ClawRun homepage screenshot
#14

ClawRun

Live

One-click OpenClaw deployment on dedicated VPS infrastructure

From
$10/mo
Security
Basic 4.7/100
Price Range
$10/mo$350/mo
Free Tier
No
Integrations
0 platforms

Security Score: 4.7/100 — Basic

ClawRun is a very young VPS provisioning service (launched Feb 8, 2026) for OpenClaw. Likely same operator as ClawHost Cloud (bfzli) based on ToS email mismatch. Dedicated-VPS model gives structural tenant isolation. Transparent fixed pricing is a genuine positive. However, zero documented security practices, no security page, no docs, no public GitHub, no MFA, no backups yet, no incident response. Privacy/ToS appear to be copy-pasted templates from ClawHost Cloud. Early-stage infrastructure tool with minimal security maturity.

10 risk categories scored 1-10 × evidence weight. Based on our methodology, grounded in OWASP Agentic Security, NIST CSF 2.0, and CIS Controls.

Can anyone else see my data?3/10
C

Dedicated VPS per user provides inherent single-tenant isolation. Claims '100% Owned Data — Your own server, your data. No shared infrastructure, no logs, no third parties.' No documentation on what data ClawRun retains on its management platform, no encryption-at-rest details, generic boilerplate privacy policy.

Can someone take over my agent?1/10
U

No mention of prompt injection defenses, sandboxing, human-in-the-loop, memory integrity, or container escape prevention. Service provides raw VPS with OpenClaw — all protections depend on user configuration. Zero guidance on securing agents.

Are my keys and passwords safe?1/10
U

No info on credential handling. Users get root SSH to own VPS, shifting responsibility to them. No credential management tools, vault, leak detection, or guidance. Management platform collects email/payment with no security details.

Can my agent do things I didn't authorize?1/10
U

No rate limiting, spending caps, kill switches, monitoring, or guardrails. Explicitly markets 'Full access to OpenClaw and the VPS, with no limits on what you can achieve' — unlimited capability, zero safety.

Can I lose my data or get locked out?1/10
C

Backups explicitly listed as upcoming ('Server snapshots for backup and restore'). Not available yet. No data export documented. ToS: 'modify, suspend, or discontinue any part of the Service at any time with or without notice.' Platform 9 days old. No SLA.

Will I get unexpected bills?4/10
D

Transparent pricing: 20+ configs from $10/mo to $350/mo with clear specs. Fixed monthly billing, cancel anytime. 'Pricing based on what you need. No forced high bills.' No usage-based surprises. However, no spending caps for API usage on deployed OpenClaw.

Who's responsible when something goes wrong?1/10
U

No audit logging, incident response, breach notification, or security monitoring. ToS contact email mismatch (legal@clawhost.cloud vs legal@clawrun.dev) — documents appear to be hastily adapted templates. No company registration, address, or team info.

What if a tool or dependency gets compromised?1/10
U

No dependency scanning, SBOM, tool vetting, or update verification. 'Auto-Updates' claims servers 'automatically kept up to date' with no validation details. Auto-updating without documented verification is itself a supply chain risk. No public GitHub repos.

Is the platform itself secure?2/10
C

Magic-link email auth only, no MFA. HTTPS/TLS. 'Secure' feature vaguely claims 'Protected by default from SSL vulnerabilities, malware, and common security threats' — no specifics. No security.txt, no pen testing, no independent audit. Platform is 9 days old.

Can I trust what my agent tells me?0/10
U

No hallucination mitigation, output verification, approval workflows, undo/rollback, or AI uncertainty guardrails. Purely infrastructure — no trust layer on top of OpenClaw.

V = VerifiedD = DocumentedC = ClaimedU = Unknown
Dedicated VPS per userFull root access100% data ownershipSSL by default

Key Features

  • One-click deployment
  • 15+ global locations
  • 25+ servers
  • Full SSH access
  • Auto-updates
  • Manage multiple instances

Strengths

  • +Full server ownership
  • +Transparent VPS-based pricing
  • +Multiple global locations
  • +Auto-updates included

Weaknesses

  • No messaging integrations — raw VPS with subdomain access only
  • Security is your responsibility
  • Similar feature set to other VPS-based providers

Verdict

Raw VPS hosting with one-click OpenClaw deployment and 15+ global locations. Full server ownership but no messaging integrations — you configure those yourself.

Visit ClawRunInfrastructure: Hetzner / DigitalOcean VPS

Compare with Similar Providers

Head-to-Head Comparisons