Your AI can think.
Now let it operate.
Connect Codex, Claude or any MCP client to real machines through one secure control plane. Start locally for free, use NevaOps Cloud, or run the platform in your own infrastructure.
One agent surface.
Three execution zones.
Network access, elevated operations and the user desktop stay separate, so every action runs in the correct security context.
Privileged, not reckless.
Typed Windows operations run through a constrained LocalSystem broker. Dangerous actions require explicit approval.
View layerOperate the real UI.
Inspect windows, invoke controls and automate interactive Windows sessions through native accessibility APIs.
View layerOne policy. Every machine.
Register nodes, route durable tasks, connect external AI clients and keep signed audit outside each machine.
View layerPower is separated
by design.
The gateway never needs SYSTEM privileges. ACL-protected local channels route each request to the only component allowed to perform it.
- Authenticated tunnel and token-scoped gateway
- Typed operations, allowlists and validation
- Streaming output, cancellation and timeouts
- Explicit confirmation for privileged commands
Machines and AI clients
meet in one workspace.
Nodes connect outbound, publish signed capability passports and lease durable tasks. External AI clients receive organization-scoped MCP access—never machine credentials.
Managed for you.
Hosted admin, MCP endpoints, task history, approvals, audit retention and billing with a practical free tier.
Codex, Claude, MCP.
Give each AI connection explicit machine, capability and risk scopes, then revoke or rotate access independently.
Your infrastructure.
Run the same control plane with your own PostgreSQL, TLS, storage, identity provider and retention policy.
BOUND
Capability before command.
Every machine declares what it can do. Every tool is constrained by policy. Every dangerous action is reviewable before execution.
Start free.
Choose where it runs.
Local operation remains useful without a subscription. Pay for managed coordination when you need it, or deploy the control plane yourself.
No subscription
Run one Windows agent and one local AI connection. Local approvals, updates and signed audit stay available.
Start small
Up to 10 machines, 2 AI connections, 5 member seats, 10 active tasks and 90-day retention.
Subscription
Up to 100 machines, 25 AI connections, 50 members, 100 active tasks and one-year retention.
Your infrastructure
Deploy the same control plane without software resource quotas; you operate its database, identity, TLS, backups and capacity.
From one Windows node
to an operating fabric.
Windows is available first. Linux and macOS follow through the same signed passport and capability model.
Windows runtime
Gateway, SYSTEM Broker, Desktop Agent, signed updates and MCP-native confirmation.
Identity & audit
Machine passports, per-node credentials, fleet inventory, revoke/rotate and external anchors.
Cloud control plane
Admin, outbound node connections, hosted MCP endpoints and durable task routing.
Linux & macOS
Shared protocol with OS-specific capability packs and native service integration.
Cloud & self-hosted
Free and paid Cloud plans plus customer-operated Compose and Helm distributions.
Give your AI
a safe way in.
Built for engineers and operators who need AI to do real work on real machines — without surrendering control.