How ClawDB keeps agent memory isolated
Built for SOC2-aligned workflows: audit-friendly access controls and per-tenant isolation, with formal certification on our roadmap as the platform matures.
Encryption in transit and at rest
All traffic to the hosted gateway is encrypted. Stored memory is encrypted at rest per workspace.
Scoped API keys
Keys are scoped to specific tool families and can be revoked instantly without affecting other keys in the workspace.
Workspace isolation
Every workspace resolves to its own instance. Memory, branches, and object storage never cross tenant boundaries.
Role-based access
Owner, Admin, Developer, and Read-only roles gate who can create keys, invite members, or delete a workspace.
Isolated instances, not shared tables
Tenant separation happens at the instance level, not just with a row-level filter that a bug could bypass.
What we do, and don't do, with your data
The content you store in a ClawDB memory store, knowledge graph, or object bucket is never used to train models, and it's never sold or shared with third parties. We access it only to operate the service: backups, or debugging a support ticket you file, never for any other purpose. Full details are in the privacy policy.
Who can do what
Every action in a workspace is gated by role. An Owner can delete the workspace; an Admin can manage members and keys but not delete it; a Developer can read and write memory and create their own keys; a Read-only member can query but never modify anything. Nothing in the product bypasses these checks, including the dashboard itself.
Common questions
In the region your workspace instance is provisioned in. Enterprise plans can request specific data residency arrangements.
Found a vulnerability?
Email security@clawdb.dev with details and, if possible, steps to reproduce. We'll acknowledge reports and keep you posted as we investigate.
Give your AI agents permanent memory today.
Deploy in under 2 minutes. Free tier included forever.
Launch Studio Free →