Security & trust

Governed execution with a clear boundary.

ClawKraft is designed so useful work can advance without collapsing isolation, review, or privacy. The public product surface explains the system. Authenticated operational surfaces run it. Privileged state stays off clawkraft.com.

Trust posture

Isolation, evidence, and authority — by design.

Security on ClawKraft is not a single switch. It is the combination of execution isolation, governed review and deployment, durable evidence, and a hard split between public explanation and operational control.

Isolated execution

Worktrees, disposable CI, containers, resource limits, and host-qualified isolation help keep parallel work from fighting over one shared mutable environment.

Governed review

Changes move through diff inspection, corrective work, tests, evidence, approval, and handoff before accepted state advances.

Governed deployment

Deployment is bound to authorization, required evidence, rollback behavior, production verification, and durable receipts.

Private workloads

Project-specific Programs, repositories, policies, credentials, and execution context stay private to the customer environment and authorized control surfaces.

Durable evidence

Checkpoints, receipts, evidence, and review state remain bound to the work that produced them so recovery does not invent proof after the fact.

Explicit failure state

Worker death, stale leases, provider loss, CI failure, review invalidation, merge races, and rollback become reconciled state rather than mystery.

Domain split

clawkraft.com is public. clawkraft.dev is operational.

This boundary keeps the product story useful without turning the public website into a privileged control plane.

Public — clawkraft.com
Product, how-it-works, use cases, and security explanation
Public docs entry and legal pages
Get Started and Login entrypoints that route off-site
Public status at a coarse availability level
Operational — clawkraft.dev
Setup and onboarding execution (setup.clawkraft.dev)
Authenticated Mission Control (app.clawkraft.dev)
Governed review surfaces (review.clawkraft.dev)
External agent MCP attachment (mcp.clawkraft.dev/mcp)

Privileged controls — pause, resume, stop, worker ON/OFF, Enable All, Disable All, Hard Stop, autonomy envelopes, authority envelope, and audit timelines — are not rendered on clawkraft.com.

Credential & data boundary

What this public surface will not contain.

The public site may consume only intentionally public interfaces and contracts. It must not become a public mirror of private operational state.

Never published here
Runtime or worker credentials
Private project inventories and Program state
Provider or deployment secrets
Mission Control / runtime source
Private operator runbooks or internal evidence
MCP boundary

External agents attach through the canonical endpoint.

External agents connect at https://mcp.clawkraft.dev/mcp. ClawKraft MCP traffic is not routed through unrelated MCP endpoints or vhosts.

See Docs for public integration entrypoints.

Privacy

Personal data has a narrow purpose.

Early-access contact details are used to manage access, communicate about availability, and operate and secure ClawKraft. They are not sold or shared for advertising.

Support

Questions about trust or access.

Use the public support entry for product and early-access questions. Operational incidents are handled through authenticated channels on clawkraft.dev.

Get started

Start on the public path. Operate on the authenticated path.