Core Principles

🔒

Your Credentials, Your Machine

Your AI API key and channel tokens are yours — they live in ~/.openclaw/openclaw.json on your machine. IronThread never has access to them.

🚹

Docker Isolation

The OpenClaw container runs in its own filesystem namespace. It can only access host resources through explicitly granted Docker flags or tools you configure.

🔌

No Persistent Connection Out

The container has no persistent outbound connection to IronThread's infrastructure. It calls your AI provider and your connected tools — nothing else.

🚀

Token-Based Dashboard Access

Mission Control uses a 48-character random hex token — not a password. Generated fresh on every install, shown only once at the end of setup.

How Data Moves

Data TypeWhere It Goes
Your AI API keySent only to your AI provider (Google, Anthropic, etc.) — never to IronThread.
Email content / calendar dataSent to your AI provider for processing, returned as a response. Not stored long-term.
Session transcriptsStored in the openclaw_data Docker volume on your machine only.
Vector embeddingsStored in SQLite/Chroma inside the Docker volume on your machine only.
IronThread infrastructureNo persistent connection. Nothing sent to install.ironthread.ai or any IronThread server.

Access Control

🔓
DM pairing policyUnknown senders require explicit approval before the assistant responds. Your assistant won't reply to strangers by default.
🌐
LAN-only dashboardMission Control binds to your LAN IP. Access remotely via router/VPN — no port forwarding to the internet required.
🔔
Rate limitingDashboard API: 10 attempts/min per IP, 5-minute lockout after failed attempts.
💻
Volume isolationThe openclaw_data volume is managed by Docker. Enable Docker volume encryption or LUKS/BitLocker for additional protection.

Enterprise Tier Additions

Enterprise customers get additional security controls: full audit trail of every action the assistant takes, compliance logging exportable to SIEM tools, and custom network isolation (air-gapped deployments available on request).
📋
Audit trailEvery tool call, document accessed, and message sent is logged with timestamp, agent, and input/output summary.
📈
Compliance exportLogs exportable as JSON for ingestion into Splunk, Datadog, or any SIEM.
🛠
Custom tool restrictionsSpecific tools can be disabled per-agent for security-sensitive deployments.
🔋
Air-gapped deploymentFully on-premise installation with no outbound connectivity. Contact [email protected].

vs. Cloud AI Assistants

Compare how IronThread handles your data versus subscription AI assistants that run entirely in the cloud:

IronThreadTypical Cloud AI
AI model runsOn your hardware (or your cloud VM)On the vendor's servers
Your data accessible by vendorNo — never leaves your infrastructureYes — for model training and processing
Credentials accessible by vendorNo — credentials stay on your machineYes — stored on vendor infrastructure
Outbound connectionsOnly to your configured AI provider + toolsMany — analytics, telemetry, training
Offline operationYes — once installed, works without internetNo — requires constant vendor connection
Data on uninstallDocker volume wipe removes everythingVendor retains per data retention policy