Pricing

The record comes with it.
Not having to read it is the product.

Your agent makes hundreds of tool calls an hour and you read almost none of them. Clawmont writes every one of them down on your own disk as it happens. What you pay for is the part that reads the record for you, keeps a copy off the laptop that wrote it, and refuses the handful of calls you could not take back. One command to install.

Clawmont Security is one product with two prices — $9.99/mo added to a setup purchase below, or $19.99/mo standalone. Both start with a 7-day trial.

Which of these do I need?

You want to know what your agent did — start here, free
Clawmont Free records every tool call to a hash-chained log on your disk and hands you a receipt at the end of each run. No card, no expiry, and the same detectors as the paid plan behind it. Most people should start here and read a week of their own traffic before paying for anything.
You do not want to read the log yourself — this is the paid one
Clawmont Security reads it for you and sends the few things worth knowing, on the quiet days too. It also keeps the trail off the machine that wrote it, and can deny a short list of calls you could not take back. $19.99/mo on its own, no setup purchase needed, 7-day trial.
You are also buying a configured install
A persona is a one-time $30 setup for OpenClaw — tools, skills and MCP servers for your role, and no security layer. Add Clawmont Security to it at checkout and the subscription is $9.99/mo instead of $19.99. Same product either way; the lower price is the setup-buyer's discount.
You only want the setup
Then buy a persona and leave the add-on unticked. It is unticked by default and we will not tick it for you. A persona on its own installs no recorder and no security layer, and we would rather say so here than have you find out later. The setup products have their own page at /openclaw.

Clawmont Free · the record

Free no card, no expiry

The full record of what your agent did, hash-chained on your own disk, with a receipt at the end of every run. No card, no expiry, and no detection held back.

  • Every tool call your agent makes, recorded to a hash-chained log on your disk. Edit one line and the chain breaks.
  • A receipt at the end of every run: what it touched, what it changed, what was flagged.
  • audit.html beside the trail, so the record opens in a browser instead of a text editor.
  • The same detectors as the paid plan. We do not hold back detection to sell an upgrade.
  • Nothing leaves your machine, so your keys cannot either.

What it will not do

  • It records; it does not read the record for you. No digest, no cross-project summary.
  • It keeps the trail on the machine that made it. Nothing is stored off-machine, and nothing is delivered to you.
Read the install guide

Want it to block? That is Clawmont Security, below.

Clawmont Security · the answer and the brakes

$ 19.99 /mo standalone

7-day free trial: $0 due today. Run it against your agent's real traffic for a week, cancel in the trial and pay nothing.

The record keeps itself and always did. This is the part that reads it for you and sends the few things worth knowing, keeps a copy off the laptop that wrote it, and refuses a short list of calls you would not be able to take back. No persona and no model setup required.

  • A deny at the tool-call boundary, before the command runs. It is off until you turn it on.
  • Today that denies things like a recursive delete outside a build directory, a private key read, and your .env going out over the wire.
  • A digest that arrives on the quiet days too, not only when something happened.

Buying a persona or Apex below? Add it at checkout for the bundled $9.99/mo, instead of $19.99/mo standalone.

Your prompt Tool dispatch Tool result

$0 due today · then $19.99/mo · Cancel anytime · Pro-rata refund

Not built yet, and we are not charging as if it were

  • Your agent just rewrote 12 files — one command to put them back. Checkpoint and undo, scoped to a single run: it restores the files that run changed, and it does not pretend to reverse an install or a network call. Not built yet.
  • Alerts off the machine, to Slack, Discord, Telegram or email. Not built yet.
  • A searchable audit trail we host, so the record outlives the laptop that wrote it. Not built yet — today the record is local only, and that is the whole of it.
  • Brakes on the rest of the irreversible list: a force-push, a reset --hard with work in the tree, a secret going into a commit. We probed our own build on 2026-08-12 and it allows all three today, even with enforcement on. That is the next thing we are fixing, and we would rather you read it here than find out later.

Setup, not security

Want a configured OpenClaw install too?

A persona is a one-time purchase that sets up OpenClaw for your role with curated tools, skills and MCP servers. It is convenience, not protection, and it installs no security layer on its own. Full detail on the OpenClaw setup page.

Single persona

$ 30 one-time

Pick one of four personas.

Developer Trader SRE Researcher
  • A role-tuned AI persona: model routing, system prompt, and sensible defaults configured for you
  • Curated MCP servers + a skills bundle, locked to your role
  • Your provider keys stay on your machine, entered in your terminal, never on our servers
  • Upgrade to Apex later for $10, no re-tier

Pay now, choose your persona in onboarding.

Apex · all-access

$ 40 one-time

Every persona, plus every future one. All in one setup.

roles, one setup
4
curated skills
32
MCP servers
15
  • All four personas merged and deduplicated into one setup
  • Switch role anytime, no re-buying or re-tiering
  • Every future persona ships free
  • Add Clawmont Security (Guardrails) anytime for $9.99/mo

One-time payment. All future personas included.

Prices exclude VAT. Applicable tax is calculated at checkout based on your location.

Your keys never leave your machine

API keys are entered in your terminal during install and stored in your OS keychain. The browser never sees them.

No access to your code

Detection runs locally, inside the agent you already run. No repo access, nothing to grant.

No code stored on our servers

Optional cloud alerts send short, redacted alert metadata. Your codebase stays with you.

Licensed under BUSL-1.1 — not open source. The install script is published in full at clawmont.com/install.sh; read it before you run it.

Before you buy

What a refusal actually looks like

Same file, different intent. Detection numbers, methodology, and known limitations are published on the security page.

after install · runs on your machine
$ openclaw clawmont doctor
ok   security plugin loaded and enabled
ok   dashboard responding
ok   keys readable, config writable

Installed is not the same as running. The install checks that the layer actually loaded, and when a check fails it prints the exact command to fix it instead of a green tick — the local dashboard is served from inside the security layer itself, so if the layer stops, there is no dashboard to open.

Keys stay local

Entered in your terminal, kept in your OS keychain — never sent to our servers.

Read the installer

The full install script is published at clawmont.com/install.sh — read every line before you run it.

Limits in writing

Detection, not a sandbox. What we catch and what we miss is published, not implied.

No sales call

Public pricing, self-serve trial, cancel in the dashboard.

Prices exclude applicable taxes (e.g. VAT), which are added at checkout where required. Persona and Apex are one-time licenses and are final sale; Guardrails can be cancelled any time with a pro-rata refund for the unused period. Statutory EU/EEA consumer rights still apply. By purchasing you agree to our Terms of Service and Refund Policy.

Pricing FAQ

Common pricing questions

What is free, exactly?

The record. Clawmont Free writes every tool call your agent makes to a hash-chained log on your own disk, hands you a receipt at the end of each run saying what it touched, and puts an audit.html beside the trail so you can read it in a browser. There is no card and no expiry, the same detectors run as on the paid plan, and nothing leaves your machine. It is a complete product, not a trial.

What do I actually get for paying?

Not having to read the log. Clawmont Security reads the record for you and sends a digest across your sessions and projects, which arrives on the quiet days too; it keeps a searchable copy of the trail off the machine that wrote it; it sends alerts to Slack, Discord, Telegram or email; and it can deny a tool call before it runs. The detectors are identical on both plans — we do not hold back detection to sell an upgrade.

What does a persona include, and is it a subscription?

A persona ($30 one-time) is a pre-configured OpenClaw setup — curated tools, skills, and MCP servers for your role. Apex ($40 one-time) merges every persona into one package. Personas are setup convenience, not the security product, and carry no recurring charge.

What is Clawmont Security (Guardrails) and what does it cost?

Clawmont Security — plan name "Guardrails" — is the paid rung. It reads your record for you, keeps a copy of it off the machine, alerts you off-machine, and can refuse a tool call before it runs. On Claude Code it inspects three boundaries locally (your prompt, the tool call, and the tool result) and denies at the tool call, which is the one boundary that can deny. It costs $9.99/month bundled with a persona or Apex, or $19.99/month standalone. Bundled and standalone are the same product; bundled is the setup-buyer price.

Does the paid plan let me undo what the agent did?

Not yet, and we would rather say so on the pricing page than in a changelog. Checkpoint and undo for a whole run is not built. What exists today is the record of everything that happened and a deny on part of the irreversible list — a recursive delete outside a build directory, a private key read, a .env going out over the wire. A force-push, a reset --hard and a secret going into a commit are still allowed even with enforcement on; we probed our own build on 2026-08-12 and that is what it did. Fixing that is the next thing we are building.

Is there a free trial?

Two ways to try it. Clawmont Free is not a trial at all: the record is free with no card and no expiry, so you can read your own traffic for as long as you like before deciding to pay for anything. Separately, the paid subscription includes a 7-day free trial on both the $9.99/mo bundled and $19.99/mo standalone rates, so you can run it against real work before you are charged. Personas and Apex are one-time purchases with no trial. After the trial, the subscription can be cancelled at any time with a pro-rata refund for the unused period.

Which coding agents does this support?

Claude Code, and only Claude Code. Adapters exist for Cursor, Codex CLI, Cline, Devin CLI and Aider, and none of them has been driven against a live attack yet, so we do not list them as supported — a written adapter is not a proven one. Continue.dev cannot work at all until Continue changes something upstream. The full state of every integration is published on the home page rather than summarised as a logo wall.

What is the refund policy?

Persona and Apex purchases are one-time licenses and final sale. Guardrails subscriptions are refunded pro-rata for the unused period when cancelled. Statutory EU/EEA consumer rights still apply.

Do my API keys ever leave my machine?

No. API keys are collected only in the terminal installer, stored in your OS keychain, and never sent to api.clawmont.com. The only thing that can leave your machine is opt-in, redacted, HMAC-signed alert metadata — and only if you enable the cloud alerts add-on.

Will Clawmont block my normal work?

Not unless you ask it to. Clawmont starts in monitor mode: everything is recorded to your local trail and nothing is denied, so you can see exactly what the brakes would have stopped on your own traffic before you turn them on. Denying happens at the tool-call boundary, and you can switch modes at any time. False-positive behaviour is measured and published on the security page rather than promised away.

What does Clawmont Security not do?

It is a detection layer, not a sandbox: it inspects agent activity and can deny tool calls, but it does not containerize your agent or filter syscalls, and a detection that misses means the call runs. We publish our detection numbers and known limitations on the security page instead of overstating what a detection layer can do. Pair it with OS-level isolation if you need containment.

More questions answered on the full FAQ page.