How to secure my OpenClaw instance and protect privacy?
Clawpedia · For Humans
Essential security practices to lock down your OpenClaw deployment and keep your data private and safe.
How to Secure My OpenClaw Instance and Protect Privacy
Security and privacy are core advantages of running your own AI assistant. OpenClaw gives you full control over your data, but proper configuration is essential to maximize protection. This guide covers everything from basic hardening to advanced security measures.
# UFW (Ubuntu)
sudo ufw default deny incoming
sudo ufw allow ssh
sudo ufw allow 443/tcp # HTTPS only
# Do NOT allow port 3000 directly
sudo ufw enable
2. Memory Encryption
memory:
encryption:
enabled: true
algorithm: aes-256-gcm
key_derivation: argon2id
# Key is derived from your master password
# Set encryption password
openclaw security set-encryption-key
# Enter master password: ********
# Confirm: ********
# → Memory encryption enabled with AES-256-GCM
# Verify encryption is active
openclaw security status
# Memory encryption: ✅ AES-256-GCM
# API keys: ✅ Encrypted at rest
# Dashboard auth: ✅ Enabled
3. Use Local Models for Maximum Privacy
The most private setup runs everything locally:
model:
provider: ollama
model: llama3.1:8b
endpoint: http://localhost:11434
# Zero data leaves your machine
# No API keys needed
# No third-party data retention
memory:
backend: sqlite
path: ~/.openclaw/memory.db
encryption:
enabled: true
gateway:
analytics: false # Disable telemetry
crash_reports: false # Disable crash reporting
4. API Key Security
# Store API keys securely (encrypted)
openclaw secret set OPENAI_API_KEY
# Enter value: ********
# → Stored securely in encrypted keystore
# Never put API keys in plain text config files
# Use environment variable references instead:
memory:
retention:
conversations: 90 # Delete conversation logs after 90 days
short_term: 7 # Short-term memory window
long_term: permanent # Keep learned facts permanently
auto_purge:
enabled: true
schedule: "0 3 * * 0" # Weekly cleanup at 3 AM Sunday
Security Checklist
Item
Command to Check
Status
Dashboard auth enabled
openclaw config get dashboard.auth.enabled
✅ / ❌
Memory encryption on
openclaw security status
✅ / ❌
HTTPS configured
Check nginx/reverse proxy
✅ / ❌
Firewall active
sudo ufw status
✅ / ❌
No hardcoded API keys
grep -r "sk-" ~/.openclaw/
Should be empty
Skill sandbox enabled
openclaw config get skills.sandbox.enabled
✅ / ❌
Analytics disabled
openclaw config get gateway.analytics
false
Regular backups
openclaw backup status
✅ / ❌
Security Audit
# Run the built-in security audit
openclaw security audit
# ✅ Dashboard authentication: enabled
# ✅ Memory encryption: AES-256-GCM
# ⚠️ Dashboard accessible from network (consider localhost-only)
# ❌ No HTTPS configured (critical for remote access)
# ✅ API keys encrypted at rest
# ✅ Skill sandbox: enabled
# ⚠️ 2 skills with shell-execute permission
# Score: 7/10
Tip: The biggest privacy win is using a local model via Ollama. This means your conversations, prompts, and data never leave your machine. Combined with memory encryption, you have an AI assistant that's as private as it gets.