EN
Back to the archive

The archive · AI & Models · Strategic decision · 2026

NanoClaw's founders refuse a $20M buyout and raise a $12M seed for secure AI agents

Brothers build NanoClaw, a sandboxed open-source AI agent platform, in six weeks; they refuse a ~$20M buyout and raise a $12M seed from Valley Capital Partners.

NanoCo (NanoClaw)

The betThat isolating the whole AI agent in a sandbox makes autonomous assistants safe enough for enterprises, and open source plus managed rollout beats a $20M buyout.Scaling

What the business is

NanoCo sells NanoClaw, a security-focused, MIT-licensed open-source AI agent platform that runs assistants in sandboxed containers, plus managed enterprise deployment and support.

Starting capital$12M oversubscribed seed led by Valley Capital Partners (2026), with Docker, Vercel, Monday.com, Slow Ventures, Clutch Capital, Factorial Capital and angels including Hugging Face CEO Clem Delangue

How it started

Gavriel Cohen, a former Wix engineer, wrote NanoClaw's first line of code on January 29, 2026, after the OpenClaw-style agents running his and brother Lazer's AI marketing agency felt powerful but dangerously unguarded. He built a deliberately small, container-sandboxed alternative and released it under the MIT License on January 31.

What happened

Endorsements from AI researcher Andrej Karpathy and then Singapore's foreign minister, who called NanoClaw his 'second brain,' made it viral. The Cohens declined a six-figure offer and then a roughly $20 million acquisition, shut down their agency, and closed an oversubscribed $12 million seed led by Valley Capital Partners — under six weeks from the first line of code.

How it ended up

By May 2026 NanoClaw had about 250,000 downloads and roughly 30,000 GitHub stars, with executives at Amazon, Google, Meta, Gap, SentinelOne and Accenture using it. NanoCo, based in Tel Aviv with about ten employees, began selling per-agent, per-month managed deployments and 'forward-deployed engineer' implementation services to enterprises.

Background

NanoClaw began as a security fix. Gavriel Cohen, a former Wix engineer, wrote its first line of code on January 29, 2026, because the OpenClaw-style agents powering his and brother Lazer's AI marketing agency were powerful but dangerously unguarded. Instead of running the agent with access to every service and credential, he isolated the whole agent inside a container and released the result under the MIT License on January 31.

The project went viral within weeks: AI researcher Andrej Karpathy praised it, and Singapore's Foreign Minister Vivian Balakrishnan called it his 'second brain' in a post that snowballed. The brothers declined a six-figure offer to sell the project and then a roughly $20 million acquisition, shut down their agency, and closed an oversubscribed $12 million seed led by Valley Capital Partners — under six weeks from the first line of code, with Docker, Vercel, Monday.com and Slow Ventures among the backers.

NanoClaw's core logic is intentionally small — about 500 lines of TypeScript versus roughly 400,000 in OpenClaw — so a security team can audit it. Every agent runs in a MicroVM-based Docker sandbox, raw credentials never reach it, and sensitive actions such as sending email or deleting files trigger human approval cards in Slack, Teams or WhatsApp.

By May 2026 NanoClaw had roughly 250,000 downloads and 30,000 GitHub stars, and executives at companies like Amazon, Google, Meta, Gap, SentinelOne and Accenture were using it. NanoCo, a Tel Aviv company of about ten employees, began selling per-agent, per-month managed deployments and 'forward-deployed engineer' implementation services, positioning itself as the first institutionally funded company in the 'claw' space.

What has to be true

  • Sandboxing the entire agent, not just its tools, made NanoClaw easy for security leaders to reason about — the differentiator that unlocked enterprise adoption.
  • A deliberately tiny, auditable core converted OpenClaw skeptics who had been 'sitting on the sidelines' into users.
  • The open-source community did the discovery work, surfacing enterprise use cases that became NanoCo's paid managed-service business.
  • Refusing a $20M buyout kept control of a project whose community value the brothers believed would grow faster than any acquisition price.

What can be applied

Viral open-source demand isn't a business until someone sells the hard part: NanoCo monetized managed security, rollout and support — treating a $20M offer as a floor, not a ceiling.

Aftermath

As of September 2026 NanoCo continues to ship NanoClaw as an MIT-licensed open-source project while selling managed enterprise deployments, per-agent subscriptions and forward-deployed engineering services; the Docker sandbox partnership and Slack/Teams integrations anchor the roadmap, and the founders report more than 100 companies have reached out since launch.

Sources

spotted an error? The archive wants to know.

Your turn

You just read one. Describe what you are building, and see who is betting on the same thing.

Free account · 3 free questions · no card

Related cases