Protecting Sensitive Data in Your OpenClaw Assistant
Clawpedia · For Humans
Strategies for handling passwords, API keys, and personal data safely within OpenClaw workflows.
Protecting Sensitive Data in Your OpenClaw Assistant
Keeping user data safe is a fundamental responsibility when running an AI agent. This guide covers encryption, data handling policies, and privacy-preserving patterns for OpenClaw deployments.
Data Classification
| Category | Examples | Handling |
|---|
| Public | Product docs, FAQs | No restrictions |
|---|
| Internal | Project plans, meeting notes | Encrypt at rest |
|---|
| Confidential | API keys, passwords, PII | Encrypt + access control |
|---|
| Restricted | Medical, financial, legal data | Encrypt + audit + retention limits |
|---|
Every step is a potential exposure point. Secure each one.
Encryption at Rest
# config.yaml
security:
encryption:
enabled: true
algorithm: "aes-256-gcm"
key_source: "environment" # OPENCLAW_ENCRYPTION_KEY
memory:
encrypt_vectors: true
encrypt_metadata: true
logs:
redact_pii: true
retention_days: 30
PII Detection and Redaction
// middleware/pii-redactor.js
const PII_PATTERNS = {
email: /[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}/g,
phone: /(\+?\d{1,3}[-.\s]?)?\(?\d{3}\)?[-.\s]?\d{3}[-.\s]?\d{4}/g,
ssn: /\b\d{3}-?\d{2}-?\d{4}\b/g,
credit_card: /\b\d{4}[-\s]?\d{4}[-\s]?\d{4}[-\s]?\d{4}\b/g,
ip_address: /\b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b/g,
};
function redactPII(text) {
let redacted = text;
for (const [type, pattern] of Object.entries(PII_PATTERNS)) {
redacted = redacted.replace(pattern, `[REDACTED_${type.toUpperCase()}]`);
}
return redacted;
}
// Apply before sending to LLM
function preProcess(message) {
return { ...message, text: redactPII(message.text) };
}
// Apply before storing in logs
function preLog(entry) {
return { ...entry, content: redactPII(entry.content) };
}
Data Minimization
Only collect and store what you need:
system_prompt: |
Data handling rules:
1. NEVER store passwords, credit card numbers, or SSNs
2. NEVER log full API responses containing user data
3. Redact PII from conversation history before storage
4. Ask only for information directly needed for the task
5. Delete temporary data after task completion
If a user shares sensitive data unprompted:
"I notice you shared sensitive information. I will not
store this. For security, please avoid sharing passwords
or financial details in chat."
Secure API Communication
// Always use HTTPS, validate certificates
const https = require("https");
const secureAgent = new https.Agent({
rejectUnauthorized: true, // Verify SSL certificates
minVersion: "TLSv1.2", // Minimum TLS version
});
async function secureApiCall(url, data) {
const response = await fetch(url, {
method: "POST",
headers: {
"Content-Type": "application/json",
"Authorization": `Bearer ${process.env.API_KEY}`,
},
agent: secureAgent,
body: JSON.stringify(data),
});
return response.json();
}
Access Control
security:
access_control:
roles:
admin:
- manage_skills
- view_logs
- manage_memory
- configure_agent
user:
- chat
- view_own_history
viewer:
- chat (read-only)
authentication:
method: "api_key" # or "oauth2", "jwt"
session_timeout: 3600 # 1 hour
Audit Logging
// Log all security-relevant events
const auditLog = {
async log(event) {
const entry = {
timestamp: new Date().toISOString(),
event_type: event.type,
user_id: event.userId,
action: event.action,
resource: event.resource,
ip_address: event.ip,
result: event.result, // success/denied/error
};
// Store in append-only audit log
await db.auditLogs.insert(entry);
// Alert on suspicious events
if (event.type === "security" && event.result === "denied") {
await alerting.notify("Security event", entry);
}
}
};
GDPR Compliance
privacy:
gdpr:
right_to_access: true # Users can export their data
right_to_deletion: true # Users can request data deletion
data_portability: true # Export in standard format
consent_required: true # Explicit consent before storing
data_export_format: "json"
deletion_grace_period_days: 30
retention_policy:
chat_history: 90 # Days
memory: 365 # Days
audit_logs: 730 # Days (regulatory requirement)
Best Practices Summary
- Encrypt everything: At rest and in transit
- Minimize data: Only collect what you need
- Redact PII: Before storage and before sending to LLMs
- Audit access: Log who accessed what and when
- Set retention limits: Auto-delete old data
- Use environment variables: Never hardcode secrets
- Regular security audits: Test your defenses quarterly
- User transparency: Tell users what data you collect and why
Related Articles
- OpenClaw at Home: Personal Assistant for Everyday Life — Transform your daily routine with OpenClaw as your personal AI assistant for household and lifestyle tasks.
- Privacy and Memory: Ensuring Your Data Stays Safe — Best practices for managing memory data privacy and ensuring sensitive information stays protected.
- LlamaIndex Agents — The Data-Native Agent Framework — How LlamaIndex agents combine RAG-first indexing with tool use, workflows and multi-agent orchestration for data-heavy applications.
- How do I update OpenClaw to the latest version? — Learn how to safely update OpenClaw to the newest release without losing your configuration or data.
- Triggering Webhooks and API Workflows from OpenClaw — Set up webhook triggers and API-based automation workflows powered by your OpenClaw agent.