Security
Your agent can reach
everything you can.
It reads your files, calls your APIs, and uses your credentials. Clawmont is the security layer that checks every prompt, tool call, and result before your agent acts — on your machine, before anything reaches the model. We publish our detection numbers, bypasses included, and the code is yours to read.
Measured detection rates
The exact numbers, caveats included
The honest reading: 78.7% is measured against a fixed corpus the detectors were iterated on, so it overstates performance on attacks they have never seen. On fresh, never-seen plain-English attacks the deterministic rate drops to roughly one-third; a cost-gated LLM judge backstops that long tail. This is best-effort defense-in-depth, not a guarantee. Review the named Clawmont AI Agent Runtime Security Benchmark or its machine-readable JSON distribution; measurement dates, misses, and caveats are included.
Verified, not claimed
Four security pillars. Each one bypass-tested.
Each one runs in-process.
Input rail, tool dispatch, tool response, and model output - defense-in-depth across the full agent loop. A fast, deterministic layer catches known attack shapes in milliseconds; an AI judge reviews the ambiguous and novel cases it flags. Each pillar is independently bypass-tested against the OWASP LLM Top 10 and a 2,300-scenario red-team corpus, with raw measurements published - full methodology at security.clawmont.com.
Input rail
A booby-trapped web page or PR comment tells your agent to hand over your keys. The input rail reads every prompt first and is built to catch the injected instruction - even when it is hidden behind encoding or obfuscation - before the model ever sees it.
Tool dispatch
rm -rf. curl | bash. DROP TABLE. Every tool call is screened before it runs; destructive or high-risk actions get refused or held for your approval, with a labelled alert - so one bad instruction does not become a wiped disk.
Tool response
A file or an API response comes back with hidden instructions buried inside it. Tool response screens every result before the model can read it - built to catch smuggled commands and quiet attempts to exfiltrate your local data before the model acts on them.
Model output
The last checkpoint. Every reply is screened before it reaches you for leaked secrets and unsafe instructions - and every prompt, tool call, and refusal lands in a tamper-evident log you can audit.
File-handling posture
What we don't scan, what we do block
Your file contents
We don't read the files you upload. They go to the model unchanged, flagged "not scanned" in your chat. Your data is yours.
Model-initiated downloads
If the model tries to download something you didn't ask for, Clawmont is built to block it. A download should start with you — a command, a click, a clear request — never the model on its own.
Guides
Practical AI agent security guides
Start with the AI agent security guide hub, then open the specific guide that matches the question.
Guide
How to Detect Prompt Injection Attacks in AI Agents
Practical guide to direct and indirect prompt injection, tool-using agents, runtime inspection, and where Clawmont fits.
Guide
MCP Security Best Practices for AI Agent Deployments
MCP server trust, tool authorization, input validation, runtime monitoring, credential scoping, and audit logging.
Guide
AI Agent Security Tools Compared (2026)
Neutral comparison of model safety, classifiers, runtime inspection, API gateways, sandboxing, and supply-chain scanning.
Egress
What leaves your machine?
Almost nothing — and anything that does is redacted on your machine before it leaves.
Aligned with
How we compare
Clawmont Guardrails vs the field
Most AI security is either nonexistent or locked behind a vendor cloud you can't audit. Clawmont runs on your machine, publishes its detection rates, and lets you verify every claim.
| Feature | Typical AI Wrapper | Standard Provider | Clawmont |
|---|---|---|---|
| API key handling | ✗Keys proxied through vendor servers | ~Keys stored in vendor cloud | ✓Keys never leave your machine — stored in your OS keychain |
| Input inspection | ✗None — prompts forwarded as-is | ~Basic keyword blocklist | ✓Obfuscation-aware scanning across all 4 ports |
| Tool-call guarding | ✗No tool-level controls | ~Model-level allow/deny only | ✓Per-tool firewall with schema validation |
| Credential scanning | ✗Not supported | ~Optional, cloud-side only | ✓In-process, every prompt and tool call |
| Sensitive-path protection | ✗No path-level controls | ~Coarse directory blocklist | ✓Symlink-aware path guard (blocks ~/.ssh, ~/.aws, etc.) |
| Audit trail | ✗No logging | ~Cloud-only logs, vendor-accessible | ✓Hash-chained local log + HMAC-signed cloud alerts |
| Detection transparency | ✗No public benchmarks | ~Undisclosed detection rates | ✓Published openly — 2,300-scenario corpus, bypasses included |
| Model compatibility | ✗Vendor-locked to one provider | ~2–3 supported providers | ✓Any model — Anthropic, OpenAI, Ollama, OpenRouter |
All of it ships in one layer — $9.99/mo bundled with any persona or Apex, or $19.99/mo standalone. See the standalone plan ↓
Generic archetypes, not named products. Clawmont is source-available under BUSL-1.1 — not a black box. Detection rates are corpus-specific and published at security.clawmont.com.
The security product
Guardrails — the security layer
The four security pillars plus cloud alerts, a hosted audit trail, and a daily digest. Bundle it with a persona or run it on its own — no model setup, just the security layer in front of whatever model your OpenClaw gateway already uses.
- ✓All four pillars — tool-call guarding, sensitive-path protection, obfuscation-aware input inspection, credential scanning
- ✓Real-time alerts to Slack, Discord, Telegram, or email
- ✓Searchable 90-day hosted audit trail + daily digest
- ✓Works with any model — Anthropic, OpenAI, Ollama, OpenRouter
Standalone price. Already buying a persona? Add Guardrails at checkout for just $9.99/mo. Cancel anytime — pro-rata refund per refund policy. Compare with persona tiers →
Licensing
Clawmont is source-available under the Business Source License 1.1, with a change date of 2028-05-08 to Apache 2.0.
Read the full license grant in our Terms of Service; the BUSL-1.1 text ships in the LICENSE file with the source.
Clawmont is a defense-in-depth layer, not a guarantee — no security product can guarantee complete protection. Honest limitations are documented in the Security Disclaimer.
Go deeper
Looking for the product page? Start with AI agent security runtime or MCP security for agents. Need the citable definition? Read AI agent runtime security. Securing OpenClaw specifically? Read the OpenClaw security guide. New to the space? Start with the agentic security guide or the AI agent security glossary. Comparing approaches? Read runtime security vs static analysis, guardrails vs sandboxes vs gateways, or Clawmont vs AgentKeeper. The blog covers MCP tool-call security, the OWASP LLM Top 10 for agents, and what 22 Claude Code security advisories teach about defending autonomous agents.
Start protecting today.
Guardrails Standalone — $19.99/mo. Three minutes to install, cancel anytime.