Average Ratings 0 Ratings
Average Ratings 0 Ratings
Description
NVIDIA OpenShell serves as an open and secure runtime environment specifically designed for autonomous AI agents, regulating their execution, access rights, and the pathways for inference traffic. Instead of embedding security within the model or application, it maintains safety measures in the surrounding environment, meaning that nothing is allowed by default; permissions are assigned through established policies, and enforcement mechanisms operate outside the agent process to prevent any circumvention via prompts. Each autonomous agent operates within a confined sandbox, which restricts direct network connectivity, limits file access, and implements kernel-level monitoring of system calls to ensure rigorous oversight. Acting as the control plane, a gateway is responsible for user authentication, lifecycle management of sandboxes, and the provision of policies, settings, credentials, and inference configurations to the agents. Additionally, a supervisor operates externally to each sandbox, scrutinizing network requests according to policies at various levels—including binary, destination, method, and path—and only grants access to credentials when explicitly permitted, thus enhancing the overall security framework. This layered architecture ensures that the agents function effectively while maintaining robust security protocols throughout their operations.
Description
nono is a novel open-source sandbox that utilizes kernel enforcement to create a secure environment for AI coding agents and LLM tasks. In contrast to traditional policy-based guardrails that merely monitor and filter operations, nono leverages operating system security features—specifically Landlock on Linux and Seatbelt on macOS—to render unauthorized operations impossible at the syscall level.
With just a single command, you can encapsulate any AI agent, including Claude Code, OpenCode, OpenClaw, or any command-line interface process. The system automatically enforces a default-deny policy for filesystem access, restricts harmful commands (such as rm, dd, chmod, and sudo), isolates sensitive credentials and API keys, and extends all imposed restrictions to any child processes, ensuring there's no avenue for escape once limitations are set.
Built-in profiles allow for rapid deployment, and secrets can be injected from the system keystore in a secure manner, with automatic zeroization upon exit. Additionally, future enhancements such as audit logging, atomic rollbacks, and Sigstore-attested policy signing are planned, offering robust tracking and security features.
It operates under the Apache 2.0 license and is developed by the same creator behind Sigstore, further emphasizing its credibility and reliability in securing AI workloads.
API Access
Has API
No
API Access
Has API
No
Screenshots View All
No images available
Integrations
Claude Code
No
NVIDIA Open Agent Safety Platform
Yes
OpenAI Codex
No
OpenClaw
No
OpenCode
No
Integrations
Claude Code
Yes
NVIDIA Open Agent Safety Platform
No
OpenAI Codex
Yes
OpenClaw
Yes
OpenCode
Yes
Pricing Details
No price information available.
Free Trial
No
Free Version
No
Pricing Details
No price information available.
Free Trial
No
Free Version
Yes
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Deployment
Web-Based
No
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
Yes
Linux
Yes
Chromebook
No
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
No
Types of Training
Training Docs
Yes
Webinars
Yes
Live Training (Online)
No
In Person
No
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Vendor Details
Company Name
NVIDIA
Founded
1993
Country
United States
Website
www.nvidia.com/en-us/ai/openshell/
Vendor Details
Company Name
Always Further
Founded
2025
Country
United Kingdom
Website
alwaysfurther.ai/