What you are actually setting up
OpenClaw is an open-source (MIT) agent that you host yourself. Its documentation describes it as a self-hosted gateway that connects chat apps such as WhatsApp, Telegram, Slack, Discord, Signal, Microsoft Teams and Google Chat to AI agents. The gateway holds sessions, routing and channel connections; the agent uses a language model, skills (SKILL.md files), local memory and scheduled jobs.
Its security documentation sets one rule that shapes every setup: a gateway is one trust boundary, meant for a single operator or a team whose members trust each other. It is not a boundary between users who do not trust each other. If two groups should not see each other's data, they need separate gateways with separate credentials.
OpenClaw hosting: where it should run
The documentation lists macOS, Linux, Windows (through WSL2), a VPS and Docker. For a company, the real question is who controls the machine, the network and the data.
| Option | Good for | What you must add |
|---|---|---|
| Your own servers (on-premises) | Sensitive data, regulated sectors, integration with internal systems | Hardware, patching, backups and someone on call |
| Private cloud or your cloud account | Most companies: control plus cloud operations | Network segmentation, identity, secrets manager and logging in your account |
| A VPS | A first pilot with non-sensitive data | Firewall, no public dashboard, hardening; rarely right for production data |
| An employee's laptop | Personal experiments only | Not suitable for company agents: no isolation, no continuity, mixed personal and company data |
Plan one gateway per trust boundary: a department, a client or a sensitivity level, not one shared gateway for everyone.
The ten decisions
- Where it runs: on-premises, private cloud or a VPS, and how many gateways, one per trust boundary.
- Which model, and what leaves the network: OpenClaw works with hosted models (Anthropic, OpenAI, Google, Mistral and others) and with models served on your own infrastructure. Every prompt sent to a hosted model leaves your network, so decide per task which data may go out and which requires a local model.
- Channels: which messaging apps the agent listens to and who may write to it. The documentation offers pairing, allow-lists, open and disabled modes for direct messages, and mention gates for groups. For a company, start with allow-lists.
- Identity per agent: each agent gets its own service accounts and the narrowest OAuth scopes its task needs. Never a person's account, never administrator credentials.
- Secrets: API keys and tokens live in a secrets manager and reach the agent at runtime. According to Wikipedia, OpenClaw 2.0 (August 2026) was criticized for not encrypting Secret Store values at rest, so do not rely on defaults.
- Isolation: run the agent and its tools in a sandbox (container, separate machine or segmented network), away from critical systems. According to Wikipedia, version 2.0 does not enable sandboxing for untrusted code automatically; turn it on and choose the most restrictive mode that works.
- Skills: the documentation says to treat third-party skills as untrusted code and read them before enabling them. Review every skill, pin its version, and keep an internal list of approved skills.
- Logging: record each instruction, tool call, data touched and result, and store the log where the agent cannot change it.
- Update policy: pin the OpenClaw version, test upgrades in a staging gateway, and patch security releases quickly. CVE-2026-25253, a one-click token-theft flaw rated CVSS 8.8, was fixed in version 2026.1.29 on January 30, 2026; instances that were not updated stayed exposed.
- Who operates it: a named owner for each agent's process and a named operator for the platform (updates, permissions, logs, incidents). Without both, the agent drifts.
Common setup mistakes
- Exposing the gateway or dashboard to the internet. In February 2026, SecurityScorecard's STRIKE team reported about 42,900 unique IP addresses hosting OpenClaw control panels across 82 countries. Current documentation says the gateway binds to loopback on regular hosts, but container images default to an exposed bind that must be paired with authentication. Keep the dashboard private and reach it through a VPN or a zero-trust access layer.
- Broad OAuth scopes. Granting full mailbox, calendar or drive access "to get it working" means any prompt injection inherits that access. Start read-only and add write scopes one by one.
- Unreviewed community skills. Palo Alto Networks' Unit 42 summarized research showing that in February 2026 Koi Security found 341 malicious skills on ClawHub, many of them installing a macOS infostealer. ClawHub added VirusTotal scanning afterwards, but scanning does not replace your own review.
- Secrets in memory or configuration files. Credentials pasted into chats, prompts or memory files end up in transcripts and on disk. Use a secrets manager and rotate anything that leaked.
- One gateway for everyone. Mixing teams, clients or sensitivity levels in a single gateway breaks the trust model the project itself documents.
- No owner and no off switch. An agent nobody owns, with no cost limits and no tested way to stop it, is an incident waiting to happen.
A short checklist before go-live
| Check | Done when |
|---|---|
| Network | The gateway and dashboard are not reachable from the internet; access goes through a VPN or zero-trust layer |
| Audit | openclaw security audit runs clean, and is scheduled to run again after every change |
| Channels | Direct messages use pairing or an allow-list; groups require a mention |
| Identity | Each agent has its own service accounts with minimal scopes |
| Secrets | No credential lives in prompts, memory or plain-text configuration |
| Sandbox | Tools run isolated, in the most restrictive mode that works |
| Skills | Every skill is reviewed, pinned and on the approved list |
| Approvals | Payments, external messages, deletions and production changes need a person |
| Logs | Actions are logged outside the agent's reach and someone reviews them |
| Operations | A named owner and operator, a version policy, cost limits and a tested shutdown |
How Appropia sets up OpenClaw
We deploy OpenClaw with AgenticOS, Appropia's product built on OpenClaw, in your cloud account, a private cloud or your own servers. AgenticOS adds per-agent permissions, human approval for sensitive actions and a record of every action, following our public AgenticOS Security Framework.
We start with a 30-day pilot on one process, in an isolated environment with limited data and human approval on everything, and widen permissions only when the pilot shows the agent behaves as expected.
Frequently asked questions
How long does OpenClaw setup take?+
The software install is quick. A company setup with isolation, identity, secrets, reviewed skills and logging is part of a pilot that we usually measure over about 30 days.
Where should we host OpenClaw?+
On infrastructure you control: your own servers, a private cloud or your cloud account. A VPS can work for a pilot with non-sensitive data. Never expose the gateway or dashboard to the internet.
Can OpenClaw run without sending data to an external model?+
Yes. It supports models served on your own infrastructure as well as hosted ones. Many companies combine both and decide per task which data may leave the network.
Is the default OpenClaw configuration safe for a company?+
Current defaults are more conservative, but they are written for a single trusted operator. A company still has to add per-agent identity, a secrets manager, sandboxing, skill review, logging and an update policy.
Can Appropia set up OpenClaw for us?+
Yes. We deploy it with AgenticOS in your infrastructure, run a measured pilot and can operate it afterwards.
Keep reading
Sources
- OpenClaw documentation: overview
- OpenClaw documentation: gateway security
- OpenClaw documentation: skills
- OpenClaw documentation: model providers
- OpenClaw, Wikipedia (version 2.0 criticism)
- The Hacker News: OpenClaw bug enables one-click remote code execution (CVE-2026-25253)
- GBHackers: SecurityScorecard STRIKE finds exposed OpenClaw control panels
- Unit 42: OpenClaw's skill marketplace and the emerging AI supply chain threat
Information as of October 5, 2026.