NemoClaw Secures the Runtime. VettIQ Secures the Supply Chain.
NemoClaw sandboxes your AI agent with OpenShell. VettIQ scans every MCP server and skill before it enters the sandbox. Together: defense in depth.
What NemoClaw Does
NVIDIA's NemoClaw (launched at GTC March 2026) provides enterprise-grade runtime security for AI agents.
Sandboxed Execution
OpenShell containers isolate agent actions from the host system. File access, network calls, and process execution are all containerized.
Policy Enforcement
Define what your agent can and cannot do with declarative policy profiles. Restrict network access, limit API calls, require human approval for sensitive actions.
Privacy Router
Route sensitive data to local Nemotron models instead of cloud APIs. PII stays on-premise, non-sensitive queries go to faster cloud models.
What NemoClaw Doesn't Do
Runtime sandboxing protects the host. But it doesn't protect you from what's inside the sandbox.
Vet MCP Server Code
NemoClaw trusts whatever you install into the sandbox. It doesn't scan MCP server source code for prompt injection, credential theft, or malicious patterns.
Check Dependency Security
MCP servers pull in npm/pip dependencies. NemoClaw doesn't scan those dependency trees for known vulnerabilities or supply chain attacks.
Score Skill Trustworthiness
Is this MCP server maintained? Does it have known issues? NemoClaw doesn't evaluate reputation, activity, or security posture of third-party skills.
How VettIQ Fills the Gap
VettIQ scans every MCP server through 4 security engines before you install it.
Snyk
Prompt injection & code vulnerabilities
Cisco Kenna
Dependency risk scoring across the full tree
Semgrep
Dangerous code patterns (eval, exec, credential access)
VirusTotal
Malware signature matching against 70+ engines
Results Published to the MCP Trust Directory
1,000+ MCP servers scanned. Free to browse at vettiq.ai/mcp
Getting Started
No install required. Just check the trust score before you install any MCP server.
Go to vettiq.ai/mcp and search for the MCP server you want to install.
Check the trust score and scanner results. Green (0-30) means safe to install.
Install into your NemoClaw OpenShell environment with confidence.
For automated security rules, download a free Security Blueprint.
Coming soon: NemoClaw + OpenShell Security Blueprint — automated rules for secure agent configuration.