MyClaw Host homepage screenshot
#20

MyClaw Host

Pre-launch

Fully managed hosting with 60-second deployment and no setup required

From
TBD
Security
Basic 1.8/100
Price Range
TBDTBD
Free Tier
No
Integrations
4 platforms

Security Score: 1.8/100 — Basic

MyClaw Host is a pre-launch managed OpenClaw hosting service with a single-page marketing website, a non-functional 'Deploy Now' button, and a 'Join Waitlist' link. The site makes several high-level claims about isolation, privacy, and monitoring but provides no technical specifics, no named technologies, and no documentation. The privacy policy and terms of service are clearly generic templates (referring to 'This App' and mentioning phone/device storage) that were not customized for an AI agent hosting service. There is no pricing, no security documentation, no status page, no public GitHub, and no evidence of third-party audits or compliance certifications. The provider appears to be in very early stages with no verifiable security practices.

10 risk categories scored 1-10 × evidence weight. Based on our methodology, grounded in OWASP Agentic Security, NIST CSF 2.0, and CIS Controls.

Can anyone else see my data?2/10
C

The homepage claims 'Dedicated OpenClaw instance per user or team' and 'Strict isolation of agents, sessions, and data' under 'Strong Privacy and Isolation.' The FAQ states 'Every customer gets a dedicated and isolated OpenClaw instance. There is no shared runtime, data, or agent context between users.' However, these are marketing claims with no technical specifics — no mention of how isolation is achieved (containers, VMs, etc.), no encryption-at-rest details, no data retention policy, and no mention of whether data is used for training. The privacy policy is a generic template that refers to 'This App' and mentions phone/device storage, suggesting it was not written for this service.

Can someone take over my agent?1/10
C

The homepage mentions 'controlled adapters with allowlists, pairing, and sandboxed execution to ensure safety' under 'Safe Channel Integrations.' However, there is no detail on what sandboxing technology is used, no mention of prompt injection defenses, no human-in-the-loop workflows, no memory integrity protection, and no discussion of container escape prevention. The single vague reference to 'sandboxed execution' is the only relevant claim.

Are my keys and passwords safe?0/10
U

No information found anywhere on the site about how API keys, bot tokens, or other credentials are stored, encrypted, rotated, or protected. The privacy policy makes no mention of credential handling. The FAQ does not address credential security. There is no documentation or security page.

Can my agent do things I didn't authorize?1/10
C

The FAQ mentions 'controlled access, channel-based permissions, and sandboxed agent sessions' for teams. The 'How OpenClaw Works' section says agents 'understand rules, permissions, and intent before responding or taking action.' However, there is no mention of rate limiting, spending caps, kill switches, behavioral monitoring, least-privilege enforcement, or high-risk tool gating. The claims are high-level marketing language.

Can I lose my data or get locked out?2/10
C

The FAQ states 'You can export configurations and move to your own self-managed setup at any time' regarding migration, and mentions 'We continuously monitor uptime and health. Services are automatically restarted and issues are handled by our team.' The 'Always Available' section claims '24/7 monitoring and health checks' and 'Automatic restarts and recovery.' However, there is no mention of backups, data retention, SLAs, disaster recovery, or what happens if the provider shuts down. The data export claim is vague.

Will I get unexpected bills?0/10
U

No pricing information exists anywhere on the site. There is no pricing page, no tier information, no mention of costs, billing, spending caps, or usage monitoring. The 'Deploy Now' and 'Join Waitlist' buttons are non-functional (link to '#'). The terms of service make no mention of pricing, refunds, or billing.

Who's responsible when something goes wrong?0/10
U

No information found about audit logging, incident response, breach notification, jurisdiction of data storage, GDPR compliance, or agent action audit trails. The privacy policy is a generic mobile app template that does not address any of these topics. The terms of service contain no liability framework specific to AI agent hosting. There is no mention of where data is stored geographically.

What if a tool or dependency gets compromised?0/10
U

No information found about dependency management, MCP server vetting, AI provider data policies, SBOM, build pipeline security, or update verification. The 'Managed Stability and Updates' section says 'We ensure the system stays updated, monitored, and optimized' but provides no details on how updates are vetted, tested, or deployed.

Is the platform itself secure?1/10
C

The site uses HTTPS (TLS). The homepage mentions 'security hardening' in the FAQ answer about what they manage, and 'Security-first defaults applied automatically.' However, there is no mention of MFA, authentication mechanisms, access control implementation, injection prevention, security testing, or any specific platform hardening measures. The privacy policy's security section contains only the generic disclaimer 'we are striving to use commercially acceptable means of protecting it.'

Can I trust what my agent tells me?0/10
U

No information found about hallucination mitigation, approval workflows, output verification, undo/rollback capabilities, or transparency about AI uncertainty. The site does not address output reliability or trust exploitation risks at all.

V = VerifiedD = DocumentedC = ClaimedU = Unknown
Isolated environmentSystem architecture docs available

Key Features

  • 60-second deployment
  • No servers, no setup, no terminal
  • Fully managed
  • System architecture transparency

Integrations

TelegramWhatsAppDiscordSlack

Strengths

  • +Zero-technical-skill required
  • +System architecture documentation
  • +Clean, professional presentation

Weaknesses

  • Pre-launch — Deploy Now buttons non-functional
  • Pricing not yet published
  • New entrant, no track record

Verdict

Professional-looking pre-launch site with good architecture docs. Deploy buttons not yet functional — wait for full launch.

Visit MyClaw HostInfrastructure: Managed cloud (unspecified)

Compare with Similar Providers