Security

How we protect your agents.

Seven security layers from hardware isolation to egress monitoring. Three are live today.

We scanned 988 skills from the OpenClaw registry. 12 contained malicious payloads. 70+ had credential theft patterns.

Seven layers of defense

Three layers are live today. Four more are in development — all will ship to every plan at no extra cost.

01

Agent isolation

Live

Each agent runs in its own Firecracker microVM with its own kernel and memory. Agents share nothing. Built on the same hypervisor technology behind AWS Lambda.

Stops container escapes, cross-agent data access, and shared-kernel exploits.

Separate Linux kernel per agent
Dedicated memory per microVM — nothing shared
Sub-125ms boot times
No shared filesystem between agents
02

Skill scanning

Live

Static analysis scans every skill before execution, catching injection patterns, exfiltration attempts, and known attack signatures.

Catches malicious code before it touches your infrastructure.

AST-level analysis of skill code
Detection of known malicious patterns
Sandboxed test execution
Skill reputation scoring
Browse the registry to see scan results
03

Audit trail

Live

Immutable log of every agent action. Full session replay. Searchable, exportable, retained per your plan.

No breach goes undetected. No action goes unrecorded.

Immutable append-only logs
Full replay of agent sessions
Searchable by agent, skill, or time
Exportable for compliance
04

Dependency checking

In development

Dependencies are scanned against CVE databases and analyzed for supply chain risks: typosquatting, malicious packages, vulnerable versions.

Blocks supply chain attacks and vulnerable packages before they reach your agents.

CVE database cross-referencing
Typosquatting detection
License compliance verification
Dependency pinning enforcement
05

MCP gateway

In development

MCP tool traffic routes through a centralized gateway. You set rate limits, content filters, and access policies.

You control what tools agents can reach and how often.

Request/response inspection
Rate limiting per agent and per skill
Content filtering for sensitive data
Protocol-level access control
06

Credential scoping

In development

We encrypt credentials at rest and log every access. Agents receive scoped tokens with minimum permissions that expire when the task ends.

Agents never touch your real keys.

Just-in-time credential provisioning
Automatic expiration after task completion
Per-task permission boundaries
No standing access to secrets
07

Egress monitoring

In development

We monitor and log outbound connections, filterable by domain allowlist. Anomalous traffic triggers alerts.

Flags unauthorized connections before data leaves your environment.

DNS-level traffic inspection
Configurable domain allowlists
Bandwidth anomaly detection
Real-time connection dashboards

Vett Enclave vs. typical OpenClaw hosts

Most OpenClaw hosts run agents in Docker containers sharing one kernel. Here's how Vett Enclave compares.

FeatureVett EnclaveTypical OpenClaw hosts
Isolation modelLiveDedicated microVM per agent — separate kernel, separate memoryDocker containers sharing one kernel
Escape impactLiveAgent can only access its own VM — nothing else existsContainer escape exposes every agent on the host
Credential handlingIn devScoped tokens with auto-expiration — agents never see real keysAPI keys in environment variables, shared across containers
Skill vettingLiveAST analysis + sandboxed execution before any skill runsNo pre-execution analysis
Dependency securityIn devCVE scanning + typosquatting detection on every dependencyNo dependency checking
Network controlIn devPer-agent egress monitoring with domain allowlistsShared network, no per-agent visibility
Audit capabilityLiveImmutable logs with full session replayBasic container logs, no session replay
MCP trafficIn devCentralized gateway with rate limiting and content filteringDirect, unmonitored MCP connections

Secure OpenClaw hosting, built from the ground up.

Founding members lock in their rate for life. 100 spots.

Claim your spot