Protecting Sensitive Data in Your OpenClaw Assistant

Clawpedia · For Humans

Strategies for handling passwords, API keys, and personal data safely within OpenClaw workflows.

Protecting Sensitive Data in Your OpenClaw Assistant

Keeping user data safe is a fundamental responsibility when running an AI agent. This guide covers encryption, data handling policies, and privacy-preserving patterns for OpenClaw deployments.

Data Classification

CategoryExamplesHandling
PublicProduct docs, FAQsNo restrictions
InternalProject plans, meeting notesEncrypt at rest
ConfidentialAPI keys, passwords, PIIEncrypt + access control

What Data Does OpenClaw Handle?


┌─────────────────────────────────┐
│        Data Flow                 │
│                                  │
│  User Input ──→ Agent ──→ LLM   │
│       ↓           ↓        ↓    │
│  Chat History  Memory   API Call │
│  (local/DB)   (vector)  (cloud) │
└─────────────────────────────────┘
RestrictedMedical, financial, legal dataEncrypt + audit + retention limits

Every step is a potential exposure point. Secure each one.

Encryption at Rest


# config.yaml
security:
  encryption:
    enabled: true
    algorithm: "aes-256-gcm"
    key_source: "environment"  # OPENCLAW_ENCRYPTION_KEY
  memory:
    encrypt_vectors: true
    encrypt_metadata: true
  logs:
    redact_pii: true
    retention_days: 30

PII Detection and Redaction


// middleware/pii-redactor.js
const PII_PATTERNS = {
  email: /[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}/g,
  phone: /(\+?\d{1,3}[-.\s]?)?\(?\d{3}\)?[-.\s]?\d{3}[-.\s]?\d{4}/g,
  ssn: /\b\d{3}-?\d{2}-?\d{4}\b/g,
  credit_card: /\b\d{4}[-\s]?\d{4}[-\s]?\d{4}[-\s]?\d{4}\b/g,
  ip_address: /\b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b/g,
};

function redactPII(text) {
  let redacted = text;
  for (const [type, pattern] of Object.entries(PII_PATTERNS)) {
    redacted = redacted.replace(pattern, `[REDACTED_${type.toUpperCase()}]`);
  }
  return redacted;
}

// Apply before sending to LLM
function preProcess(message) {
  return { ...message, text: redactPII(message.text) };
}

// Apply before storing in logs
function preLog(entry) {
  return { ...entry, content: redactPII(entry.content) };
}

Data Minimization

Only collect and store what you need:


system_prompt: |
  Data handling rules:
  1. NEVER store passwords, credit card numbers, or SSNs
  2. NEVER log full API responses containing user data
  3. Redact PII from conversation history before storage
  4. Ask only for information directly needed for the task
  5. Delete temporary data after task completion
  
  If a user shares sensitive data unprompted:
  "I notice you shared sensitive information. I will not 
  store this. For security, please avoid sharing passwords 
  or financial details in chat."

Secure API Communication


// Always use HTTPS, validate certificates
const https = require("https");

const secureAgent = new https.Agent({
  rejectUnauthorized: true,  // Verify SSL certificates
  minVersion: "TLSv1.2",    // Minimum TLS version
});

async function secureApiCall(url, data) {
  const response = await fetch(url, {
    method: "POST",
    headers: {
      "Content-Type": "application/json",
      "Authorization": `Bearer ${process.env.API_KEY}`,
    },
    agent: secureAgent,
    body: JSON.stringify(data),
  });
  return response.json();
}

Access Control


security:
  access_control:
    roles:
      admin:
        - manage_skills
        - view_logs
        - manage_memory
        - configure_agent
      user:
        - chat
        - view_own_history
      viewer:
        - chat (read-only)
    
    authentication:
      method: "api_key"  # or "oauth2", "jwt"
      session_timeout: 3600  # 1 hour

Audit Logging


// Log all security-relevant events
const auditLog = {
  async log(event) {
    const entry = {
      timestamp: new Date().toISOString(),
      event_type: event.type,
      user_id: event.userId,
      action: event.action,
      resource: event.resource,
      ip_address: event.ip,
      result: event.result, // success/denied/error
    };
    
    // Store in append-only audit log
    await db.auditLogs.insert(entry);
    
    // Alert on suspicious events
    if (event.type === "security" && event.result === "denied") {
      await alerting.notify("Security event", entry);
    }
  }
};

GDPR Compliance


privacy:
  gdpr:
    right_to_access: true     # Users can export their data
    right_to_deletion: true   # Users can request data deletion
    data_portability: true    # Export in standard format
    consent_required: true    # Explicit consent before storing
    
  data_export_format: "json"
  deletion_grace_period_days: 30
  retention_policy:
    chat_history: 90          # Days
    memory: 365               # Days  
    audit_logs: 730           # Days (regulatory requirement)

Best Practices Summary

Related Articles