Logo
Logo

OrionClawOrionClaw

The sovereign AI appliance.

OrionClaw™ is Labor Ex Machina delivered as a machine: a complete digital workforce — pre-wired, governed, and running on dedicated hardware under German jurisdiction.

No public cloud. No telemetry. No standing access. Every action logged.

I

The Machine.

A workforce, delivered as hardware.

You do not buy OrionClaw to build AI agents. You buy it to own them.

Inside the machine: dedicated NVIDIA compute. Open-weight models, version-pinned and documented. A pre-wired team of digital workers — crawlers, analysts, coordinators, reporters — each with a defined role and a defined set of permissions. And the harness: the control layer that governs every action they take.

No assembly. No integration project. You define the mission. The machine executes.

Think of it the way you think of staff.

  • It has a job description — every worker has a defined role and defined duties.
  • It has access rights — workers touch only what their role requires.
  • It is supervised — no external action without human approval.
  • It keeps a record — every action logged, exportable to your SIEM. /* CLAIM-VERIFY-1: Audit log exportable/streams to your SIEM — which formats/integrations exist today? */
  • And it can be dismissed — one control stops the entire workforce, instantly.

Onboard it like an employee. Audit it like a machine.

II

The Harness.

The harness. The part your security team audits.

The Harness — Engineering Plate No. 1 · Diagram in production

Placeholder for the engineering plate diagram of the OrionClaw harness.

Every worker operates inside the harness. A defined permission envelope — workers touch only what their role requires. Human checkpoints — no external action without human approval. A complete audit log — every action recorded, exportable to your SIEM. A kill switch — one control stops the entire workforce instantly.

This is not a policy document. It is the architecture.

III

Access.

Zero standing access.

OrionClaw never initiates a connection. All access is inbound — granted by you, time-boxed, and logged end to end.

Service sessions authenticate under your security policy: hardware keys where your organization issues them, your identity provider, your jump hosts. The appliance is designed for zero-trust environments — it assumes nothing and verifies every session.

Updates are signed packages, applied only in windows you approve. Nothing changes between them.

For environments that forbid remote access entirely, there is the air-gapped option: no external connection, updates on signed physical media, service on-site by appointment.

IV

Deployment.

Three deployment models. One jurisdiction.

Hosted Tenancy

What: Your workers on our own machines in a Frankfurt datacenter

For: Organizations that want sovereignty without hardware

Tenancy: Strictly limited, never oversubscribed, hard isolation between clients

Dedicated Appliance

What: Your own machine — our Frankfurt rack or your server room

For: Enterprises standardizing on sovereign AI

Tenancy: Single tenant by construction

Air-Gapped

What: Your building. No external connection — not even to us

For: Regulated and defense-adjacent environments

Tenancy: Single tenant, physically disconnected

All three: German jurisdiction, German contract law, and no public cloud at any point in the data path.

V

Verification.

Don't trust this page. Test it.

ClaimHow your team verifies it
No telemetry, no phone-homeMirror the port. Watch it.
No standing vendor accessNo vendor account exists until you create one
Administration under your policyHardware keys and identity providers you issue and control
Every action loggedAudit log streams to your SIEM
Nothing changes without approvalSigned update packages, applied in your windows
Known software supply chainFull SBOM, version-pinned, open-weight models

Controls map to ISO/IEC 27001 Annex A. Engineered to support GDPR, BSI C5, and EU AI Act obligations.

VI

Proof.

Proven in production. Not in a demo.

OrionClaw's first workload is BrandSafe.cloud — the digital assembly line that automated global brand compliance at BMW Group.

"By designing web crawlers to analyze over 4,000 websites globally and integrating NLP and AI agents for content consistency checks, Jonathan [Agile Systems] achieved 99% accuracy and 97% efficiency gains, automating tasks that previously required a seven-person technical team a full week to complete."

— Mirja Haedke, Digital Marketing, BMW Group

4,000+

websites under review

99%

accuracy

One day

the work that took a seven-person team a full week

Your people supervise. The workers execute.

See the machine. Read the harness.

Book a thirty-minute technical briefing. We walk your team through the architecture, the access model, and the audit trail — and leave you the Architecture & Security Overview to take to your security office.

CLAIM-VERIFY-1: Audit log exportable/streams to your SIEM — which formats/integrations exist today?CLAIM-VERIFY-2: Full SBOM — is SBOM generation actually in the build pipeline?CLAIM-VERIFY-3: Updates are signed packages — are update packages genuinely signed?CLAIM-VERIFY-4: Kill switch — one control stops the entire workforce — does this exist as a real control or is it roadmap?CLAIM-VERIFY-5: Hard isolation between clients (Hosted Tenancy) — confirm isolation architecture before strengthening this language.CLAIM-VERIFY-6: BMW quote reuse on this page — confirm permission scope covers orionclaw.ai.