| Confidential | Customer data, financials | Local models only, full encryption |
| Restricted | Passwords, PII, secrets | Never store in memory, auto-redact |
enterprise:
data_classification:
confidential_keywords:
- "revenue"
- "salary"
- "customer list"
restricted_keywords:
- "password"
- "ssn"
- "credit card"
policy:
confidential: encrypt_and_local
restricted: never_store
---
Compliance
Audit Logging
enterprise:
audit:
enabled: true
log_all_messages: true # Log every interaction
log_all_actions: true # Log every skill execution
retention: 365d # Keep audit logs for 1 year
destination:
type: syslog
host: siem.company.com
port: 514
format: cef # Common Event Format
Data Retention Policies
enterprise:
retention:
conversations: 90d # Auto-delete after 90 days
memory: 365d # Auto-delete unused memories after 1 year
logs: 365d
audit_logs: 2555d # 7 years for compliance
GDPR Compliance
enterprise:
gdpr:
enabled: true
data_export: true # Allow users to export their data
right_to_delete: true # Allow users to delete all their data
consent_required: true # Require consent before storing personal data
dpo_email: privacy@company.com
---
Network Security
API Gateway
enterprise:
network:
api_gateway:
url: https://gateway.company.com
rate_limit: 1000 # Requests per minute
ip_allowlist:
- "10.0.0.0/8" # Internal network only
outbound:
allowed_domains:
- "api.openai.com"
- "api.anthropic.com"
- "*.company.com"
proxy: http://proxy.company.com:8080
TLS Configuration
enterprise:
tls:
min_version: "1.2"
cert: /etc/openclaw/tls/cert.pem
key: /etc/openclaw/tls/key.pem
ca: /etc/openclaw/tls/ca.pem
client_auth: required # Mutual TLS
---
Multi-Tenant Deployment
For organizations with multiple teams or departments:
enterprise:
multi_tenant:
enabled: true
isolation: strict # strict or shared
tenants:
engineering:
model: gpt-4o
skills: [github-integration, docker-manager]
memory_isolation: true
marketing:
model: gpt-4o-mini
skills: [social-media-manager, analytics]
memory_isolation: true
support:
model: gpt-4o
skills: [customer-support]
memory_isolation: true
---
Incident Response
Prepare for security incidents:
enterprise:
incident_response:
auto_lockdown: true # Automatically disable on anomaly
anomaly_detection:
unusual_api_calls: 5x # 5x normal rate triggers alert
off_hours_usage: true # Alert on usage outside business hours
new_ip_address: true # Alert on access from new IP
contacts:
- email: security@company.com
severity: [critical, high]
- slack: "#security-alerts"
severity: [critical, high, medium]
---
Deployment Recommendations
| Environment | Recommendation |
| Development | Standard config, cloud models OK |
| Staging | Production-like security, test data only |
| Production | Full enterprise config, encrypted, audited |
| Air-gapped | Local models only, no external network access |
---
Tips
- Start with a pilot team before rolling out organization-wide.
- Use SSO from day one — managing individual accounts does not scale.
- Enable full audit logging for compliance and incident investigation.
- Choose enterprise AI plans from providers (OpenAI Enterprise, Anthropic) for data privacy guarantees.
- Run regular security assessments and penetration tests.
- Document everything — policies, configurations, and incident procedures.
---
Troubleshooting
| Problem | Solution |
| SSO authentication fails | Check certificate and IdP configuration |
| Users cannot access the agent | Verify LDAP group mapping |
| Audit logs not appearing | Check syslog destination and network access |