Skip to content

OpenClaw · Setup and hosting

OpenClaw setup for enterprises: decisions before you install.

Installing OpenClaw is quick. Setting it up for a company takes decisions: where it runs, which model it uses and what data leaves your network, which channels it listens to, which identity and permissions each agent gets, where secrets live, how it is isolated, which skills it may use, what gets logged, how it is updated and who operates it. Those choices, not the install command, decide whether the agent is an asset or a liability.

This is not a command-by-command tutorial; the official documentation covers that. It is the list of decisions we work through with clients before anything is installed. Appropia has implemented OpenClaw since February 2026 and runs dozens of agents in production for several clients.

Talk to our team

What you are actually setting up

OpenClaw is an open-source (MIT) agent that you host yourself. Its documentation describes it as a self-hosted gateway that connects chat apps such as WhatsApp, Telegram, Slack, Discord, Signal, Microsoft Teams and Google Chat to AI agents. The gateway holds sessions, routing and channel connections; the agent uses a language model, skills (SKILL.md files), local memory and scheduled jobs.

Its security documentation sets one rule that shapes every setup: a gateway is one trust boundary, meant for a single operator or a team whose members trust each other. It is not a boundary between users who do not trust each other. If two groups should not see each other's data, they need separate gateways with separate credentials.

OpenClaw hosting: where it should run

The documentation lists macOS, Linux, Windows (through WSL2), a VPS and Docker. For a company, the real question is who controls the machine, the network and the data.

OptionGood forWhat you must add
Your own servers (on-premises)Sensitive data, regulated sectors, integration with internal systemsHardware, patching, backups and someone on call
Private cloud or your cloud accountMost companies: control plus cloud operationsNetwork segmentation, identity, secrets manager and logging in your account
A VPSA first pilot with non-sensitive dataFirewall, no public dashboard, hardening; rarely right for production data
An employee's laptopPersonal experiments onlyNot suitable for company agents: no isolation, no continuity, mixed personal and company data

Plan one gateway per trust boundary: a department, a client or a sensitivity level, not one shared gateway for everyone.

The ten decisions

  • Where it runs: on-premises, private cloud or a VPS, and how many gateways, one per trust boundary.
  • Which model, and what leaves the network: OpenClaw works with hosted models (Anthropic, OpenAI, Google, Mistral and others) and with models served on your own infrastructure. Every prompt sent to a hosted model leaves your network, so decide per task which data may go out and which requires a local model.
  • Channels: which messaging apps the agent listens to and who may write to it. The documentation offers pairing, allow-lists, open and disabled modes for direct messages, and mention gates for groups. For a company, start with allow-lists.
  • Identity per agent: each agent gets its own service accounts and the narrowest OAuth scopes its task needs. Never a person's account, never administrator credentials.
  • Secrets: API keys and tokens live in a secrets manager and reach the agent at runtime. According to Wikipedia, OpenClaw 2.0 (August 2026) was criticized for not encrypting Secret Store values at rest, so do not rely on defaults.
  • Isolation: run the agent and its tools in a sandbox (container, separate machine or segmented network), away from critical systems. According to Wikipedia, version 2.0 does not enable sandboxing for untrusted code automatically; turn it on and choose the most restrictive mode that works.
  • Skills: the documentation says to treat third-party skills as untrusted code and read them before enabling them. Review every skill, pin its version, and keep an internal list of approved skills.
  • Logging: record each instruction, tool call, data touched and result, and store the log where the agent cannot change it.
  • Update policy: pin the OpenClaw version, test upgrades in a staging gateway, and patch security releases quickly. CVE-2026-25253, a one-click token-theft flaw rated CVSS 8.8, was fixed in version 2026.1.29 on January 30, 2026; instances that were not updated stayed exposed.
  • Who operates it: a named owner for each agent's process and a named operator for the platform (updates, permissions, logs, incidents). Without both, the agent drifts.

Common setup mistakes

  • Exposing the gateway or dashboard to the internet. In February 2026, SecurityScorecard's STRIKE team reported about 42,900 unique IP addresses hosting OpenClaw control panels across 82 countries. Current documentation says the gateway binds to loopback on regular hosts, but container images default to an exposed bind that must be paired with authentication. Keep the dashboard private and reach it through a VPN or a zero-trust access layer.
  • Broad OAuth scopes. Granting full mailbox, calendar or drive access "to get it working" means any prompt injection inherits that access. Start read-only and add write scopes one by one.
  • Unreviewed community skills. Palo Alto Networks' Unit 42 summarized research showing that in February 2026 Koi Security found 341 malicious skills on ClawHub, many of them installing a macOS infostealer. ClawHub added VirusTotal scanning afterwards, but scanning does not replace your own review.
  • Secrets in memory or configuration files. Credentials pasted into chats, prompts or memory files end up in transcripts and on disk. Use a secrets manager and rotate anything that leaked.
  • One gateway for everyone. Mixing teams, clients or sensitivity levels in a single gateway breaks the trust model the project itself documents.
  • No owner and no off switch. An agent nobody owns, with no cost limits and no tested way to stop it, is an incident waiting to happen.

A short checklist before go-live

CheckDone when
NetworkThe gateway and dashboard are not reachable from the internet; access goes through a VPN or zero-trust layer
Auditopenclaw security audit runs clean, and is scheduled to run again after every change
ChannelsDirect messages use pairing or an allow-list; groups require a mention
IdentityEach agent has its own service accounts with minimal scopes
SecretsNo credential lives in prompts, memory or plain-text configuration
SandboxTools run isolated, in the most restrictive mode that works
SkillsEvery skill is reviewed, pinned and on the approved list
ApprovalsPayments, external messages, deletions and production changes need a person
LogsActions are logged outside the agent's reach and someone reviews them
OperationsA named owner and operator, a version policy, cost limits and a tested shutdown

How Appropia sets up OpenClaw

We deploy OpenClaw with AgenticOS, Appropia's product built on OpenClaw, in your cloud account, a private cloud or your own servers. AgenticOS adds per-agent permissions, human approval for sensitive actions and a record of every action, following our public AgenticOS Security Framework.

We start with a 30-day pilot on one process, in an isolated environment with limited data and human approval on everything, and widen permissions only when the pilot shows the agent behaves as expected.

Frequently asked questions

How long does OpenClaw setup take?+

The software install is quick. A company setup with isolation, identity, secrets, reviewed skills and logging is part of a pilot that we usually measure over about 30 days.

Where should we host OpenClaw?+

On infrastructure you control: your own servers, a private cloud or your cloud account. A VPS can work for a pilot with non-sensitive data. Never expose the gateway or dashboard to the internet.

Can OpenClaw run without sending data to an external model?+

Yes. It supports models served on your own infrastructure as well as hosted ones. Many companies combine both and decide per task which data may leave the network.

Is the default OpenClaw configuration safe for a company?+

Current defaults are more conservative, but they are written for a single trusted operator. A company still has to add per-agent identity, a secrets manager, sandboxing, skill review, logging and an update policy.

Can Appropia set up OpenClaw for us?+

Yes. We deploy it with AgenticOS in your infrastructure, run a measured pilot and can operate it afterwards.

Keep reading

Sources

Information as of October 5, 2026.

Talk to our team

Planning an OpenClaw setup? Let's review the decisions with you.

WhatsApp
WhatsAppTalk to us