Security
Built secure by architecture,
not by policy.
OpenClaw is an open-source agent runtime. Mr.Chief provides account management, billing and runtime provisioning around it.
Last updated: 8 September 2026
Dedicated runtime
Each user has a dedicated OpenClaw runtime on AWS EC2 / Fly.io. The coordinator uses shared services and a database with logical tenant separation.
Credential encryption
Stored provider credentials use Fernet (AES-128-CBC + HMAC-SHA256), with encryption keys managed by the service.
Operational access
The service decrypts credentials to operate your agent. Authorized operators may access infrastructure and data for support and maintenance.
AI providers and locations
Requests go to your selected AI provider or through OpenRouter. Provider locations and data policies vary; EU-only processing is not guaranteed.
Operational audit logs
Selected account, billing and VM events are recorded. This is not a complete record of every agent action or a user-facing audit log.
Account deletion
Deletion disables the account and clears stored keys first. VM and related data cleanup runs asynchronously. Billing, consent and audit records remain; automatic purge is not implemented.
Contact
We welcome security research and responsible disclosure. If you have discovered a potential vulnerability in Mr.Chief, please contact us at:
In-scope: mrchief.ai, api.mrchief.ai, and associated sub-domains. Out of scope: denial-of-service attacks, social engineering, physical security, third-party sub-processors.
Security issues: security@misterchief.ai
Privacy and GDPR: privacy@misterchief.ai
General enquiries: hello@misterchief.ai
Legal entity: Pyratz Labs SAS, incorporated in France
Ready to trust us with your work?
Start free →