
IronClaw
Officially listedA security-first open-source AI agent runtime built in Rust by NEAR AI.
IronClaw
IronClaw is a secure AI agent runtime from NEAR AI, built in Rust and created in response to OpenClaw's security flaws. OpenClaw has 9 CVE vulnerabilities and the ClawHavoc supply chain attack affected 9,000+ users—IronClaw addresses these with triple protection: WASM sandboxing, TEE encrypted enclaves, and credential isolation. It is led by Illia Polosukhin, co-author of the Transformer paper.
Core Capabilities
- WASM sandbox isolation: Every tool runs in its own WebAssembly container with capability-based permissions (FileRead/NetConnect/EnvRead require explicit grants)
- Encrypted credential vault: Credentials are stored in TEE encrypted enclaves; the LLM only receives placeholders and never sees raw keys
- Real-time leak detection: Outbound traffic is scanned for credential exfiltration attempts, with network allowlists restricting where data can go
- MCP protocol support: Compatible with Model Context Protocol servers, connecting to any MCP-compatible service
- Offline operation: Fully offline deployment with local Ollama and PostgreSQL—zero external dependencies
- Multi-channel deployment: Supports Telegram, Slack, Discord, WhatsApp, and a web gateway
Use Cases AI agent deployments handling sensitive information such as financial data, health records, and API keys. Suited to enterprise teams in regulated industries and security-conscious users migrating from OpenClaw. For personal calendars or social bots, OpenClaw remains the simpler choice.
Unique Advantages Five independent security boundaries (WASM sandbox, capability permissions, TEE enclave, network allowlist, Rust memory safety)—the most complete in its class. The 3.4MB binary starts in under 10ms with only 7.8MB of memory, far lighter than OpenClaw's Node.js runtime. The iron-port tool supports OpenClaw skill migration (22/30 convert automatically).
Editor's Review The security design is impressive—in testing, a known malicious OpenClaw skill was successfully blocked for lacking capability tokens. But 890 verified skills versus OpenClaw's 5,700+ means the ecosystem still lags, and initial setup requires auditing each skill's capability manifest—a test of patience. A strong fit for teams where security comes first, but be prepared for higher configuration complexity.
Pricing
### 💰 定价模式:免费增值 **起步价**:免费(开源自托管) #### 主要方案 - **自托管**:$0 - 完整功能,Apache 2.0 + MIT双协议 - **Starter**:$5/月 - 1代理实例,TEE托管 - **Basic**:$20/月 - 2代理实例,13M tokens - **Pro+**:$200/月 - 5代理实例,130M tokens,优先支持 #### 试用/其他信息 自托管需Rust 1.85+和PostgreSQL 15+。支持Homebrew、cargo install和Docker部署。 — Visit website
FAQ
Is IronClaw free?
It is open source and free (dual-licensed under Apache 2.0 and MIT), and self-hosting costs nothing. NEAR AI Cloud hosting ranges from $5/month (1 agent) to $200/month (5 agents + priority support).
What can IronClaw be used for?
Building and running secure AI agents, with MCP protocol support, hybrid search, multi-channel deployment, scheduled tasks, and dynamic tool construction. Its core value: agents that handle sensitive data without leaking credentials.
How does IronClaw differ from OpenClaw?
OpenClaw gives every skill full user permissions and stores credentials in plaintext. IronClaw isolates every tool in a WASM sandbox, encrypts credentials in a TEE, and enforces five security boundaries. The trade-off is a smaller skill ecosystem (890 vs 5,700+) and more complex configuration.
Can IronClaw migrate OpenClaw skills?
Yes. In testing, the iron-port migration tool auto-converted 22 of 30 skills, 5 needed manual adjustment, and 3 were incompatible because they relied on unrestricted shell access.
How does IronClaw defend against prompt injection attacks?
Credentials are isolated in TEE-encrypted storage and the LLM receives only placeholders; keys are injected solely into allowlisted HTTP requests. Combined with pattern detection, content sanitization, and policy enforcement, prompt injection is structurally blocked from stealing credentials.
Is IronClaw suitable for individual users?
Technically yes, but it is designed for security-sensitive scenarios. For a personal calendar or social bot, OpenClaw is simpler with a richer ecosystem. IronClaw fits scenarios involving financial data, health records, or API keys with real financial risk.