AgentOSYour workforce, your infrastructure, your control surface.
AgentOS is designed for trusted operator environments and explicit hosted configuration. Security depends on how you deploy it, which resources you connect and how you manage credentials, network access and human review.

Operator-controlled deployment
AgentOS supports trusted local operator machines and an explicitly configured hosted deployment. The documented Railway path runs the application and Gateway in one persistent service.
Gateway boundary
The published Railway deployment keeps the OpenClaw Gateway on container loopback. Remote Gateway URLs are blocked by default in AgentOS unless explicitly enabled.
Bring your own keys
Model credentials are supplied by the operator and provider access is configured in the deployment. Sensitive values are redacted from diagnostics and compatibility reports where supported.
Authentication and origins
The packaged launcher generates an API token and starts with authentication. Remote write access is disabled by default; intentionally remote operator deployments require authentication, HTTPS and exact trusted origins.
Runtime visibility
AgentOS can expose Gateway health, compatibility, auth state, supported capabilities, sessions and runtime data. Visibility is not a claim of complete audit logging or formal compliance.
Limits that remain visible
Approval-required account rules are blocked until approval dispatch exists. Browser and account access are an MVP bridge, and typed browser-profile dispatch is not yet exposed by OpenClaw.
Responsibilities and limitations
Operators are responsible for access policies, provider credentials, the security of connected accounts, workspace file access and their hosting environment. Railway volumes persist data at runtime; protect and back up the environment appropriately. AgentOS does not claim SOC 2, ISO 27001, HIPAA, SAML, SCIM, complete RBAC, immutable audit logs or a security SLA.
Secure the deployment before expanding access.
Use a trusted environment, a ready model, minimal account scope and a review step for consequential work.