Custom Agents
Features

Security

Cloud-sandboxed agents, encrypted credentials, rate limiting, full audit trails, and role-based access control.

Enterprise-grade security

Custom Agents is designed with security as a first principle. Your agents run in the cloud, sandboxed from your local systems, with full audit trails and role-based access control.

Security: Local Agents vs Custom Agents

RiskLocal Agent (e.g. OpenClaw)Custom Agents
File system accessFull local accessNone — cloud sandboxed
Credential storageOn deviceEncrypted, server-side
Data exfiltrationPossible (employee risk)Impossible (cloud sandboxed)
Runaway executionUnboundedRate-limited, token-budgeted
Data persistenceLost if device failsCloud-backed, redundant
Multi-user accessSingle userTeam-based with RBAC
Audit trailNoneFull activity logging
Offboarding riskKnowledge walks out the doorKnowledge stays permanently

Key security features

  • Cloud sandboxing — agents cannot access your local file system or network
  • Encrypted credentials — all API keys and OAuth tokens stored server-side, encrypted at rest
  • Rate limiting — prevents runaway execution and cost overruns
  • Full audit trail — every action logged and reviewable
  • Role-based access control — team-based permissions for multi-user accounts
  • OAuth-scoped integrations — each integration has granular permissions you control

Security built in, not bolted on

Your agents run in a secure cloud environment with full audit trails.