# Security & Data Handling

We believe you deserve a clear picture of what MeetClaw sees, touches, and stores during your setup. No vague promises — just specifics.

## Architecture Overview

MeetClaw's service is a human-delivered, session-based professional service. We do not run a persistent SaaS platform that continuously accesses your environment. Here is how a typical engagement works:

1. You book a session. We agree on scope in writing before we start.
2. You grant temporary access to your machine or cloud environment (SSH, screen share, or similar).
3. Our engineer installs, configures, and hardens OpenClaw on your infrastructure — not ours.
4. We hand over a documented deployment and revoke/close all session access.
5. Your OpenClaw runs entirely on your own hardware or cloud. MeetClaw has no persistent back-channel into it.

After handover, **we have no access to your environment** unless you explicitly re-engage us for a follow-up session.

## What We See During Setup

During an active session, our engineers may temporarily view:

- Your operating system and environment configuration
- API keys or tokens needed to configure integrations (e.g. OpenAI key, messaging platform tokens)
- File system paths relevant to the OpenClaw installation
- Network configuration details relevant to the integration being wired

**We do not:** record sessions, take copies of your files, log your credentials, or retain any access after the session ends.

## Our Security Principles

**Least Privilege**  
We request only the minimum access required to complete the agreed setup. We do not request root or admin access unless strictly necessary and documented.

**Encrypted Channels Only**  
All credential sharing happens over encrypted channels — SSH, encrypted credential vaults, or end-to-end encrypted screen share. We never request credentials over email or plain-text chat.

**Separate Service Accounts**  
Our standard deployment creates dedicated service accounts for each OpenClaw integration, avoiding shared credentials and making future revocation straightforward.

**Credentials Not Retained**  
Any credentials we work with during setup are not stored in MeetClaw systems. After the session, you should rotate them as a standard practice.

**Sandboxed Agents**  
We configure OpenClaw's agent capabilities (file access, shell, browser) with the minimum scope your use case requires — not maximum-access by default.

## Recommended Customer Practices Post-Setup

After your session concludes, we recommend the following to maintain a strong security posture:

- **Rotate all credentials** shared during the session — API keys, tokens, and any temporary SSH keys
- **Review access logs** on your machine or cloud environment to confirm no unexpected access occurred
- **Restrict OpenClaw's network access** using firewall rules appropriate to your use case
- **Enable two-factor authentication** on any accounts whose tokens are used by OpenClaw
- **Periodically audit** the tools and integrations active in your OpenClaw instance
- **Keep OpenClaw updated** by following the official OpenClaw project release notes

## OpenClaw's Own Security Model

OpenClaw is a powerful self-hosted agent that can interact with your files, shell, browser, and messaging platforms. The OpenClaw project's own documentation and terms emphasise that users are responsible for:

- Securing their deployments
- Managing API keys and permissions
- Complying with all third-party platform policies

MeetClaw's hardening service is designed to give you the best possible starting configuration, but ongoing security is a shared responsibility that ultimately resides with you as the infrastructure owner.

## Security Contact & Responsible Disclosure

**Responsible Disclosure**  
If you discover a security vulnerability in MeetClaw's website or service delivery practices, please report it responsibly. We will acknowledge your report within 48 hours and aim to resolve confirmed issues within 30 days.

[security@meetclaw.ai](mailto:security@meetclaw.ai)
