Security
Built to pass your security review.
Agents touch money, customer records and production systems. Clawsseum is designed so you can explain exactly what an agent can reach, what it did, and what was kept.
Data flow
How a request moves through Clawsseum.
Every message takes the same path through five boundaries. At each one you can see what runs, what is checked, and what is kept.
- 01
Channel
Slack, email, web widget, API
Inbound events are signature-verified and mapped to a session. Unsigned or replayed requests are dropped at the edge.
What we keep
Event metadata, inside the redacted trace.
- 02
Runtime
Clawsseum runtime
Policy, budget and approval checks run before the agent sees anything. PII is redacted before a single byte is logged.
What we keep
Redacted traces, kept for your plan's retention window.
- 03
Agent
Your code, built with the SDK
Your agent plans and calls tools inside an isolated worker created for this run and torn down after it.
What we keep
Only the memory you declare in code, for the TTL you set.
- 04
Adapter
Adapter layer
A scoped credential is fetched from the vault for this call only. Operations outside the adapter's allowlist are refused.
What we keep
Nothing. Credentials never appear in traces or logs.
- 05
Provider
Model or system of record
The request reaches OpenAI, Stripe, Zendesk or whichever provider you wired in, under your own account and keys.
What we keep
Governed by your agreement with that provider.
Retention
What is stored, and for how long.
Short defaults, explicit controls. Anything not on this list is not stored.
| Data | Where it lives | How long | Your controls |
|---|---|---|---|
| Traces | The region you choose (US or EU) | 7, 30 or 90 days by plan. Unlimited on Enterprise. | Delete any run. Export to your stack over OpenTelemetry. |
| Agent memory | Your project | The TTL you set in code. | Purge by key, by end user or by agent. |
| Eval datasets | Your project | Until you delete them. | PII is scrubbed at record time, before storage. |
| Adapter credentials | KMS-backed vault | Until you revoke them. | Rotate or revoke instantly. Access is audit-logged. |
| Model prompts and outputs | Inside traces only | Same window as traces. | Switch payload capture off per agent. |
Controls
Least privilege by default.
The safe setting is the default setting. Loosening anything is a reviewed change in code, and it shows up in the audit log.
Your model keys, your account
Model calls run under your own provider account. Payload capture can be switched off per agent, so prompts and outputs never leave the run.
Scoped credentials per adapter
Secrets live in a KMS-backed vault. Each adapter declares the exact scopes it needs, like refunds:write and nothing else.
Approvals for side effects
Tools marked as side-effecting pause for a human in Slack or the dashboard. The Team plan adds policies: amount limits, reviewers, quorum.
PII redaction at the boundary
Emails, phone numbers, card numbers and government IDs are masked as data crosses an adapter, before traces are written. Add your own patterns.
Encryption everywhere
TLS 1.2 or higher in transit and AES-256 at rest. Enterprise customers can bring their own encryption keys.
SSO and SCIM
SAML and OIDC single sign-on with role-based access on Team. SCIM provisioning and custom roles on Enterprise.
Audit log
Every deploy, config change, approval and credential access is recorded with who, what and when. Export it to your SIEM.
Data residency
Pin traces, memory and eval datasets to the US or the EU. Requests are processed in the region you choose.
Self-hosted runtime
On Enterprise, the runtime and adapters run inside your own AWS, GCP or Azure VPC. Our control plane only sees metadata.
No training on your data
We never train models on your data. Where a provider offers zero retention or a no-training control, the adapter turns it on by default.
Budgets and kill switches
Per-agent spend caps, rate limits and step ceilings. One switch stops an agent mid-run, everywhere, immediately.
Run isolation
Every run gets its own isolated worker. Generated code executes in a separate sandbox with no network access unless you grant it.
Compliance
Security documentation on request.
We are an early-stage company and we do not claim certifications we have not completed. Here is the documentation we can share today with your security and procurement teams.
Available on request
- 01Security overview: architecture, controls and incident response
- 02A working session with an engineer to review your deployment
- 03Data processing agreement and current subprocessor list
- 04Your security questionnaire, completed by us
Responsible disclosure
Report a vulnerability.
Email security@clawsseum.com with a description of the issue and the steps to reproduce it. We acknowledge every report within two business days and keep you updated until it is resolved.
We will not pursue legal action against good-faith research that avoids privacy violations, data destruction and service disruption, and that gives us reasonable time to fix the issue before disclosure.
Out of scope
- Social engineering, phishing or physical attacks
- Denial of service and volumetric testing
- Vulnerabilities in third-party providers we connect to, which should go to that provider