
Clawhost (Dev)
LiveManaged SaaS hosting claiming 10K+ agents deployed
Security Score: 2.8/100 — Basic
Clawhost (Dev) is an early-stage Beta product with polished marketing but extremely thin security posture. No docs, no security page, no status page, no about page. Claims limited to Privacy Policy (AES-256-GCM, isolated containers, TLS) — none verifiable. GitHub has one empty repo ('ClawOS'). Terms warn about data loss/interruptions contradicting '99.9% uptime SLA.' No MFA, no named team, Czech base with Delaware law. clawhost.com is a separate 'coming soon' page. Users would entrust API keys and autonomous agents to a provider with essentially zero verifiable evidence.
10 risk categories scored 1-10 × evidence weight. Based on our methodology, grounded in OWASP Agentic Security, NIST CSF 2.0, and CIS Controls.
Privacy policy claims 'isolated container environments for each user' and FAQ states 'each instance runs in an isolated container with end-to-end encryption.' No documentation on isolation mechanism, no security page, no third-party audit. Claims unverifiable.
No mention of prompt injection protections, sandboxing, memory integrity, or human-in-the-loop. FAQ promotes '100+ integrations' and '24/7 autonomous' but zero info on how hijacking is mitigated.
Privacy policy claims 'AES-256-GCM encryption for stored secrets and API keys' and 'we never have access to your plaintext API keys after encryption.' Meaningful claim but unverifiable — no key management docs, no audit, no bug bounty. No credential leak detection or rotation.
No guardrails, rate limiting, spending caps, kill switches, behavioral monitoring, or approval workflows. Promotes '24/7 autonomous operation' and 'close your laptop and relax' with no rogue-agent prevention.
Terms explicitly warn Beta: 'unexpected downtime, data loss, or service interruptions' and 'we may reset or migrate data.' Privacy policy mentions 30-day deletion and 7-day log retention. '99.9% uptime SLA' claim contradicts Beta disclaimer. No backups, export, or DR. No status page.
Single plan $25/mo with 'no per-launch fees, no hidden costs.' Yearly saves $50. Terms: 'price changes communicated in advance.' No spending caps for API usage, refunds 'non-refundable except where required by law.'
Czech Republic per GitHub. No company registration, named team, or address. Only contact: legal@clawhost.dev. No incident response, breach notification, GDPR specifics, or audit logging. Delaware governing law despite Czech base — unusual.
No dependency management, tool vetting, CI/CD security, or SBOM docs. GitHub 'ClawOS' repo completely empty (0 code). Claims '100+ integrations' with no info on how they're secured or vetted.
Login shows email+password only, no MFA. No security headers docs, pen testing, bug bounty, or security.txt. Privacy claims 'TLS/SSL' and 'secure SSH' — baseline expectations. No CAPTCHA on signup.
No hallucination warnings, output verification, approval workflows, or undo capabilities. Homepage promotes full autonomy without caveats about AI reliability or human oversight.
Key Features
- ✓One-click setup (no terminal required)
- ✓24/7 autonomous operation
- ✓100+ integrations claimed
- ✓Persistent memory
- ✓Priority support
- ✓Live terminal demo
Integrations
Strengths
- +Claims 10K+ agents deployed
- +Simple single-price model
- +Non-technical setup (no terminal needed)
- +Live demo on homepage
Weaknesses
- −Confusing branding (multiple 'Clawhost' providers exist)
- −10K+ claim unverifiable
Verdict
Managed SaaS option with non-technical setup. The 10K+ agents claim needs verification.