HIPAA · SOC 2 · FedRAMP · Attorney-Client Privilege

OpenClaw hosting
your security team approves.

Generic hosts run your AI agents on shared infrastructure with API keys in environment variables and unrestricted internet access. When your security team says no, they're right. We built the hosting that passes the review.

Isolation enforced by
Kubernetes Namespaces HashiCorp Vault Cilium eBPF Pod Security Standards OpenTelemetry Audit Logs
Industries We Serve

Built for companies where data exposure is never acceptable.

If your AI agents touch regulated data, proprietary workflows, or client confidences — generic hosting isn't a cost saving. It's a liability.

Healthcare

Agents that touch PHI must live in HIPAA-compliant environments. We provide isolated namespaces, access-controlled audit trails, and security documentation for your compliance officer and BAA discussions.

HIPAA · PHI Protection · BAA

Legal

Attorney-client privilege doesn't stop at your firewall. Every client's agent environment is isolated from every other — at the network level, not just the application level. No shared processes, no shared memory.

Attorney-Client Privilege · Client Data Isolation

Financial Services

SOC 2 and SEC requirements demand documented controls, audit trails, and verifiable access policies. Our audit logs, egress allow-lists, and Vault credential management give your security team something concrete.

SOC 2 · SEC · Audit Logging

Government Contractors

CMMC and FedRAMP-adjacent programs require dedicated infrastructure, documented network controls, and verifiable access logging. Shared hosting fails the first technical review. We were built for this.

CMMC · FedRAMP-adjacent · CUI

Insurance

Underwriting data, claims information, and actuarial models processed by AI need the same protection as your core systems — not a $5/mo VPS shared with strangers.

Underwriting Data · PII Protection

Your industry isn’t listed?

If your agents touch data your legal or security team cares about, the answer is probably the same. Let’s talk.

Talk to Us →
What Generic Hosts Give You

Your security team blocked generic hosting. They were right.

Shared hosting works fine for personal projects. The moment your agents touch real client data, production credentials, or regulated systems — the architecture that made it cheap is exactly what makes it dangerous.

Gray Fox was built specifically so your security review has something to say yes to.

Shared infrastructure

Your agents run alongside other customers' agents on the same host. One misconfigured sandbox can reach another tenant's data. No shared-infrastructure host can prevent this by design.

Credentials in environment variables

API keys stored as env vars are visible to any process in the container, appear in logs and crash reports, and are readable by anyone with host-level access — including the hosting provider.

No egress control

Agents can reach any endpoint on the internet with no allowlist, no visibility, and no protection against data exfiltration. Nothing stops a compromised dependency from calling home.

Gray Fox fixes all three — in writing

Dedicated namespace, Vault-backed credentials, and deny-by-default network policy — each enforced independently at the kernel level, with documentation you can hand to your compliance team.

Why Gray Fox

Generic hosting vs. Gray Fox.

The difference isn't a feature. It's the entire architecture.

Generic OpenClaw Hosts
Gray Fox
Environment isolation
Shared infrastructure
Dedicated Kubernetes namespace per client
Credential storage
Environment variables
HashiCorp Vault — injected at the network layer
Network egress
Unrestricted internet access
Deny-by-default, explicit allowlist only
Cross-client traffic
Not enforced
Blocked at the kernel via Cilium eBPF
Audit logging
None
Full audit trail with operator identity and timestamp
Compliance documentation
None available
Security architecture docs for HIPAA, SOC 2, FedRAMP reviews
Uptime model
Best-effort, single host
HA Kubernetes — auto-recovery in seconds
Security Architecture

Four layers generic hosts don't have.

Each layer is hard enforcement — not best-effort. Any one of them alone would stop most breaches. Together, they're what enterprise actually means.

Layer 01

Network Egress Control

Cilium eBPF enforces deny-by-default at the kernel. Agents can only reach explicitly approved hostnames, ports, and HTTP methods. A packet that bypasses your agent code is still dropped if it doesn't match an allow rule — before it leaves the node.

CiliumeBPFCiliumNetworkPolicy
Layer 02

Credential Vault Injection

Your API keys live in HashiCorp Vault and are injected into outbound requests by Envoy at the network layer. The agent only ever holds a placeholder string. Keys never appear in pod memory, environment variables, logs, or kubectl describe output.

HashiCorp VaultEnvoyExternal Secrets
Layer 03

Isolated Environments

Every client runs in a dedicated Kubernetes namespace with RBAC scoped exclusively to that namespace. Cross-environment traffic is blocked cluster-wide at the kernel. One environment cannot read, reach, or write to another — regardless of misconfiguration.

Kubernetes RBACNamespace isolationVault path scoping
Layer 04

Hardened Pod Security

Agents run non-root with a read-only filesystem, all Linux capabilities dropped, and seccomp RuntimeDefault applied. These are enforced at admission — a pod that violates them is rejected before it ever starts. Security tests run on every commit to prevent regression.

Pod Security StandardsseccompAdmission Webhooks
Process

From first call to running agents in days.

We handle the infrastructure and the compliance documentation. You focus on what your agents actually do.

Tell Us About Your Use Case

We start with a conversation — your industry, your compliance requirements, your data types. We'll tell you exactly what we can and can't cover before any commitment.

We Configure Your Environment

We provision your isolated namespace, vault your credentials, and configure egress policies for every integration your agents need — scoped exactly to what they require and nothing more.

Your Agents Go Live

Always-on agents with automatic recovery, full audit logging, and a dedicated Grafana dashboard. We handle uptime, patching, and secret rotation. You get the security documentation.

Common Questions

Questions your security team will ask.
We’ve answered them first.

If your question isn't here, ask us directly. We'd rather answer before the procurement process starts than during it.

Integrations

Connect to the tools your agents need.

13 pre-built policy presets. Each one whitelists the exact hostnames, ports, and HTTP paths required — nothing more, nothing less.

AI Providers
OpenAI Anthropic Google Gemini NVIDIA Groq HuggingFace Ollama (local)
Messaging & Channels
Slack Discord Telegram WhatsApp Microsoft Outlook Meta / Facebook
Developer Tools
GitHub Jira / Atlassian npm PyPI Brave Search

Need an integration not listed? Custom policy presets are available on request.

Platform

Built for teams that can't afford surprises.

Always-On, Self-Healing

No single point of failure. If a node goes down, your sandbox is rescheduled and running again within seconds — automatically, without paging anyone.

Audit-Ready Logging

Every agent creation, deletion, and policy change is logged with operator identity and timestamp. Query in Grafana or export for compliance reviews.

REST API + CLI

Manage agents programmatically with a JWT-authenticated REST API or the gfclaw CLI. Full OpenAPI spec included. Integrates with your existing pipelines.

Dedicated Observability

Grafana dashboards, Prometheus metrics, and distributed tracing scoped to your environment. Your telemetry doesn't share a panel with other clients.

Live Policy Updates

Add or remove integration presets on running agents without pod restarts or credential rotation. Changes propagate in seconds via the operator's reconcile loop.

Zero-Touch Secret Rotation

Update a credential in Vault. The Envoy sidecar picks it up in under 60 seconds. No restart. No downtime. No exposure window during rotation.

Request Access

Let’s find out if we’re the right fit.

Tell us about your use case, your industry, and any compliance requirements you're working with. We'll come back with a direct answer — whether that's a yes, a proposal, or a referral if we're not the right match.

  • Response within 1 business day
  • Security documentation available before any commitment
  • We'll tell you if we're not the right fit
  • No sales pressure — just an honest conversation