NOMOO

Intelligence built for everything.

NOMOO builds AI and the infrastructure it runs on. ROOTS runs your team from one room: attendance, progress, on-call, leave and fair KPIs, scored by the AI of your choice inside your own walls. Sovereign Cloud is a turnkey private cloud that keeps data and control in your country. Doorcheck stands at the door of every inbox and stops the phishing that looks legitimate.

0%

Of hardware left for workloads; management uses 5%

4–10 weeks

From contract to a live sovereign cloud, training included

9–18 months

Typical return on investment

3 nodes

Enough for a highly available site; scale to thousands

NOMOO
ROOTS

AI-driven team productivity, on-premise and air-gapped

Run the whole team from one room, and let everyone see the same truth.

ROOTS is a sovereign team-operations platform. Attendance, progress, on-call, leave and fair KPIs, scored by the AI of your choice and running entirely inside your walls. People post the way they already do, in chat; ROOTS does the rest, in your language, on your infrastructure.

+0%

productivity, no micromanagement

0

bytes of data leave your network

0

pre-trained bots, ready on day one

Book a live demo

Standups became noise. Metrics became politics.

Managers hover to feel informed

Chasing updates in DMs burns trust and hours on both sides.

KPIs feel arbitrary and unfair

Nobody knows how the number was reached, so nobody believes it.

On-call and leave live in spreadsheets

Who is covering tonight? Who has balance left? Nobody is sure.

SaaS tools take your data offsite

Attendance, IPs and HR notes sitting on someone else's cloud.

Transparency does what micromanagement only pretends to. When the whole team sees the same scorecard, people manage themselves and the manager finally gets to lead.

From a one-line standup to a fair, explainable score

1Post in chat 2AI parses intent 3Signals gathered 4Efficiency scored 5Everyone sees it

Sign-in, progress and blockers as plain text, in any language.

Parsing that copes with non-native phrasing extracts hours, tasks, location and blockers.

Presence, punctuality, on-call, pings, IP class and progress are collected.

Five weighted pillars become one weekly percentage that drills down to evidence.

Self-report scorecards, a fair KPI and one-click request-review for everyone.

A score people trust, because they can see how it was built

Output-led, not clock-led. Five pillars, configurable per team, every threshold audited. Never a black box.

Pillar weights

Default configuration

40%
Progress
25%
Presence
15%
Reliability
10%
Integrity
10%
Responsibility

Team efficiency, this week

Example dashboard

0%
Progress78
Presence88
Reliability64

On-call tonight: J. Smith, reachable on WhatsApp

Explainable KPI: J. Smith, 68%

Every point has a reason

  • Shipped 3 tasks+4%
  • 2 missed sign-offs−6%
  • 3 missed presence checks−12%
  • 7 days leaveexcused

Reward policy

<25%
rebuild first
25–99%
coaching, scaling reward
100%
paid at 110%

Twelve professional personas, ready on day one

Each bot knows its function's language and what good output looks like. Your internal knowledge bases and documents are ingested, so bots answer from day one. Behaviour and automations are settings, with manager and admin overrides, and you can author your own.

TE

Technical

Engineers and ICs

DO

DevOps / SRE

Uptime, incidents

SE

Security

Threats, reviews

SA

Sales

Leads and pipeline

CS

Customer success

Accounts, renewals

PM

Project manager

Coordination

HR

HR

People ops

FI

Finance

Close and reporting

OF

Office

Day-to-day ops

ON

Onboarding

Ramps new joiners

SC

Standup coach

Sharper updates

GE

General

Or build your own

One brain, every channel

ROOTS Chat, Slack and Microsoft Teams flow into the same pipeline. WhatsApp and SMS or voice close the loop when it matters most: on-call.

ROOTS Chat, native, end-to-end encrypted Slack Microsoft Teams WhatsApp SMS and voice Email iOS and Android push
  • Reach the person, not the room: a high-priority ticket pings the on-call primary directly.
  • Escalation that never stalls: no acknowledgement in the SLA window and the chain walks itself, primary to backup to lead.
  • Fair on-call credit: whoever actually covered earns it; a miss is attributed and coached, never guessed.

The whole workday, tracked fairly

Support ticketing and SLA
Tickets tracked to resolution with timers and escalation; resolutions feed the Responsibility pillar.
Leave, sick and vacation
Request in chat, rules-based auto-approval with guardrails, live balances, admin queue for the rest.
Doctor's notes, OCR-read
Extended sick leave prompts a note upload, read into a searchable record. Switchable off.
Time zones and hybrid
Per-person time zone, flexible and WFH models, Sunday or Monday weeks, six-day weeks.
Home, office, on the go
Consent-gated IP classification shows where work happens and flags a productive WFH pattern.
Dev work, corroborated
Standups cross-checked against real activity; claimed work is backed by evidence.

Your people data never leaves your perimeter

  • Bring your own AI, air-gapped. Fifteen providers including on-host Ollama. Point it at a local model and standup text never touches a public API.
  • Minimal token footprint. Budgets, memoisation and deterministic scoring keep inference cost near zero.
  • Offline geo and IP intelligence. A bundled database classifies IPs on-host; nothing is sent out.
  • GDPR-ready consent and audit. Versioned, e-signed policy consent and an immutable audit log of every action.
AnthropicOpenAIGeminiMistralOllamaGroqDeepSeekCohereHugging Face+6 more

No telemetry. No external call required. Nothing egresses.

Live today, in production

ROOTS runs a real organisation's daily operations right now. One process, one container, SQLite or Postgres, and it becomes your platform: white-label branding, OpenAPI, role-based access with OTP and 2FA, and automations for any system with an API.

0

API routes

0

data models

0

scheduled jobs

0

bot experts

0

AI providers

0

fairness pillars

For governments, defence, telecoms, finance, healthcare, education and energy

A sovereign cloud you own, not one you rent.

NOMOO Sovereign Cloud is a complete cloud platform delivered on your own bare-metal hardware, inside your own data centre or point of presence. It gives your teams a self-service, hyperscaler-like experience while your data, your policies and your intellectual property stay under your jurisdiction.

One perpetual licence replaces the stack you would otherwise assemble from VMware, Nutanix, Hyper-V, OpenStack, Veeam, ServiceNow and SolarWinds: virtualisation, hyper-converged storage, software-defined networking, DNS, security, monitoring, billing, CRM, support and a marketplace.

Discuss a sovereign deployment
NOMOO
SOVEREIGN CLOUD

Five ways to deploy it

Distributed infrastructure with central control. The same platform runs in every model, so a workload built for one can move to another.

Central control plane Air-gapped Private Hybrid Edge Public

Air-gapped

Intranet-only, fully isolated zones. No connection to the outside world, ever.

Private

On-premise cloud for one organisation, with self-service for every department.

Hybrid

Dedicated cloud nodes securely joined to your home network, with global load balancing and automated DR between sites.

Edge

Start with three nodes at a site or POP and scale to thousands, all managed from one console.

Public, white-label

Sell cloud under your own brand with billing, resellers, eKYC and a marketplace built in.

What is in the box

Ninety-plus modules across nine layers, on a KVM hypervisor and a container-based microservices architecture. These are the ones customers ask about first.

Hyper-converged infrastructure
Compute, software-defined networking and software-defined storage (block, object and file) on any bare metal. High availability with no single point of failure.
Zero-trust security
Multi-tenant isolation, firewall and ACL automation, SSL and SSH key management, MFA and OTP, DDoS detection and mitigation, IAM, encryption at rest.
Ransomware-immune backups
Immutable S3 buckets, scheduled and on-demand snapshots, geo-redundant replication across three sites, tape and USB support, and backup to external clouds.
Disaster recovery
VM-level and storage-array replication, active-active or active-passive sites, live migration of VMs and storage, and failover plans you can simulate before you need them.
Platform services
Managed Kubernetes, container registry, managed databases, load balancers, block storage and S3 as a service, Terraform support and live API documentation.
AI and GPU ready
NVIDIA vGPU and AMD SR-IOV sharing across isolated tenants, PCI pass-through, confidential computing, GPU telemetry, and affinity rules for placing ML, rendering and VDI workloads.
Compliance and auditing
GDPR controls, a compliance engine, log aggregation, anomaly detection and reporting without a separate SIEM licence or network taps. Regional data-residency rules enforced from the admin portal.
Business operations
CRM, chargeback, pre-paid, post-paid and hybrid billing, e-wallet and payment aggregation, reseller hierarchy, tenant, admin, support and monitoring portals, iOS and Android apps, English and Arabic with ten more languages available.

How the platform is layered

Every layer ships in the same licence. Portals sit on top, the orchestration platform in the middle, your bare metal at the bottom, with security wrapped around all of it.

Portals and intelligence Who uses it
Admin dashboardTenant self-serviceSupport portalReseller portaliOS and Android appsAnalytics and reporting
Operations How it runs the business
CRMBilling and eKYCMarketplaceMonitoringNotificationsAutoscalingDNS and IP automationLanguage engine
Cloud orchestration platform The engine
Multi-tenancyService catalogueAI engineAPI gatewayKubernetesDR and replicationCLI and TerraformConfig management
Hypervisor and hardware Your bare metal
Compute
KVM, CPU and GPU
Network
SDN, BGP, VPC
Storage
SDS: block, object, file
Security across every layer Zero-trust, firewall and ACL, SDN isolation, encryption, IAM, MFA, GDPR, auditing

Spend on workloads, not overhead

Share of hardware consumed by platform management.

NOMOO Sovereign Cloud0%
Alternative stacks00%
Platform management Usable compute

Live in four to ten weeks

A typical deployment, training included. Most sites go live around week six.

  1. Weeks 1–2

    Hardware and design

    Three or more nodes, two switches, network and zoning plan.

  2. Weeks 3–4

    Platform install and migration

    Cluster build, VMware or Hyper-V workloads moved across.

  3. Weeks 5–6

    Policies, billing and training

    Data-residency rules, tenants, portals and team hand-over.

  4. Week 6–10

    Go live

    Follow-the-sun support from day one; return on investment in 9–18 months.

Move in without starting over

Existing workloads come across; existing skills still apply.

Seamless migration

VMware

Easy migration

Hyper-V

Native KVM

Red Hat, Proxmox, OVH, OCI

Who runs it

Government, defence and regulated enterprise

Air-gapped and private deployments where data sovereignty is a legal requirement. Model-driven configuration, isolated zones, secure application publishing and Kubernetes for modern workloads, with compliance reporting the regulator can read.

Telecom operators and data centres

Turn connectivity and real estate into a regional, low-latency cloud business under your own brand in six to eight weeks. Resell 5G, cloud, AI, gaming and CDN services on the same compute, with resellers, eKYC onboarding and a marketplace for third-party licences.

ISPs and internet exchanges

Offer members compute where their data already resides. One-click vendor appliances instead of shipped hardware, automated peering and SD-WAN, and value-added services such as S3, managed databases, VDI and DRaaS as new revenue.

Backup, DR and VNF automation

Replace manual, single-server network functions with template-driven, multi-site orchestration. Automated backups, deduplication, storage tiering and ransomware protection as a service, restorable in minutes rather than days.

NOMOO DOORCHECK

AI-native email security, sovereign by design

Phishing stops at the door.

The dangerous email looks like your CEO, your vendor or your bank. No malware, no attachment, just "can you send the wire today?" Doorcheck's AI checks the intent and the relationship behind every message, and recalls what doesn't belong from every inbox in seconds. No MX changes; it plugs into Microsoft 365, Google Workspace, Exchange on-premise, cPanel and IMAP.

Live quarantine feedExample
  • PHISHquarantined

    Action required: your mailbox will be suspended

    Lookalike domain. "rn" is not "m".

  • BECquarantined

    Re: wire instructions for Friday's closing

    Executive impersonation plus an urgent payment ask.

  • VENDOR FRAUDpurged from 31 inboxes

    Updated remittance details, invoice #8841

    Real account, hijacked. Bank details never seen in three years of invoices.

  • PHISHpurged from 12 inboxes

    MFA reset requested for your account

    Credential lure. Same pattern in 12 mailboxes.

Caught before anyone clicks. Nothing is deleted; purge means recall to quarantine.

Your filters check the email. Doorcheck checks the relationship.

Traditional security asks whether an email is malicious. Doorcheck asks whether it makes sense, reasoning over the signals around the message. The sender can be real, the mailbox real, the conversation real, and the request can still be wrong.

Who is communicating?

Sender and recipient history, not just SPF and DKIM.

Is this relationship normal?

First contact, or a five-year vendor thread?

Has the conversation changed?

New tone, new urgency, new reply-to address.

Is the request unusual?

Payments, credentials and secrecy raise the score.

Does history back it up?

A new bank account that no invoice ever used.

Is it part of a campaign?

The same pattern landing in 40 other mailboxes.

Check. Catch. Clear.

One attack. One decision. Every copy gone.

1
2
3

Check

The AI learns your communication graph: people, vendors, relationships and what normal looks like for each.

Catch

Every message is scored for intent and context, so impersonation, BEC and account takeover are caught even when they look legitimate.

Clear

Confirmed threats are traced across the organisation and recalled from every inbox into quarantine, audit-logged and reversible with one click.

Find one. Purge all.

One detection maps the whole campaign. Every copy is recalled to quarantine in one click, seconds from verdict to clean inboxes.

7 copies of the same campaign recalled across 24 mailboxes

0%

of the AI can run on your own hardware

0

bytes of mail content leave a sovereign deployment

0

detection layers keep verdicts flowing, even offline

Watch first. Enforce when ready.

Monitor mode

Every message is scored and you see what would have been quarantined, while mail flows untouched. Judge the AI on real traffic before it acts.

Enforce mode

One toggle turns verdicts into action: threats are recalled automatically and campaigns purged fleet-wide, every action logged and reversible.

Mailbox reports

Every mailbox owner gets a digest of what was blocked and why, and releases a wrong call themselves in one click. Each release teaches the AI.

Built for the attacks that look legitimate

  • Phishing. Polished, personalised, AI-written; caught by intent, not just links.
  • Business email compromise. The invoice that costs you money is rarely malicious. It is checked anyway.
  • Vendor fraud. A trusted sender is not trusted forever. The relationship is watched.
  • Account takeover. Same mailbox, same signature, different behaviour.
  • Impersonation. Lookalike domains and display-name games, flagged on arrival.
Microsoft 365Google WorkspaceExchange on-premcPanelIMAPSlackSplunkAny SIEM / SOARWebhooks and REST API

Built for whoever is defending

Lean IT teams
No SOC required. Verdicts, purges and training run themselves; you review a digest, not a queue.
Security teams
Campaign hunting, cross-tenant intelligence and audit-grade logs that slot into your SIEM.
MSPs
Multi-tenant console with per-client policies, every customer from one pane of glass.
Regulated organisations
Encrypted at rest, SSO, audit-grade logs, and sovereign self-hosted AI when data must never leave.

Protected in minutes: OAuth into Microsoft 365 or Google Workspace, no MX changes, no mail-flow surgery. Full details, integrations and the security and compliance posture are at doorcheck.ai.

From first call to production in four steps.

  1. 1

    Connect

    Bridge Slack or Teams, or use ROOTS Chat. The first standup scores itself the same day.

  2. 2

    Build

    Pick the bots your teams need, ingest your knowledge base and set pillar weights and thresholds per team.

  3. 3

    Govern

    Choose your AI provider, local or hosted, set budgets and consent policies. Every action lands in the audit log.

  4. 4

    Scale

    Run ROOTS on a single container in your own data centre, or inside NOMOO Sovereign Cloud when the contract requires it.

Questions we hear most.

Is my data used to train NOMOO models?

No. ROOTS runs on your own infrastructure with the AI provider you choose, including fully local models, and sends no telemetry. Nothing is used for training and nothing leaves your network.

Can I run ROOTS inside Sovereign Cloud?

Yes. ROOTS ships as a single container with SQLite or Postgres, and Sovereign Cloud is GPU-ready, so both the app and a local model can run entirely inside your boundary.

Which AI can ROOTS use?

Fifteen providers, including Anthropic, OpenAI, Gemini, Mistral, Groq, DeepSeek and Cohere, plus on-host Ollama for air-gapped deployments. Switch providers in settings; scoring stays deterministic.

How long does a Sovereign Cloud deployment take?

Four to ten weeks for a full offering including training, with an average around six. A highly available site needs as little as three servers and two switches, and grows from there.

Tell us what you're building.

A solutions engineer replies within one business day. If you already know you need Sovereign Cloud, say so and we'll bring the deployment team.