OpenClaw. Hardened.
One click.

A local AI runtime that doesn't phone home. ClawFactory installs OpenClaw inside a WSL2 sandbox with an egress firewall, loopback-only gateway, and one-click kill switch — for developers and operators who need their agent isolated, not connected.

Download v1.0.17 →
Windows 10/11  ·  Free to build  ·  $299 pre-built installer

What every install includes

Control What it does
WSL2 sandbox Agent runtime isolated from Windows filesystem
Rootless Docker No root access inside the container
nftables egress firewall Outbound traffic scoped to clawuser UID only
automount=false Windows drives invisible to the agent
Loopback-only gateway Gateway binds to 127.0.0.1:8787 — not the network
Windows Firewall rule Inbound connections to port 8787 blocked
DPAPI key storage API key in Windows Credential Manager, never plaintext
Kill Switch One-click shutdown from Start Menu

From zero to isolated agent in three steps.

Step 01 / Download
Download
Run ClawFactory-Secure-Setup.exe as Administrator.
Step 02 / Configure
Configure
Enter your API key. The installer stores it in Windows Credential Manager.
Step 03 / Run
Run
Your AI agent is live at 127.0.0.1:8787. Nothing leaves your machine without your permission.

A local AI runtime that doesn't phone home.

No telemetry. No cloud dependency. No data collection. Ever.