Security

Your agent can reach
everything you can.

It reads your files, calls your APIs, and uses your credentials. Clawmont is the security layer that checks every prompt, tool call, and result before your agent acts — on your machine, before anything reaches the model. We publish our detection numbers, bypasses included, and the code is yours to read.

Measured detection rates

The exact numbers, caveats included

78.7%
detection on the tested corpus
2,324 adversarial vectors
~33%
on novel, unseen attacks
fresh-corpus generalization test
0
false positives
across 62 clean negatives
0
unexpected bypasses
in the tested corpus run

The honest reading: 78.7% is measured against a fixed corpus the detectors were iterated on, so it overstates performance on attacks they have never seen. On fresh, never-seen plain-English attacks the deterministic rate drops to roughly one-third; a cost-gated LLM judge backstops that long tail. This is best-effort defense-in-depth, not a guarantee. Review the named Clawmont AI Agent Runtime Security Benchmark or its machine-readable JSON distribution; measurement dates, misses, and caveats are included.

Verified, not claimed

Four security pillars. Each one bypass-tested.

Each one runs in-process.

Input rail, tool dispatch, tool response, and model output - defense-in-depth across the full agent loop. A fast, deterministic layer catches known attack shapes in milliseconds; an AI judge reviews the ambiguous and novel cases it flags. Each pillar is independently bypass-tested against the OWASP LLM Top 10 and a 2,300-scenario red-team corpus, with raw measurements published - full methodology at security.clawmont.com.

01

Input rail

A booby-trapped web page or PR comment tells your agent to hand over your keys. The input rail reads every prompt first and is built to catch the injected instruction - even when it is hidden behind encoding or obfuscation - before the model ever sees it.

02

Tool dispatch

rm -rf. curl | bash. DROP TABLE. Every tool call is screened before it runs; destructive or high-risk actions get refused or held for your approval, with a labelled alert - so one bad instruction does not become a wiped disk.

03

Tool response

A file or an API response comes back with hidden instructions buried inside it. Tool response screens every result before the model can read it - built to catch smuggled commands and quiet attempts to exfiltrate your local data before the model acts on them.

04

Model output

The last checkpoint. Every reply is screened before it reaches you for leaked secrets and unsafe instructions - and every prompt, tool call, and refusal lands in a tamper-evident log you can audit.

File-handling posture

What we don't scan, what we do block

DON'T SCAN

Your file contents

We don't read the files you upload. They go to the model unchanged, flagged "not scanned" in your chat. Your data is yours.

DO BLOCK

Model-initiated downloads

If the model tries to download something you didn't ask for, Clawmont is built to block it. A download should start with you — a command, a click, a clear request — never the model on its own.

Guides

Practical AI agent security guides

Start with the AI agent security guide hub, then open the specific guide that matches the question.

Egress

What leaves your machine?

Almost nothing — and anything that does is redacted on your machine before it leaves.

API keys Never
Prompts Never
Code & files Never
Telemetry Opt-in only
Alerts (only with Guardrails) HMAC-signed, redacted

Aligned with

OWASP LLM Top 10 (2025) OWASP Agentic Top 10 — detection coverage on 8/10 risks NCSC AI Cyber Security (2024) Row-by-row mapping in source

How we compare

Clawmont Guardrails vs the field

Most AI security is either nonexistent or locked behind a vendor cloud you can't audit. Clawmont runs on your machine, publishes its detection rates, and lets you verify every claim.

Feature Typical AI Wrapper Standard Provider Clawmont
API key handling Keys proxied through vendor servers ~Keys stored in vendor cloud Keys never leave your machine — stored in your OS keychain
Input inspection None — prompts forwarded as-is ~Basic keyword blocklist Obfuscation-aware scanning across all 4 ports
Tool-call guarding No tool-level controls ~Model-level allow/deny only Per-tool firewall with schema validation
Credential scanning Not supported ~Optional, cloud-side only In-process, every prompt and tool call
Sensitive-path protection No path-level controls ~Coarse directory blocklist Symlink-aware path guard (blocks ~/.ssh, ~/.aws, etc.)
Audit trail No logging ~Cloud-only logs, vendor-accessible Hash-chained local log + HMAC-signed cloud alerts
Detection transparency No public benchmarks ~Undisclosed detection rates Published openly — 2,300-scenario corpus, bypasses included
Model compatibility Vendor-locked to one provider ~2–3 supported providers Any model — Anthropic, OpenAI, Ollama, OpenRouter

All of it ships in one layer — $9.99/mo bundled with any persona or Apex, or $19.99/mo standalone. See the standalone plan ↓

Generic archetypes, not named products. Clawmont is source-available under BUSL-1.1 — not a black box. Detection rates are corpus-specific and published at security.clawmont.com.

The security product

Guardrails — the security layer

The four security pillars plus cloud alerts, a hosted audit trail, and a daily digest. Bundle it with a persona or run it on its own — no model setup, just the security layer in front of whatever model your OpenClaw gateway already uses.

Bundled with a persona

$9.99/mo

Pick a persona or Apex, add Guardrails at checkout

  • All four pillars — tool-call guarding, sensitive-path protection, obfuscation-aware input inspection, credential scanning
  • Real-time alerts to Slack, Discord, Telegram, or email
  • Searchable 90-day hosted audit trail + daily digest
  • Works with any model — Anthropic, OpenAI, Ollama, OpenRouter

Standalone price. Already buying a persona? Add Guardrails at checkout for just $9.99/mo. Cancel anytime — pro-rata refund per refund policy. Compare with persona tiers →

Licensing

Clawmont is source-available under the Business Source License 1.1, with a change date of 2028-05-08 to Apache 2.0.

Read the full license grant in our Terms of Service; the BUSL-1.1 text ships in the LICENSE file with the source.

Clawmont is a defense-in-depth layer, not a guarantee — no security product can guarantee complete protection. Honest limitations are documented in the Security Disclaimer.

Go deeper

Looking for the product page? Start with AI agent security runtime or MCP security for agents. Need the citable definition? Read AI agent runtime security. Securing OpenClaw specifically? Read the OpenClaw security guide. New to the space? Start with the agentic security guide or the AI agent security glossary. Comparing approaches? Read runtime security vs static analysis, guardrails vs sandboxes vs gateways, or Clawmont vs AgentKeeper. The blog covers MCP tool-call security, the OWASP LLM Top 10 for agents, and what 22 Claude Code security advisories teach about defending autonomous agents.

Start protecting today.

Guardrails Standalone — $19.99/mo. Three minutes to install, cancel anytime.

Compare all plans Try the playground