Isolated execution
Worktrees, disposable CI, containers, resource limits, and host-qualified isolation help keep parallel work from fighting over one shared mutable environment.
ClawKraft is designed so useful work can advance without collapsing isolation, review, or privacy. The public product surface explains the system. Authenticated operational surfaces run it. Privileged state stays off clawkraft.com.
Security on ClawKraft is not a single switch. It is the combination of execution isolation, governed review and deployment, durable evidence, and a hard split between public explanation and operational control.
Worktrees, disposable CI, containers, resource limits, and host-qualified isolation help keep parallel work from fighting over one shared mutable environment.
Changes move through diff inspection, corrective work, tests, evidence, approval, and handoff before accepted state advances.
Deployment is bound to authorization, required evidence, rollback behavior, production verification, and durable receipts.
Project-specific Programs, repositories, policies, credentials, and execution context stay private to the customer environment and authorized control surfaces.
Checkpoints, receipts, evidence, and review state remain bound to the work that produced them so recovery does not invent proof after the fact.
Worker death, stale leases, provider loss, CI failure, review invalidation, merge races, and rollback become reconciled state rather than mystery.
This boundary keeps the product story useful without turning the public website into a privileged control plane.
Privileged controls — pause, resume, stop, worker ON/OFF, Enable All, Disable All, Hard Stop, autonomy envelopes, authority envelope, and audit timelines — are not rendered on clawkraft.com.
The public site may consume only intentionally public interfaces and contracts. It must not become a public mirror of private operational state.
External agents connect at https://mcp.clawkraft.dev/mcp. ClawKraft MCP traffic is not routed through unrelated MCP endpoints or vhosts.
See Docs for public integration entrypoints.
Early-access contact details are used to manage access, communicate about availability, and operate and secure ClawKraft. They are not sold or shared for advertising.
Use the public support entry for product and early-access questions. Operational incidents are handled through authenticated channels on clawkraft.dev.