Security & Compliance

The Vault

Every build ships with verifiable compliance documentation. Zero trust isn't a feature — it's the architecture.

Zero-Trust Compliance Framework

All OpenClaw builds are designed with zero-trust principles: no implicit trust, continuous verification, least-privilege access. Every component is auditable and every connection is encrypted.

VERIFIED

Data Encryption

AES-256-GCM

All data at rest and in transit is encrypted with hardware-accelerated AES-256-GCM. Keys never leave the device.

VERIFIED

Zero Telemetry

PRIVACY-FIRST

No usage data, analytics, or telemetry is collected. No phone-home capabilities. Fully air-gappable.

VERIFIED

Supply Chain Audit

SBOM v2.3

Full software bill of materials for every firmware and driver. Verifiable provenance for all components.

VERIFIED

Secure Boot

UEFI 2.10

Hardware-rooted secure boot chain. TPM 2.0 attestation with measured boot for firmware integrity.

VERIFIED

Network Isolation

VLAN/μSEG

Hardware-level network segmentation. Optional air-gap mode with physical kill switch for all radios.

PENDING

SOC 2 Type II

AICPA

Organizational security controls are audited annually. Report available upon request under NDA.