Built secure from minute one.
Agent HQ runs on a security stack of small specialized layers. Each one watches a specific surface so failures, leaks, and bad input never reach you.
Agent HQ runs on a security stack of small specialized layers. Each one watches a specific surface so failures, leaks, and bad input never reach you.
Gateway-keeper + claw-medic feed a green dot on the Home tab. Tap for status.
Claw-jobs and claw-cron show every automated task in the Schedule tab: name, frequency, last run, result, next run.
Claw-channel-watch puts a status dot on every connection card so you know what's online.
Claw-drift logs platform updates in Settings under System Updates.
Claw-audit and claw-monitor produce the full security audit and diagnostics view.
Starter and Starter+ see a simplified security score on Home.
Claw-sandbox isolates every code execution in a subprocess your agent cannot escape.
Claw-perms enforces file permission bits before any read or write your agent attempts.
Claw-allowlist gates every outbound HTTP request through a forward proxy. Unknown hosts are blocked.
Claw-vault stores credentials encrypted with rotation. Secrets never appear in chat or logs.
Claw-leak scans every outbound response for accidentally-leaked secrets and redacts before delivery.
Claw-throttle stops runaway loops and rate-limit spirals before they cost you anything.
Claw-resources caps memory, CPU, and process count per container. No agent can starve the host.
Claw-ssrf blocks cloud metadata endpoints and private network probes at the proxy boundary.
Claw-injection scans inbound payloads for shell-injection patterns and rejects them before execution.
Claw-tls rejects plain-HTTP requests to unknown hosts. HTTPS-only by default for outbound traffic.
Claw-encrypt protects credentials and customer data on disk with platform-managed keys.
Claw-forensics writes a structured audit log of every privileged action: who, what, when, from where.
Claw-reaper and claw-session-repair clean up dead processes and recover crashed sessions automatically.
Claw-pin locks dependencies. Claw-skills-lint validates every first-party skill before it loads.
Claw-drift watches for unexpected changes to configuration and platform state, and surfaces them in Settings.
Claw-channel-watch tracks every connected app's health so the dashboard always shows the truth.
The full security stack ships with every Agent HQ instance.
GET STARTED →