finance, healthcare, and public sector
- Standardizing security posture for AI agents across RTX workstations to DGX clusters
- Reducing token spend by running local Nemotron inference while selectively using cloud models
Pros
- Provides kernel-level sandbox isolation for AI agent execution via OpenShell
- Enables default-deny networking with operator approvals for all outbound requests
- Supports local inference with Nemotron models to keep sensitive data on-device
- Offers intelligent Privacy Router to classify and route data based on sensitivity
- Facilitates immutable audit trails for compliance and security monitoring
Cons
- Requires specific hardware such as NVIDIA GPUs for full functionality
- Installation on macOS currently relies on Colima or Docker Desktop with limited support
- Podman is not yet supported on macOS, restricting container runtime options
Frequently asked questions about NVIDIA NemoClaw
What is NVIDIA NemoClaw and what does it do?
NVIDIA NemoClaw is an open-source security stack designed to secure AI agents running on NVIDIA GPUs. It combines OpenShell kernel sandboxes, a default-deny network policy engine, and a Privacy Router to classify and route data based on sensitivity.
Who should use NemoClaw?
NemoClaw is particularly valuable for regulated industries such as finance, healthcare, and public sector, where compliance requirements like SOC 2 and HIPAA are critical. Security and MLOps teams adopting AI agents also benefit from its standardized security posture.
How does NemoClaw handle sensitive data?
NemoClaw keeps sensitive data on local GPUs by default using Nemotron models for offline inference. Only non-sensitive queries are routed to cloud APIs, ensuring data privacy and reducing token costs.
What are the deployment options for NemoClaw?
NemoClaw supports deployments ranging from a single RTX workstation to DGX clusters, enabling both offline-only and mixed local/cloud setups. It can be installed with a single command on Linux, Windows (via WSL2), and macOS (via Colima or Docker Desktop).
Does NemoClaw require internet access for local inference?
No, NemoClaw allows running Nemotron models locally for offline inference, meaning no internet access is required for sensitive or internal queries.
How does NemoClaw assist with compliance audits?
NemoClaw provides immutable audit trails of all agent activity, including network requests and operator approvals, which can be presented to auditors for compliance verification.
NVIDIA NemoClaw Website Engagement
Last Update: 9 days ago
Monthly Traffic
Traffic Sources
Traffic Share By Country
- United States58.2%
- India22.4%
- Japan10.7%
- Australia5%
- Taiwan2.2%