AI-native machine operations

Your AI can think.
Now let it operate.

Connect Codex, Claude or any MCP client to real machines through one secure control plane. Start locally for free, use NevaOps Cloud, or run the platform in your own infrastructure.

Human approval for privileged actions Windows available. Linux and macOS planned.
Fleet overview● Live
CONTROL PLANEGood evening, operator.⌘ K
Machines online12 / 12100%
Active sessions042 interactive
Pending approvals01Review
Machine fleetCapability-aware routing
workstation-01Windows 11Interactive
build-node-04Windows ServerHealthy
design-mac-02macOS runtimeRoadmap
Broker health42 ms▂▄▃▅▄▆▅▇▆█
BUILT ON◉ Model Context Protocol Least privilege Observable execution
01 / PLATFORM

One agent surface.
Three execution zones.

Network access, elevated operations and the user desktop stay separate, so every action runs in the correct security context.

SYSTEM BROKER

Privileged, not reckless.

Typed Windows operations run through a constrained LocalSystem broker. Dangerous actions require explicit approval.

View layer
DESKTOP AGENT

Operate the real UI.

Inspect windows, invoke controls and automate interactive Windows sessions through native accessibility APIs.

View layer
CONTROL PLANE

One policy. Every machine.

Register nodes, route durable tasks, connect external AI clients and keep signed audit outside each machine.

View layer
02 / ARCHITECTURE

Power is separated
by design.

The gateway never needs SYSTEM privileges. ACL-protected local channels route each request to the only component allowed to perform it.

  • Authenticated tunnel and token-scoped gateway
  • Typed operations, allowlists and validation
  • Streaming output, cancellation and timeouts
  • Explicit confirmation for privileged commands
REMOTE CONTROL PATH
AI CLIENTCodex / Agent
Authenticated MCP
LOOPBACKNevaOps GatewayUnprivileged
SESSION 0SYSTEM Broker
USER SESSIONDesktop Agent
03 / CONTROL PLANE

Machines and AI clients
meet in one workspace.

Nodes connect outbound, publish signed capability passports and lease durable tasks. External AI clients receive organization-scoped MCP access—never machine credentials.

NEVAOPS CLOUD

Managed for you.

Hosted admin, MCP endpoints, task history, approvals, audit retention and billing with a practical free tier.

AI CONNECTIONS

Codex, Claude, MCP.

Give each AI connection explicit machine, capability and risk scopes, then revoke or rotate access independently.

SELF-HOSTED

Your infrastructure.

Run the same control plane with your own PostgreSQL, TLS, storage, identity provider and retention policy.

APPROVAL
BOUND
04 / SECURITY

Capability before command.

Every machine declares what it can do. Every tool is constrained by policy. Every dangerous action is reviewable before execution.

Scoped machine identitySeparate credentials and audit trail for every node.
Fail-closed approvalsNo compatible confirmation UI means no privileged execution.
Execution evidenceStream lifecycle and output in real time.
05 / DEPLOYMENT & PLANS

Start free.
Choose where it runs.

Local operation remains useful without a subscription. Pay for managed coordination when you need it, or deploy the control plane yourself.

LOCAL FREE

No subscription

Run one Windows agent and one local AI connection. Local approvals, updates and signed audit stay available.

CLOUD FREE

Start small

Up to 10 machines, 2 AI connections, 5 member seats, 10 active tasks and 90-day retention.

CLOUD PRO

Subscription

Up to 100 machines, 25 AI connections, 50 members, 100 active tasks and one-year retention.

SELF-HOSTED

Your infrastructure

Deploy the same control plane without software resource quotas; you operate its database, identity, TLS, backups and capacity.

06 / ROADMAP

From one Windows node
to an operating fabric.

Windows is available first. Linux and macOS follow through the same signed passport and capability model.

01AVAILABLE

Windows runtime

Gateway, SYSTEM Broker, Desktop Agent, signed updates and MCP-native confirmation.

02AVAILABLE

Identity & audit

Machine passports, per-node credentials, fleet inventory, revoke/rotate and external anchors.

03IN BUILD

Cloud control plane

Admin, outbound node connections, hosted MCP endpoints and durable task routing.

04PLANNED

Linux & macOS

Shared protocol with OS-specific capability packs and native service integration.

05PLANNED

Cloud & self-hosted

Free and paid Cloud plans plus customer-operated Compose and Helm distributions.

Private technical preview

Give your AI
a safe way in.

Built for engineers and operators who need AI to do real work on real machines — without surrendering control.