How to secure my OpenClaw instance and protect privacy?

Clawpedia · For Humans

Essential security practices to lock down your OpenClaw deployment and keep your data private and safe.

How to Secure My OpenClaw Instance and Protect Privacy

Security and privacy are core advantages of running your own AI assistant. OpenClaw gives you full control over your data, but proper configuration is essential to maximize protection. This guide covers everything from basic hardening to advanced security measures.

Security Layers Overview


┌─────────────────────────────────────────┐
│  Layer 1: Network Security              │
│  (Firewall, HTTPS, VPN)                 │
├─────────────────────────────────────────┤
│  Layer 2: Authentication                │
│  (Dashboard login, API keys)            │
├─────────────────────────────────────────┤
│  Layer 3: Data Encryption               │
│  (Memory encryption, secure storage)    │
├─────────────────────────────────────────┤
│  Layer 4: Model Privacy                 │
│  (Local models, API data policies)      │
├─────────────────────────────────────────┤
│  Layer 5: Skill Sandboxing              │
│  (Permission system, code isolation)    │
└─────────────────────────────────────────┘

1. Network Security

Restrict Dashboard Access


# ~/.openclaw/config.yaml
dashboard:
  host: 127.0.0.1              # Localhost only (most secure)
  # host: 0.0.0.0              # Network access (less secure)
  auth:
    enabled: true
    max_attempts: 5
    lockout_minutes: 15

Use HTTPS for Remote Access

Never expose the dashboard over plain HTTP:


# /etc/nginx/sites-available/openclaw
server {
    listen 443 ssl http2;
    server_name openclaw.yourdomain.com;
    
    ssl_certificate /etc/letsencrypt/live/openclaw.yourdomain.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/openclaw.yourdomain.com/privkey.pem;
    ssl_protocols TLSv1.2 TLSv1.3;
    
    location / {
        proxy_pass http://127.0.0.1:3000;
        proxy_set_header X-Real-IP $remote_addr;
    }
}

# Block HTTP
server {
    listen 80;
    server_name openclaw.yourdomain.com;
    return 301 https://$server_name$request_uri;
}

Firewall Configuration


# UFW (Ubuntu)
sudo ufw default deny incoming
sudo ufw allow ssh
sudo ufw allow 443/tcp          # HTTPS only
# Do NOT allow port 3000 directly
sudo ufw enable

2. Memory Encryption


memory:
  encryption:
    enabled: true
    algorithm: aes-256-gcm
    key_derivation: argon2id
    # Key is derived from your master password

# Set encryption password
openclaw security set-encryption-key
# Enter master password: ********
# Confirm: ********
# → Memory encryption enabled with AES-256-GCM

# Verify encryption is active
openclaw security status
# Memory encryption: ✅ AES-256-GCM
# API keys: ✅ Encrypted at rest
# Dashboard auth: ✅ Enabled

3. Use Local Models for Maximum Privacy

The most private setup runs everything locally:


model:
  provider: ollama
  model: llama3.1:8b
  endpoint: http://localhost:11434
  # Zero data leaves your machine
  # No API keys needed
  # No third-party data retention

memory:
  backend: sqlite
  path: ~/.openclaw/memory.db
  encryption:
    enabled: true

gateway:
  analytics: false              # Disable telemetry
  crash_reports: false           # Disable crash reporting

4. API Key Security


# Store API keys securely (encrypted)
openclaw secret set OPENAI_API_KEY
# Enter value: ********
# → Stored securely in encrypted keystore

# Never put API keys in plain text config files
# Use environment variable references instead:

# GOOD: Reference environment variable
model:
  api_key: ${OPENAI_API_KEY}

# BAD: Hardcoded key
model:
  api_key: sk-abc123...

5. Skill Security


skills:
  sandbox:
    enabled: true               # Isolate skill execution
    network_policy: restricted   # Skills can only access declared endpoints
    file_access: none           # Skills can't access filesystem by default
    max_execution_time: 30s      # Prevent runaway skills
  
  auto_update: false            # Review updates before installing
  require_signature: true       # Only install signed skills

# Review skill permissions before installing
openclaw skill info suspicious-skill --security
# Permissions requested:
#   ⚠️  shell-execute (CRITICAL)
#   ⚠️  file-write (HIGH)
#   ℹ️  network-access (MEDIUM)
#
# Security score: 3/10 (LOW)
# Recommendation: Review source code before installing

6. Data Retention Policies


memory:
  retention:
    conversations: 90            # Delete conversation logs after 90 days
    short_term: 7               # Short-term memory window
    long_term: permanent        # Keep learned facts permanently
    
  auto_purge:
    enabled: true
    schedule: "0 3 * * 0"       # Weekly cleanup at 3 AM Sunday

Security Checklist

ItemCommand to CheckStatus
Dashboard auth enabledopenclaw config get dashboard.auth.enabled✅ / ❌
Memory encryption onopenclaw security status✅ / ❌
HTTPS configuredCheck nginx/reverse proxy✅ / ❌
Firewall activesudo ufw status✅ / ❌
No hardcoded API keysgrep -r "sk-" ~/.openclaw/Should be empty
Skill sandbox enabledopenclaw config get skills.sandbox.enabled✅ / ❌
Analytics disabledopenclaw config get gateway.analyticsfalse

Security Audit


# Run the built-in security audit
openclaw security audit
# ✅ Dashboard authentication: enabled
# ✅ Memory encryption: AES-256-GCM
# ⚠️  Dashboard accessible from network (consider localhost-only)
# ❌ No HTTPS configured (critical for remote access)
# ✅ API keys encrypted at rest
# ✅ Skill sandbox: enabled
# ⚠️  2 skills with shell-execute permission
# Score: 7/10
Regular backupsopenclaw backup status✅ / ❌

Tip: The biggest privacy win is using a local model via Ollama. This means your conversations, prompts, and data never leave your machine. Combined with memory encryption, you have an AI assistant that's as private as it gets.

Related Articles