Clawy homepage screenshot
#16

Clawy

Pre-launch

Pre-launch BYOK hosting by Driple with WhatsApp, Telegram, Discord, and Slack

From
$29/mo
$29/mo founding member pricing per instance (locked in); BYOK required. Domain moved to clawy.thedriple.com
Security
Basic 3/100
Price Range
$29/mo$29/mo
Free Tier
No
Integrations
3 platforms

Security Score: 3/100 — Basic

Clawy is a pre-launch managed OpenClaw hosting service operated by 'driple,' likely a German/EU entity (parent domain hosted on ALL-INKL.COM, analytics on PostHog EU Frankfurt). The service is currently waitlist-only with no live product to evaluate. Security claims are limited to marketing-level language: 'isolated containers,' 'encrypted at rest' (for API keys), and 'TLS.' No named technologies, no architecture documentation, no security policies for the hosting service, and no public code to inspect. The Privacy Policy and Terms only cover the pre-launch website, not the actual hosting infrastructure. The $29/mo BYOK pricing model provides some cost transparency, but no agent-specific guardrails (rate limits, kill switches, approval flows) are documented. Given the pre-launch status and absence of technical documentation, scores are necessarily low across nearly all categories.

10 risk categories scored 1-10 × evidence weight. Based on our methodology, grounded in OWASP Agentic Security, NIST CSF 2.0, and CIS Controls.

Can anyone else see my data?2/10
C

The FAQ states 'Every clawy user gets their own isolated container — your data is never shared with other users' and the features section claims 'Secure Isolation — Your instance runs in its own secure container. No shared risk.' The Privacy Policy covers only the website (not the hosting service, which is pre-launch) and mentions PostHog analytics on EU servers and Cloudflare as subprocessors. However, there is no detail on what container technology is used, no mention of encryption at rest for user data (only API keys), no data retention policy for agent data, no mention of whether data is used for AI training, and no employee access controls are described. These are marketing-level claims without technical specifics.

Can someone take over my agent?1/10
C

The homepage mentions 'No exposed ports' and 'Isolated containers' under the 'Secure by Default' heading, but there is no documentation of prompt injection defenses, sandboxing technology, human-in-the-loop approvals, memory integrity protection, or container escape prevention. The service is pre-launch so no architecture documentation exists. The only claim is generic container isolation with no named technologies.

Are my keys and passwords safe?2/10
C

The FAQ states 'Your AI API key is encrypted at rest, and all connections are secured with TLS.' This addresses encrypted storage and transport security at a high level but provides no specifics about the encryption method, key management, credential rotation, whether credentials are excluded from model context, or credential leak detection in outputs. The BYOK model means users provide their own keys, but how those keys are stored and protected beyond 'encrypted at rest' is undocumented.

Can my agent do things I didn't authorize?0/10
U

No information found about guardrails for agent behavior. There is no mention of rate limiting, kill switches, tool gating, least-privilege permissions, behavioral monitoring, or approval workflows. The homepage's problem section ironically highlights '$300+ in 2 days — Claude Opus API costs spiral without visibility or controls' as a self-hosting pain point, but the solution section does not describe any specific cost controls or agent guardrails that Clawy implements.

Can I lose my data or get locked out?1/10
C

The Terms state 'We aim to provide 24/7 uptime but do not guarantee uninterrupted service. We are not liable for any downtime or service interruptions.' There is no mention of backups, data export, disaster recovery, or what happens to user data if the service shuts down. The FAQ mentions 'Cancel anytime. No lock-in, no questions asked' but does not address data portability. The parent company thedriple.com is a placeholder page, raising concerns about provider stability.

Will I get unexpected bills?3/10
C

Pricing is clearly stated at '$29 per month per OpenClaw instance' with the FAQ adding 'AI usage costs are separate and go directly to your AI provider via your own API key.' The BYOK model means users control their AI spending directly. The Terms note 'You are solely responsible for your AI API keys and any costs incurred through their use. We recommend setting usage limits with your AI provider to avoid unexpected costs.' This is reasonable transparency, but there are no hard spending caps, usage monitoring, or alerts provided by Clawy itself. Pricing change policy is vague: 'Founding member pricing is subject to change before launch.'

Who's responsible when something goes wrong?2/10
C

The Privacy Policy covers GDPR rights and names subprocessors (PostHog EU, Cloudflare). The Terms reference isolated containers and link to the Privacy Policy. However, there is no incident response process, no breach notification timeline, no audit logging described, no agent action audit trail, and no information about data jurisdiction for the hosting service itself (only analytics is confirmed EU-hosted). The Privacy Policy only covers the website, not the actual hosting service which is pre-launch.

What if a tool or dependency gets compromised?0/10
U

No information found about dependency management, MCP server vetting, software bill of materials, build pipeline security, or how third-party tools are vetted. The 'Auto-Updates' feature is listed but with no detail on how updates are verified or delivered. No GitHub repositories are public for inspection.

Is the platform itself secure?1/10
C

The FAQ claims 'all connections are secured with TLS' and the homepage says 'No exposed ports.' The website itself is served via Cloudflare (per Privacy Policy). However, there is no information about authentication mechanisms (MFA support), access control, injection prevention, security testing, or platform hardening. The service is pre-launch so no dashboard or API exists to evaluate. No independent security testing or audits are mentioned.

Can I trust what my agent tells me?0/10
U

No information found about approval workflows, output verification, hallucination mitigation, undo/rollback capability, or transparency about AI uncertainty. The service does not document any guardrails for ensuring output reliability or preventing trust exploitation.

V = VerifiedD = DocumentedC = ClaimedU = Unknown
Isolated containersNo exposed portsSecurity-first architectureEncrypted connections

Key Features

  • BYOK (bring your own API keys)
  • Multi-platform messaging
  • Waitlist with founding price
  • Backed by Driple (existing company)

Integrations

WhatsAppTelegramSlack

Strengths

  • +Backed by existing company (Driple)
  • +WhatsApp + Telegram + Slack from day one
  • +Founding member pricing

Weaknesses

  • Pre-launch — no live product yet
  • BYOK adds friction
  • Limited feature details available
  • Generic security claims

Verdict

Interesting pre-launch from an established company. Wait for launch to evaluate. Also known as ClawStack.

Visit ClawyInfrastructure: Managed cloud (by Driple)

Compare with Similar Providers