
LobsterLair
LiveAI-included hosting with MiniMax M2.1 model and 48-hour free trial
Security Score: 9.7/100 — Basic
LobsterLair is a small, single-operator managed OpenClaw hosting service (Banalabs / Tobias Bischoff) with some basic security hygiene (TLS 1.3, security headers, AES-256-GCM credential encryption claims, Docker isolation). Security posture is almost entirely claim-based with no independent verification. Registered at HK mail forwarding address while claiming German jurisdiction — accountability concern. Contradictory API key statements in Terms vs marketing. Data export feature is a positive. Overall basic-tier with documented claims but minimal verifiable evidence.
10 risk categories scored 1-10 × evidence weight. Based on our methodology, grounded in OWASP Agentic Security, NIST CSF 2.0, and CIS Controls.
Privacy policy claims 'Isolated Docker containers per user' and 'Encryption in transit (TLS/SSL)' with per-user access control via Telegram User ID. No documentation of employee access controls, audit trail for data access, or data-at-rest encryption beyond API keys. 'Only you can talk to your bot' addresses single-tenancy at Telegram layer but not infrastructure layer.
No mention of prompt injection protections, input sanitization, or separation of instructions from external data. No sandboxing beyond basic Docker — no gVisor, Firecracker, etc. No human-in-the-loop for goal changes or code execution. Memory feature ('Your bot learns your preferences') has no documented integrity protection against poisoning.
Privacy policy: 'API keys encrypted with AES-256-GCM' and 'Telegram bot tokens (encrypted).' FAQ reiterates encryption claim. However, no key management practices (HSM, rotation, who holds keys), no credential leak detection in outputs, no documentation on whether credentials appear in logs. Specific claims but unverifiable without audit.
No guardrails: no spending caps, rate limiting details, tool gating, kill switch, or behavioral monitoring. FAQ mentions 'strict resource limits' on containers but this addresses compute, not agent behavioral boundaries. Complete absence of rogue-agent protections.
FAQ: 'Data is retained for 30 days in case you resubscribe' and 'Download My Data button to export all your bot's configuration and workspace data as a ZIP file.' Meaningful data portability. No backups, backup testing, disaster recovery, or status page. Terms: 'We strive to maintain 24/7 uptime but do not guarantee uninterrupted service.' Provider registered at HK mail forwarding address.
Clear pricing: single plan $19/month. 48-hour free trial, no credit card. However, Terms say users responsible for 'All costs associated with your AI provider API usage' while homepage claims 'AI included — no API key needed' — contradictory. No spending caps or usage alerts. Price changes via 'Last updated' date only.
Privacy policy has GDPR section with 30-day response commitment. Terms specify German governing law. However, provider address is HK mail forwarding ('C/O SEKO 13C Por Mee Fty Bldg') — jurisdiction mismatch. No incident response, breach notification timeline, audit logging, or security monitoring. Entity 'Banalabs' has minimal public presence. No security.txt.
FAQ: 'We review every OpenClaw update for security issues before deploying' and updates 'go through our security review process.' Meaningful claim but unverifiable — no review details, no SBOM, no dependency scanning. Uses MiniMax M2.5 as AI provider with no documented data policies. No MCP server or tool vetting.
Strong HTTP headers verified: HSTS with preload, X-Frame-Options, X-Content-Type-Options, CSP, Permissions-Policy. TLS 1.3. Google OAuth available. However, CSP includes 'unsafe-inline' and 'unsafe-eval' weakening script protection. No MFA beyond Google's own. No rate limiting on login, no session management details, no independent security testing.
No protections against hallucinations, output manipulation, or trust exploitation. No approval workflows, verification mechanisms, undo/rollback, or AI uncertainty transparency. Gap for platform encouraging email drafting and shopping use cases.
Key Features
- ✓AI model included (MiniMax M2.1)
- ✓No BYOK required
- ✓48-hour free trial
- ✓One-click deployment
- ✓Persistent storage
Integrations
Strengths
- +AI included — no API keys needed
- +48-hour free trial
- +Simple single-tier pricing
Weaknesses
- −Telegram-only integration
- −MiniMax M2.1 is less capable than Claude/GPT
- −Limited feature set
- −New provider, limited track record
Verdict
Simple option with AI included. The free trial is nice, but the included model (MiniMax M2.1) is less capable than mainstream alternatives.