πŸ”’ Enterprise Trust & Security

The AI Agent That
Enterprises Trust

BYOK architecture. Data residency. Audit logs. SLA guarantees. Parent-org controls. A security posture built for legal, financial, and regulated professional services.

Schedule a Security Review Enterprise Overview β†’
99.9% Uptime SLA
7 Data Regions
0 Keys Stored
24h Incident Response
Full BYOK β€” we never hold your API keys, your data, or your secrets. Your AI infrastructure is yours alone. See the architecture β†’

Bring Your Own Keys

You own your AI provider relationship. We provision the infrastructure; you control the intelligence layer.

πŸ”‘

Keys Never Touch Our Servers

Your AI provider API keys are entered directly into your OpenClaw instance on your own server. They are never transmitted to, stored on, or accessible through OpenClawInstall.AI infrastructure. Setup is the last time your keys are handled by our automation β€” and only then if you opt for guided installation.

πŸ›οΈ

Your Server. Your Data.

Every OpenClaw instance runs on a dedicated server assigned exclusively to your organization. No shared tenancy. No cross-customer data exposure. All prompts, responses, and session state remain on your infrastructure from day one.

πŸ”„

Rotate Anytime, Zero Downtime

Rotate your API keys through OpenClaw's dashboard at any time. No involvement from OpenClawInstall.AI required. If you use OpenClaw Credits instead, no API keys are needed at all β€” we handle provider access on our own infrastructure.

πŸ“‹

Vendor Lock-In: None

OpenClaw supports Claude, GPT-4, Gemini, Kimi K2.6, MiniMax, and Ollama simultaneously. Switch models or providers without re-installing. Your deployment is provider-agnostic by architecture, not by promise.

BYOK vs. OpenClaw Credits vs. Shared-Key SaaS

Capability BYOK (Your Keys) OpenClaw Credits Shared-Key SaaS
API keys stored by vendor βœ— Never βœ“ N/A (no keys) βœ— Yes
Data stays on your server βœ“ Always β—‘ Per-plan βœ— Vendor cloud
Direct provider billing βœ“ Yes βœ— Handled by us βœ— No
Multi-model support βœ“ All providers βœ“ All providers βœ— Single provider
Key rotation control βœ“ Instant β—‘ Via dashboard βœ— Requires support
Enterprise audit trail βœ“ Full β—‘ Standard β—‘ Limited

Choose Where Your Data Lives

Cloud deployments are available across seven regions. On-Site and Ship-In deployments keep all data on your hardware, in your facility.

πŸ‡ΊπŸ‡Έ United States β€” East

US-East (Default)

Ashburn, VA β€” optimal for East Coast law firms, financial services, and Greater Philadelphia prospects.

πŸ‡ΊπŸ‡Έ United States β€” West

US-West

California β€” for West Coast operations and firms with California jurisdictional requirements.

πŸ‡ͺπŸ‡Ί European Union

EU (Frankfurt / Amsterdam)

GDPR-resident. For EU-based firms or organizations with EU data governance requirements.

πŸ‡¬πŸ‡§ United Kingdom

UK (London)

Post-Brexit UK residency for SRA-regulated law firms and UK professional services.

πŸ‡¨πŸ‡¦ Canada

Canada (Toronto / Montreal)

PIPEDA-compliant deployment for Canadian firms and federally regulated industries.

🏒 On-Premise

On-Site / Ship-In

Your hardware. Your network. Zero data leaves your facility. Full physical control β€” ideal for privilege-sensitive practices.

πŸ‡¦πŸ‡Ί Australia

APAC (Sydney)

For Australian firms and APAC operations requiring data locality within the region.

On-Premise is the gold standard for legal privilege. Attorney-client communications, litigation strategy, M&A analysis, and privileged documents never leave your network with On-Site or Ship-In deployment. This is the preferred option for AmLaw 200 firms, large accounting firms, and any regulated entity with strict data-sovereignty requirements.

How Security Flows

Every deployment is isolated, encrypted, and access-controlled from the first provisioning step.

Typical Cloud Deployment β€” Per-Customer Isolation
πŸ‘€
You / Your Team
Telegram, Signal, Discord, Slack, iMessage
β†’
πŸ”’
OpenClaw Instance
Your dedicated server. TLS inbound.
β†’
βš™οΈ
Your AI Provider
Claude / GPT / Gemini β€” BYOK only
● Encrypted channel    ● Your API keys never touch our infrastructure    ● No shared compute
πŸ›‘οΈ

Server Hardening

SSH key-pair auth only, firewall locked to known IPs, automatic OS security patches, and no unnecessary services running. Every server ships locked down.

πŸ”

TLS Everywhere

All inbound connections (Telegram, Discord, Signal, Slack, webhooks) are encrypted in transit. AI provider API calls are made over HTTPS with TLS 1.2+.

🚫

No Log Persistence

OpenClaw session logs are written to your server's local disk only. We do not receive, aggregate, or store your conversation logs on any external system.

πŸ”§

Dependency Transparency

OpenClaw is open-source. Every dependency, integration, and API call is inspectable at github.com/p intermed/openclow. No black-box AI processing.

Enterprise Uptime Guarantee

Cloud deployments are backed by a 99.9% monthly uptime SLA. On-Site deployments carry no SLA from our side since the hardware is yours β€” but we provide documentation to build your own.

99.9%
Monthly Uptime
Enterprise Cloud plans. Measured monthly. Pro-rated credits for any shortfall.
<30m
Max Downtime / Month
~4.4 hours per year maximum. Excludes planned maintenance with 48h notice.
<
<4h
MTTR β€” Business Hours
Mean time to resolution during standard business hours (9 AM–6 PM, requester's timezone).
24h
MTTR β€” Critical
P1 incidents affecting core functionality acknowledged and actively worked within 24 hours.
48h
Planned Maintenance Notice
All scheduled maintenance announced at least 48 hours in advance via email and dashboard.
5
Nines of Durability
Object-level durability for any customer data snapshots stored on our infrastructure.
SLA credits β€” If monthly uptime falls below 99.9%, enterprise customers receive a pro-rated service credit proportional to the downtime, applied to the next billing cycle. SLA credits do not exceed the monthly plan cost. Credits are the sole remedy for SLA breaches unless a separate Enterprise MSA is negotiated.

Framework & Certification Readiness

We maintain active alignment with major compliance frameworks. Current status for each is listed below.

πŸ›‘οΈ

SOC 2 Type II

Security, availability, and confidentiality trust service criteria

In Progress β€” 2026
πŸ‡ͺπŸ‡Ί

GDPR

EU data protection regulation for EU-resident data processing

Active β€” EU region
πŸ‡¬πŸ‡§

UK GDPR

UK data protection post-Breuit for UK-resident processing

Active β€” UK region
πŸ‡¨πŸ‡¦

PIPEDA

Canadian personal information protection for Canadian deployments

Active β€” CA region
πŸ›οΈ

Attorney-Client Privilege

Architecture supports privilege-protected deployments (on-premise recommended)

Architecture Ready
πŸ”’

Data Processing Agreement

Signed DPA available for enterprise engagements upon request

Available on Request
πŸ“‹

Custom MSA / SOW

Master services agreement with custom liability, IP, and SLA terms

Available on Request
πŸ“‚

CCPA

California Consumer Privacy Act alignment for CA residents' data

Active
For law firms and legal organizations: OpenClawInstall.AI does not provide legal advice and does not require access to your case data or client communications. Our architecture is designed so that privileged content never routes through our infrastructure β€” see the On-Premise option for maximum privilege protection. We are happy to sign firm-specific DPAs and MSAs.

Full Activity Visibility

Enterprise customers get a complete, exportable audit trail of all administrative actions taken on their deployment.

πŸ“‹

Admin Action Log

Every server config change, user permission update, channel connection, and API key rotation is timestamped and logged locally on your server.

πŸ’Ύ

Session Export

Export conversation histories in JSON or CSV for compliance archiving, litigation holds, or internal review β€” no data leaves your server.

πŸ”

Access History

See who accessed the admin panel, when, from what IP, and what was changed. Retained for 12 months locally.

πŸ“Š

Usage Reporting

Monthly AI usage reports broken down by model, user, and channel. Available via dashboard export for billing reconciliation.

πŸ””

Anomaly Alerts

Configurable alerts for unusual access patterns, new API key usage, or administrative changes outside business hours.

πŸ“œ

Compliance Export Pack

Annual data export package for auditors: access logs, config snapshots, and usage summaries in a ZIP archive.

Multi-User Governance Without Chaos

Enterprise parent accounts manage billing, seat allocation, and rollout policy from a single dashboard β€” with granular controls over what each tier can and cannot do.

1

Parent Account β€” Billing & Policy

The parent org owns the master billing account, defines the default AI lane, and sets organization-wide policies (allowed channels, data residency, allowed AI models). The parent can enable or disable any per-seat capability globally.

2

Seat Allocation β€” Staged Rollout

Add seats in bulk or in cohorts. Stage the rollout by department, role, or geography. New seats inherit the organization's default AI lane but can be assigned custom lanes independently.

3

Per-Seat AI Lane β€” Independent or Shared

Each seat can run its own independent OpenClaw instance or share a team-scoped instance. Shared instances give the parent org visibility while keeping individual user sessions private.

4

Revocation & Offboarding

Revoke any seat instantly from the parent dashboard. All API keys, session data, and channel integrations for that seat are deactivated. Data can be retained per the organization's retention policy.

Parent vs. Seat Permissions Matrix

βœ“ Parent: view all seat activity logs
βœ“ Seat: private session history
βœ“ Parent: revoke any seat instantly
βœ“ Seat: own API keys (BYOK)
βœ“ Parent: set org-wide allowed models
βœ“ Seat: choose own persona/config
βœ“ Parent: export org-wide usage report
βœ“ Seat: own channel integrations
βœ“ Parent: enforce data residency policy
βœ“ Seat: private memory (LightRAG)
βœ“ Parent: billing and subscription management
βœ“ Seat: independent AI provider (BYOK)

When Something Goes Wrong

Our incident response process is time-bound, transparent, and built around minimizing impact to your operations.

T+0 β€” Detection

Incident Acknowledged

P1 incidents (core functionality down) are acknowledged within 1 hour during business hours, 4 hours off-hours. P2 incidents acknowledged within 4 hours. A support ticket is opened and a dedicated Slack/Teams channel is established for enterprise customers.

T+1h β€” Assessment

Impact Scope Defined

We identify affected systems, customer impact scope, and whether any customer data is at risk. You receive a status page update and direct notification if your organization is in the affected scope.

T+4h β€” Containment

Immediate Containment

Affected services are isolated. API keys can be rotated by you at any time without our involvement. Temporary workarounds (channel switches, fallback model routing) are documented and shared.

T+24h β€” Resolution or ETA

Fix Deployed or Timeline Confirmed

Most incidents are resolved within 24 hours. If longer, we provide a concrete ETA, executive-level updates every 8 hours, and a root cause analysis within 5 business days of resolution.

T+5 Days β€” Post-Mortem

RCA & Prevention Plan

Enterprise customers receive a written root cause analysis, timeline of events, and a preventive action plan with completion dates. Shared within 5 business days of incident resolution.

Breach notification: If a security breach results in unauthorized access to customer data, we notify affected customers within 72 hours of confirmation. Notification includes: nature of breach, data affected, current remediation status, and contact for questions.符合 GDPR Article 33 requirements.

Continuous Security Hardening

We run automated security scanning, maintain a vulnerability disclosure program, and apply patches systematically.

πŸ”

Automated Security Scanning

All OpenClaw releases are scanned for known vulnerabilities in dependencies before deployment. Infrastructure undergoes automated network-level scanning weekly.

πŸ› οΈ

Dependency Patching

Critical CVEs patched within 72 hours of disclosure. High-severity within 14 days. All patches tested in staging before production rollout.

🎯

Penetration Testing

Annual third-party penetration test conducted by a qualified security firm. Results shared with enterprise customers under NDA upon request.

πŸ“’

Responsible Disclosure

Security researchers can report vulnerabilities via [email protected]. We acknowledge within 24 hours and target resolution within 90 days for valid findings.

Common Security Questions

The questions enterprise buyers ask before signing.

Who owns the data generated by my AI agent?

You own all data generated by your AI agent β€” prompts, responses, session logs, and any files processed. We claim no ownership, no license, and no rights to your data. Our automation only touches provisioning and infrastructure management, never the content of your sessions.

Can we sign our own MSA/DPA?

Yes. We provide a standard DPA and MSA for all enterprise engagements. For firms with specific requirements, we accommodate reasonable redlines. Standard turnaround on MSA review is 5 business days. Contact us at [email protected].

What happens to our data if we cancel?

You can export all session logs, configuration files, and usage data at any time before cancellation. Within 30 days of account closure, we delete all customer-provisioned data from our infrastructure. On-Premise and Ship-In deployments leave zero data on our systems since all data stays on your hardware.

Can OpenClawInstall.AI staff access our agent?

Only if you grant explicit, time-limited access through a support session you initiate. We do not have standing access to any customer deployment. All access is logged in the audit trail. Cloud deployments can be configured to block all remote access β€” in that mode, troubleshooting requires you to share specific logs voluntarily.

Do you use customer data to train AI models?

No. We do not use customer prompts, responses, or any session content to train, fine-tune, or improve any AI model β€” ours or any third party's. This is explicitly prohibited in our terms of service and our AI provider agreements.

Are your sub-processors listed?

Yes. Our current sub-processor list is available on request and includes: cloud infrastructure providers (Hetzner, Vultr), payment processor (Stripe), and support tooling (Discord, email). We notify enterprise customers 30 days before adding any new sub-processor.

What is your AI model selection policy?

We support any AI provider that offers a public API. Current first-class integrations include Anthropic (Claude), OpenAI (GPT), Google (Gemini), Moonshot (Kimi K2.6), MiniMax, and Ollama for local models. We do not favor any provider algorithmically in our recommendations. BYOK means you select β€” not us.

Ready for a Security-First Conversation?

Talk to a solutions engineer about enterprise deployment, compliance requirements, or a custom MSA.

Enterprise sales: [email protected] Β· Response within 1 business day