
ClawNest
LiveManaged hosting with OpenRouter AI credits and WhatsApp/Telegram support
Security Score: 6.7/100 — Basic
ClawNest is a very early-stage startup (all content dated Feb 2026) offering managed OpenClaw hosting targeted at non-technical users. Security claims are marketing-level without technical depth. The privacy policy is a copy-pasted template from 'Draftr.' No dedicated security page, no documentation, no GitHub, no Terms of Service, no About page, no company entity identified. Pricing is transparent with included AI credits. Device pairing for Telegram is a meaningful access control feature. Cloudflare protection on the app. Overall weak security posture with broad claims but no substantiation.
10 risk categories scored 1-10 × evidence weight. Based on our methodology, grounded in OWASP Agentic Security, NIST CSF 2.0, and CIS Controls.
The homepage claims 'Only you can access your OpenClaw Assistant' and mentions device pairing. The comparison page claims 'Isolated containers' and 'Network isolation.' However, the privacy policy is a generic template (references 'Draftr' instead of ClawNest), mentions Google Analytics, and says data may be shared with 'trusted vendors.' No encryption at rest details, no data training opt-out, no log sanitization, no employee access controls.
The homepage states 'Your Assistant doesn't have access to your PC' and runs on a 'virtual computer...100% differenciated from your own hardware.' The comparison page claims 'No Docker socket exposure — Can't escape to host.' However, no documentation of prompt injection defenses, memory integrity protection, sandboxing specifics, or output sanitization.
The homepage prominently claims 'No API Key needed' — AI credits are included via OpenRouter. The comparison page claims 'Secrets management — API keys encrypted at rest.' However, no details on encryption mechanism, no mention of credential rotation, leak detection, or lifecycle management.
No information found about rate limiting agent actions, least-privilege principles, kill switches, behavioral monitoring, or resource consumption limits. No mention of tool gating or approval workflows.
The comparison page claims 'Backup & recovery: Automatic, duration based on your plan.' Blog FAQ mentions configuration export for migration. However, no details on backup frequency, tested restores, data export formats, or what happens if ClawNest shuts down. No SLA or uptime guarantees.
Pricing is clearly documented: Basic $49/mo, Pro $99/mo, Max $199/mo with specific RAM/storage allocations. AI credits included. 7-day free trial. 'Cancel anytime.' However, no hard spending caps, no usage monitoring dashboards, no price change notification policy.
Privacy policy mentions 'industry-standard security measures' including HTTPS/TLS and access controls but provides no specifics. No incident response process, no breach notification timeline, no audit logging, no GDPR details. Privacy policy is a copy-pasted template from 'Draftr.' No company entity identified.
No information about dependency scanning, MCP server vetting, build pipeline security, or SBOM. Mentions OpenRouter for AI but no details on vetting this dependency.
App uses Cloudflare protection. Comparison page claims 'Isolated containers,' 'No Docker socket exposure,' 'Network isolation,' 'Automatic security patches,' and 'Regular security audits' — but none substantiated with details. No MFA mentioned. No independent security testing evidence.
No information about hallucination mitigation, approval workflows, output verification, undo/rollback, or AI uncertainty transparency.
Key Features
- ✓Managed OpenClaw hosting
- ✓AI credits included (OpenRouter)
- ✓Dedicated support
- ✓7-day free trial on Basic plan
Integrations
Strengths
- +AI credits included via OpenRouter — no BYOK needed
- +WhatsApp + Telegram integration
- +Managed service with dedicated support
Weaknesses
- −Most expensive entry price ($49/mo)
- −Previous claims of SOC 2 / data residency not verifiable on site
- −Only 2 messaging integrations
- −Overkill for individual users
Verdict
Decent managed option with included AI credits, but expensive for what's offered. Previous compliance marketing claims were not verifiable.