Intelligence built for everything.
NOMOO builds AI and the infrastructure it runs on. ROOTS runs your team from one room: attendance, progress, on-call, leave and fair KPIs, scored by the AI of your choice inside your own walls. Sovereign Cloud is a turnkey private cloud that keeps data and control in your country. Doorcheck stands at the door of every inbox and stops the phishing that looks legitimate.
0%
Of hardware left for workloads; management uses 5%
4–10 weeks
From contract to a live sovereign cloud, training included
9–18 months
Typical return on investment
3 nodes
Enough for a highly available site; scale to thousands
Three solutions, one platform underneath.
ROOTS runs the team, Sovereign Cloud runs the infrastructure, and Doorcheck guards the inbox. All three can run entirely on your own hardware. Pick the one that matches where you are, and add the others when you need them.
Run the whole team from one room
Sovereign team operations: standups, on-call, leave and explainable KPIs, powered by an AI you host yourself. Nothing leaves your network.
Explore ROOTSRun your own cloud, in your own country
A turnkey private, hybrid, edge or air-gapped cloud on your own hardware. One licence covers compute, storage, networking, security, billing and support.
Explore Sovereign CloudPhishing stops at the door
AI email security that checks the relationship behind every message and recalls phishing, BEC and vendor fraud from every inbox in seconds.
Explore DoorcheckAI-driven team productivity, on-premise and air-gapped
Run the whole team from one room, and let everyone see the same truth.
ROOTS is a sovereign team-operations platform. Attendance, progress, on-call, leave and fair KPIs, scored by the AI of your choice and running entirely inside your walls. People post the way they already do, in chat; ROOTS does the rest, in your language, on your infrastructure.
+0%
productivity, no micromanagement
0
bytes of data leave your network
0
pre-trained bots, ready on day one
Standups became noise. Metrics became politics.
Managers hover to feel informed
Chasing updates in DMs burns trust and hours on both sides.
KPIs feel arbitrary and unfair
Nobody knows how the number was reached, so nobody believes it.
On-call and leave live in spreadsheets
Who is covering tonight? Who has balance left? Nobody is sure.
SaaS tools take your data offsite
Attendance, IPs and HR notes sitting on someone else's cloud.
Transparency does what micromanagement only pretends to. When the whole team sees the same scorecard, people manage themselves and the manager finally gets to lead.
From a one-line standup to a fair, explainable score
Sign-in, progress and blockers as plain text, in any language.
Parsing that copes with non-native phrasing extracts hours, tasks, location and blockers.
Presence, punctuality, on-call, pings, IP class and progress are collected.
Five weighted pillars become one weekly percentage that drills down to evidence.
Self-report scorecards, a fair KPI and one-click request-review for everyone.
A score people trust, because they can see how it was built
Output-led, not clock-led. Five pillars, configurable per team, every threshold audited. Never a black box.
Pillar weights
Default configuration
Team efficiency, this week
Example dashboard
On-call tonight: J. Smith, reachable on WhatsApp
Explainable KPI: J. Smith, 68%
Every point has a reason
- Shipped 3 tasks+4%
- 2 missed sign-offs−6%
- 3 missed presence checks−12%
- 7 days leaveexcused
Reward policy
rebuild first
coaching, scaling reward
paid at 110%
Twelve professional personas, ready on day one
Each bot knows its function's language and what good output looks like. Your internal knowledge bases and documents are ingested, so bots answer from day one. Behaviour and automations are settings, with manager and admin overrides, and you can author your own.
Technical
Engineers and ICs
DevOps / SRE
Uptime, incidents
Security
Threats, reviews
Sales
Leads and pipeline
Customer success
Accounts, renewals
Project manager
Coordination
HR
People ops
Finance
Close and reporting
Office
Day-to-day ops
Onboarding
Ramps new joiners
Standup coach
Sharper updates
General
Or build your own
One brain, every channel
ROOTS Chat, Slack and Microsoft Teams flow into the same pipeline. WhatsApp and SMS or voice close the loop when it matters most: on-call.
- Reach the person, not the room: a high-priority ticket pings the on-call primary directly.
- Escalation that never stalls: no acknowledgement in the SLA window and the chain walks itself, primary to backup to lead.
- Fair on-call credit: whoever actually covered earns it; a miss is attributed and coached, never guessed.
The whole workday, tracked fairly
- Support ticketing and SLA
- Tickets tracked to resolution with timers and escalation; resolutions feed the Responsibility pillar.
- Leave, sick and vacation
- Request in chat, rules-based auto-approval with guardrails, live balances, admin queue for the rest.
- Doctor's notes, OCR-read
- Extended sick leave prompts a note upload, read into a searchable record. Switchable off.
- Time zones and hybrid
- Per-person time zone, flexible and WFH models, Sunday or Monday weeks, six-day weeks.
- Home, office, on the go
- Consent-gated IP classification shows where work happens and flags a productive WFH pattern.
- Dev work, corroborated
- Standups cross-checked against real activity; claimed work is backed by evidence.
Your people data never leaves your perimeter
- Bring your own AI, air-gapped. Fifteen providers including on-host Ollama. Point it at a local model and standup text never touches a public API.
- Minimal token footprint. Budgets, memoisation and deterministic scoring keep inference cost near zero.
- Offline geo and IP intelligence. A bundled database classifies IPs on-host; nothing is sent out.
- GDPR-ready consent and audit. Versioned, e-signed policy consent and an immutable audit log of every action.
No telemetry. No external call required. Nothing egresses.
Live today, in production
ROOTS runs a real organisation's daily operations right now. One process, one container, SQLite or Postgres, and it becomes your platform: white-label branding, OpenAPI, role-based access with OTP and 2FA, and automations for any system with an API.
0
API routes
0
data models
0
scheduled jobs
0
bot experts
0
AI providers
0
fairness pillars
For governments, defence, telecoms, finance, healthcare, education and energy
A sovereign cloud you own, not one you rent.
NOMOO Sovereign Cloud is a complete cloud platform delivered on your own bare-metal hardware, inside your own data centre or point of presence. It gives your teams a self-service, hyperscaler-like experience while your data, your policies and your intellectual property stay under your jurisdiction.
One perpetual licence replaces the stack you would otherwise assemble from VMware, Nutanix, Hyper-V, OpenStack, Veeam, ServiceNow and SolarWinds: virtualisation, hyper-converged storage, software-defined networking, DNS, security, monitoring, billing, CRM, support and a marketplace.
Discuss a sovereign deploymentFive ways to deploy it
Distributed infrastructure with central control. The same platform runs in every model, so a workload built for one can move to another.
Air-gapped
Intranet-only, fully isolated zones. No connection to the outside world, ever.
Private
On-premise cloud for one organisation, with self-service for every department.
Hybrid
Dedicated cloud nodes securely joined to your home network, with global load balancing and automated DR between sites.
Edge
Start with three nodes at a site or POP and scale to thousands, all managed from one console.
Public, white-label
Sell cloud under your own brand with billing, resellers, eKYC and a marketplace built in.
What is in the box
Ninety-plus modules across nine layers, on a KVM hypervisor and a container-based microservices architecture. These are the ones customers ask about first.
- Hyper-converged infrastructure
- Compute, software-defined networking and software-defined storage (block, object and file) on any bare metal. High availability with no single point of failure.
- Zero-trust security
- Multi-tenant isolation, firewall and ACL automation, SSL and SSH key management, MFA and OTP, DDoS detection and mitigation, IAM, encryption at rest.
- Ransomware-immune backups
- Immutable S3 buckets, scheduled and on-demand snapshots, geo-redundant replication across three sites, tape and USB support, and backup to external clouds.
- Disaster recovery
- VM-level and storage-array replication, active-active or active-passive sites, live migration of VMs and storage, and failover plans you can simulate before you need them.
- Platform services
- Managed Kubernetes, container registry, managed databases, load balancers, block storage and S3 as a service, Terraform support and live API documentation.
- AI and GPU ready
- NVIDIA vGPU and AMD SR-IOV sharing across isolated tenants, PCI pass-through, confidential computing, GPU telemetry, and affinity rules for placing ML, rendering and VDI workloads.
- Compliance and auditing
- GDPR controls, a compliance engine, log aggregation, anomaly detection and reporting without a separate SIEM licence or network taps. Regional data-residency rules enforced from the admin portal.
- Business operations
- CRM, chargeback, pre-paid, post-paid and hybrid billing, e-wallet and payment aggregation, reseller hierarchy, tenant, admin, support and monitoring portals, iOS and Android apps, English and Arabic with ten more languages available.
How the platform is layered
Every layer ships in the same licence. Portals sit on top, the orchestration platform in the middle, your bare metal at the bottom, with security wrapped around all of it.
KVM, CPU and GPU
SDN, BGP, VPC
SDS: block, object, file
Spend on workloads, not overhead
Share of hardware consumed by platform management.
Live in four to ten weeks
A typical deployment, training included. Most sites go live around week six.
-
Weeks 1–2
Hardware and design
Three or more nodes, two switches, network and zoning plan.
-
Weeks 3–4
Platform install and migration
Cluster build, VMware or Hyper-V workloads moved across.
-
Weeks 5–6
Policies, billing and training
Data-residency rules, tenants, portals and team hand-over.
-
Week 6–10
Go live
Follow-the-sun support from day one; return on investment in 9–18 months.
Move in without starting over
Existing workloads come across; existing skills still apply.
Seamless migration
VMware
Easy migration
Hyper-V
Native KVM
Red Hat, Proxmox, OVH, OCI
Who runs it
Government, defence and regulated enterprise
Air-gapped and private deployments where data sovereignty is a legal requirement. Model-driven configuration, isolated zones, secure application publishing and Kubernetes for modern workloads, with compliance reporting the regulator can read.
Telecom operators and data centres
Turn connectivity and real estate into a regional, low-latency cloud business under your own brand in six to eight weeks. Resell 5G, cloud, AI, gaming and CDN services on the same compute, with resellers, eKYC onboarding and a marketplace for third-party licences.
ISPs and internet exchanges
Offer members compute where their data already resides. One-click vendor appliances instead of shipped hardware, automated peering and SD-WAN, and value-added services such as S3, managed databases, VDI and DRaaS as new revenue.
Backup, DR and VNF automation
Replace manual, single-server network functions with template-driven, multi-site orchestration. Automated backups, deduplication, storage tiering and ransomware protection as a service, restorable in minutes rather than days.
AI-native email security, sovereign by design
Phishing stops at the door.
The dangerous email looks like your CEO, your vendor or your bank. No malware, no attachment, just "can you send the wire today?" Doorcheck's AI checks the intent and the relationship behind every message, and recalls what doesn't belong from every inbox in seconds. No MX changes; it plugs into Microsoft 365, Google Workspace, Exchange on-premise, cPanel and IMAP.
-
PHISHquarantined
Action required: your mailbox will be suspended
Lookalike domain. "rn" is not "m".
-
BECquarantined
Re: wire instructions for Friday's closing
Executive impersonation plus an urgent payment ask.
-
VENDOR FRAUDpurged from 31 inboxes
Updated remittance details, invoice #8841
Real account, hijacked. Bank details never seen in three years of invoices.
-
PHISHpurged from 12 inboxes
MFA reset requested for your account
Credential lure. Same pattern in 12 mailboxes.
Caught before anyone clicks. Nothing is deleted; purge means recall to quarantine.
Your filters check the email. Doorcheck checks the relationship.
Traditional security asks whether an email is malicious. Doorcheck asks whether it makes sense, reasoning over the signals around the message. The sender can be real, the mailbox real, the conversation real, and the request can still be wrong.
Who is communicating?
Sender and recipient history, not just SPF and DKIM.
Is this relationship normal?
First contact, or a five-year vendor thread?
Has the conversation changed?
New tone, new urgency, new reply-to address.
Is the request unusual?
Payments, credentials and secrecy raise the score.
Does history back it up?
A new bank account that no invoice ever used.
Is it part of a campaign?
The same pattern landing in 40 other mailboxes.
Check. Catch. Clear.
One attack. One decision. Every copy gone.
Check
The AI learns your communication graph: people, vendors, relationships and what normal looks like for each.
Catch
Every message is scored for intent and context, so impersonation, BEC and account takeover are caught even when they look legitimate.
Clear
Confirmed threats are traced across the organisation and recalled from every inbox into quarantine, audit-logged and reversible with one click.
Find one. Purge all.
One detection maps the whole campaign. Every copy is recalled to quarantine in one click, seconds from verdict to clean inboxes.
7 copies of the same campaign recalled across 24 mailboxes
0%
of the AI can run on your own hardware
0
bytes of mail content leave a sovereign deployment
0
detection layers keep verdicts flowing, even offline
Watch first. Enforce when ready.
Monitor mode
Every message is scored and you see what would have been quarantined, while mail flows untouched. Judge the AI on real traffic before it acts.
Enforce mode
One toggle turns verdicts into action: threats are recalled automatically and campaigns purged fleet-wide, every action logged and reversible.
Mailbox reports
Every mailbox owner gets a digest of what was blocked and why, and releases a wrong call themselves in one click. Each release teaches the AI.
Built for the attacks that look legitimate
- Phishing. Polished, personalised, AI-written; caught by intent, not just links.
- Business email compromise. The invoice that costs you money is rarely malicious. It is checked anyway.
- Vendor fraud. A trusted sender is not trusted forever. The relationship is watched.
- Account takeover. Same mailbox, same signature, different behaviour.
- Impersonation. Lookalike domains and display-name games, flagged on arrival.
Built for whoever is defending
- Lean IT teams
- No SOC required. Verdicts, purges and training run themselves; you review a digest, not a queue.
- Security teams
- Campaign hunting, cross-tenant intelligence and audit-grade logs that slot into your SIEM.
- MSPs
- Multi-tenant console with per-client policies, every customer from one pane of glass.
- Regulated organisations
- Encrypted at rest, SSO, audit-grade logs, and sovereign self-hosted AI when data must never leave.
Protected in minutes: OAuth into Microsoft 365 or Google Workspace, no MX changes, no mail-flow surgery. Full details, integrations and the security and compliance posture are at doorcheck.ai.
From first call to production in four steps.
-
1
Connect
Bridge Slack or Teams, or use ROOTS Chat. The first standup scores itself the same day.
-
2
Build
Pick the bots your teams need, ingest your knowledge base and set pillar weights and thresholds per team.
-
3
Govern
Choose your AI provider, local or hosted, set budgets and consent policies. Every action lands in the audit log.
-
4
Scale
Run ROOTS on a single container in your own data centre, or inside NOMOO Sovereign Cloud when the contract requires it.
Questions we hear most.
Is my data used to train NOMOO models?
No. ROOTS runs on your own infrastructure with the AI provider you choose, including fully local models, and sends no telemetry. Nothing is used for training and nothing leaves your network.
Can I run ROOTS inside Sovereign Cloud?
Yes. ROOTS ships as a single container with SQLite or Postgres, and Sovereign Cloud is GPU-ready, so both the app and a local model can run entirely inside your boundary.
Which AI can ROOTS use?
Fifteen providers, including Anthropic, OpenAI, Gemini, Mistral, Groq, DeepSeek and Cohere, plus on-host Ollama for air-gapped deployments. Switch providers in settings; scoring stays deterministic.
How long does a Sovereign Cloud deployment take?
Four to ten weeks for a full offering including training, with an average around six. A highly available site needs as little as three servers and two switches, and grows from there.
Tell us what you're building.
A solutions engineer replies within one business day. If you already know you need Sovereign Cloud, say so and we'll bring the deployment team.