GoogleGoogle 4.6TrustPilotTrustPilot 4.9

Built to be boringly safe 🔒

Encrypted end-to-end, per-workspace isolated, audit-logged, monitored by the engineers who wrote the runtime. The security stack you’d expect from a much bigger company — without the compliance theatre.

How we keep you safe
Six things built into every workspace, on every plan, from the free tier up.
Encrypted end-to-end

Every request is served over TLS 1.3. Secrets, persona files and chat history are encrypted at rest with per-workspace envelope keys.

Per-workspace isolation

Every hosted agent runs in its own container with a dedicated key ring. One workspace can never read another workspace's traffic, secrets or logs.

Provider keys never leave us

We hold every model provider account. Your requests never touch a third-party API key — you talk to Claws, we talk to the model.

Least-privilege by default

Team members get workspace-scoped roles. Personal access tokens carry the narrowest scope that gets the job done, and can be revoked in one click.

Audit-logged everywhere

Every login, secret access, deploy and admin action lands in an append-only audit log you can export from the console.

Real engineers on call

The people who wrote the runtime carry the pager. Security incidents get a human eye within the hour, day or night, with a public postmortem within a week.

Standards & compliance
The specifics for your security team’s spreadsheet.
TLS 1.3
All ingress + egress.
AES-256-GCM
Envelope encryption at rest.
SOC 2 Type II
Aligned; report in-progress.
GDPR + CCPA
DPA available on request.
PCI DSS
Card data handled entirely by Stripe.
Zero-knowledge secrets
Provider keys sealed; only the runtime unlocks them.

Responsible disclosure and a real bounty.

If you find a vulnerability, tell us first. Email security@claws.io with a description and a proof of concept. Confirmed reports get an acknowledgement within 24 hours, a fix ETA within 72, and a bounty scaled to severity.

We don’t lawyer bug reporters. Test only against your own workspace, respect user privacy, and we’ll work together in good faith.

Frequently asked
Straight answers to the things your security team keeps asking us.
Where is my data stored?
In the EU, on hardware we own and operate. No shared multi-tenant DB rows across workspaces. Data residency options are available on Enterprise.
Can I bring my own API keys?
For most models, no — we route through the single Claws endpoint using our provider accounts, so you skip per-provider key management. Enterprise workspaces can attach BYOK for specific providers with per-provider isolation.
What happens to my data if I delete my workspace?
Everything — chat history, personas, secrets, container state — is scheduled for hard-delete within 30 days. Encrypted backups roll off within 90.
Do you train on my prompts?
No. Requests and responses are never used for model training, ours or any third party. That's a contractual commitment on every tier.
How do I report a vulnerability?
security@claws.io with a description and proof-of-concept. Confirmed reports get an acknowledgement within 24 hours and a fix ETA within 72.

Need a DPA, SOC 2 report or a signed questionnaire?

Email security@claws.io — we’ll send the current pack within a business day.