Quick Facts

  • NanoClaw has gained 20,000 GitHub stars and 100,000 downloads since launching last month
  • Partnership enables single-command deployment of AI agents in Docker’s MicroVM sandboxes
  • Docker research shows 95% of organizations now consider building agents a strategic priority

NanoCo and Docker announced an integration that allows NanoClaw AI agents to deploy inside Docker’s MicroVM-based Sandboxes with a single command. The partnership addresses enterprise security concerns that have blocked wider AI agent adoption.

NanoClaw has exploded in popularity since launching last month, surpassing 20,000 GitHub stars and 100,000 downloads. The open-source platform emerged as a response to security vulnerabilities in OpenClaw, which crossed 250,829 GitHub stars in March.

“Teams trust agents to take on increasingly complex and valuable work, but securing agents cannot be based on trust,” said Gavriel Cohen, CEO and co-founder of NanoCo. “It needs to be based on a provably secure hard boundary, scoped access to data and tools, and control over the actions agents are allowed to take.”

The integration runs agents in lightweight microVMs with private Docker daemons. If an agent attempts a container escape through a zero-day vulnerability, it remains contained within the isolated MicroVM that can be discarded instantly.

“Infrastructure needs to catch up to the intelligence of agents,” said Mark Cavage, President and Chief Operating Officer at Docker. “Powerful agents require isolation.”

Docker’s latest State of Agentic AI research surveyed more than 800 developers and decision-makers worldwide. The study found that building agents is now a strategic priority for 95% of respondents, with security surfacing as the top adoption blocker.

NanoClaw’s minimal architecture uses just 15 core source files, making it up to 100 times smaller than alternatives like OpenClaw, which has nearly 500,000 lines of code and 70+ dependencies. This streamlined approach enabled the Docker integration without architectural changes.

“We were able to put NanoClaw into Docker Sandboxes without making any architecture changes to NanoClaw,” Cohen explained. “It just works, because we had a vision of how agents should be deployed and isolated.”

Docker Sandboxes currently support macOS and Windows, with Linux support rolling out in coming weeks. Docker serves millions of developers and nearly 80,000 enterprise customers.

The partnership reflects a broader market shift toward bounded agents operating across teams and tasks, rather than centralized AI systems. Reports emerged this week about NemoClaw, a planned enterprise agent from Nvidia, though details remain unconfirmed ahead of next week’s GTC conference.

Read more: NanoClaw and Docker partner to make sandboxes the safest way for enterprises to deploy AI agents

This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.