OpenClaw Host homepage screenshot
#9

OpenClaw Host

Live

Multi-agent VPS hosting with up to 10 agents per account

From
$19/mo
Security
Basic 5.5/100
Price Range
$19/mo$99/mo
Free Tier
No
Integrations
4 platforms

Security Score: 5.5/100 — Basic

OpenClaw Host is a managed hosting provider focused on ease-of-use. Security posture is extremely thin: vague marketing about 'isolated Docker containers' and 'encrypted volumes' with no technical specifics. No security page, no docs, no compliance, no team page, no public code. ToS/Privacy use heavily themed language obscuring legal substance. Missing basic web security headers despite Cloudflare, wildcard CORS, no MFA. Most risk categories unaddressed or vague marketing only. One relative strength: transparent flat-rate pricing.

10 risk categories scored 1-10 × evidence weight. Based on our methodology, grounded in OWASP Agentic Security, NIST CSF 2.0, and CIS Controls.

Can anyone else see my data?2/10
C

Homepage FAQ: 'Every agent runs in an isolated Docker container. Your API keys and memory are encrypted and never shared.' Privacy policy claims 'isolated encrypted volumes' and they 'do not inspect the logic of your agent's private directory.' No technical specifics — no encryption standards, key management, data retention, log sanitization, or AI training opt-out. Docker container isolation alone is weak without hardening details.

Can someone take over my agent?1/10
C

No information on prompt injection defenses, sandboxing, human-in-the-loop, memory integrity, or container escape prevention. Install page references 'security hardening' via 'Every installation goes through a safety check' but zero technical specifics. No separation of instructions from external data or output sanitization mentioned.

Are my keys and passwords safe?2/10
C

FAQ: 'Your API keys and memory are encrypted and never shared.' Privacy policy mentions 'isolated encrypted volumes.' No details on encryption method, key management, credential leak detection, rotation, or whether credentials are excluded from AI model context. BYOK model but no protection details.

Can my agent do things I didn't authorize?0/10
U

No information found on agent guardrails, rate limiting, kill switches, behavioral monitoring, tool gating, or least-privilege. Advertises 'Unlimited Agents' and 'unlimited usage' with no resource consumption limits or spending caps.

Can I lose my data or get locked out?1/10
C

Homepage mentions 'Persistent Storage' and 5-agent plan includes 'Safe Volume Backups.' No details on backup frequency, restore procedures, data export, or provider shutdown policy. ToS: service 'as is' with no liability for 'logical data decay, agent downtime.' No SLA except custom enterprise.

Will I get unexpected bills?4/10
D

Flat-rate pricing clearly displayed: $19/mo (1 agent), $69/mo (5 agents), $99/mo (10 agents). 'All plans include unlimited usage. You provide your own API keys.' Transparent but no price change notification policy, no spending caps, no usage alerts.

Who's responsible when something goes wrong?1/10
C

No audit logging, incident response, breach notification, or regulatory compliance mentioned. Privacy policy has no GDPR reference. ToS uses themed language ('Terms of Engagement', 'Command Responsibility') obscuring legal substance. No company registration, address, or team info. Contact email is support@myclaw.host.

What if a tool or dependency gets compromised?0/10
U

No information on dependency scanning, MCP server vetting, SBOM, build pipeline security. Deploy page: 'Python, dependencies, and core OpenClaw logic are pre-installed' with no vetting details. No GitHub repos linked.

Is the platform itself secure?2/10
C

Login offers Google/Apple OAuth plus email/password, no MFA. Site behind Cloudflare but critical security headers missing (no HSTS, CSP, X-Frame-Options). CORS wildcard 'access-control-allow-origin: *' is a security concern. VPS page claims 'Baked-in security protocols' with zero specifics. No penetration testing.

Can I trust what my agent tells me?0/10
U

No information on hallucination mitigation, approval workflows, output verification, undo/rollback, or AI uncertainty transparency.

V = VerifiedD = DocumentedC = ClaimedU = Unknown
Isolated Docker containersDedicated VPS per planPersistent storage

Key Features

  • Multi-agent support (1-10 agents)
  • 1-click deployment
  • Web terminal access
  • YouTube setup tutorial
  • Enterprise custom plans
  • Auto-scalable infrastructure

Integrations

TelegramWhatsAppDiscordSlack

Strengths

  • +Multi-agent support up to 10
  • +Clear tiered pricing
  • +Video tutorials for setup
  • +Enterprise plans available

Weaknesses

  • Generic security claims
  • Limited integrations
  • New entrant, limited track record

Verdict

Good option if you need multiple agents on one account. Clear pricing tiers from solo to enterprise.

Visit OpenClaw HostInfrastructure: Dedicated VPS per user

Compare with Similar Providers

Head-to-Head Comparisons