OpenClaw Security Best Practices
Your AI assistant has access to sensitive information. Here's how to keep it secure.
1. API Key Management
Never Share API Keys
Your AI provider API keys are the most sensitive credentials. Never:
Rotate Regularly
Change your API keys every 90 days:
Use Provider-Specific Keys
Create separate API keys for OpenClaw. If compromised, you can revoke without affecting other services.
2. WhatsApp Security
Linked Device Review
Regularly check WhatsApp → Settings → Linked Devices:
Two-Factor Authentication
Enable 2FA on your WhatsApp account for additional protection.
3. Data Encryption
At Rest
MyOpenClaw.cloud encrypts all sensitive data at rest:
In Transit
All communication uses TLS 1.3:
4. Access Control
Strong Passwords
Your OpenClaw setup password should be:
Session Management
Log out of unused sessions:
5. Instance Isolation
Each MyOpenClaw instance is:
6. Update Promptly
Security updates are released regularly. On MyOpenClaw.cloud:
7. Monitor for Suspicious Activity
Watch for:
8. Backup Your Data
While we maintain backups, you should:
Reporting Security Issues
Found a vulnerability? Email security@myopenclaw.cloud
We take security seriously and respond within 24 hours.
Secure your AI assistant today →