BYOK by design

We never see your data.

BetterClaw is the orchestration layer, not the middleman. Your prompts and your LLM responses travel directly between you and your provider. Here's exactly how that works - and what we can and cannot access.

  • AES-256 encrypted
  • Secrets auto-purge in 5 min
  • Skills verified before they run
  • GDPR-ready
ISO 27001 certified — Information Security Management

ISO 27001 certified

Information Security Management

The difference

How your data flows

Most platforms sit in the middle of every request. BetterClaw doesn't.

Typical platform

You

The Platform

Sees every prompt, response & key

LLM Provider
Your data is exposed to the middleman

BetterClaw (BYOK)

You

LLM Provider

Direct connection - your key, your data

BetterClaw orchestration layer - coordinates the agent via a dotted side-channel. Never touches the data payload.

Your data never touches our servers

Full transparency

Exactly what we see — and what we don't

What BetterClaw can see

  • Your email address
  • Your agent configuration (names, connected tools, instructions)
  • Usage metadata (how many minutes used)

What BetterClaw cannot see

  • Your conversations with your agent
  • Your prompts
  • Your LLM responses
  • Your API key (encrypted at rest)
  • Your connected tool data (emails, files, messages)

Under the hood

How we keep it that way

How credentials are stored

Your API keys are encrypted at rest, never written to logs, and auto-purged when you remove them. They're decrypted only in memory at the moment a request is made to your provider.

Skill verification

ClawHub hosts 13,000+ skills, with hundreds flagged as malicious. BetterClaw verifies every skill before it runs, so untrusted code never executes inside your agent.

Data retention

Free plan: 7-day chat-log retention, memory files persist. Pro plan: configurable retention. All data is deletable by you at any time.

Isolated containers per agent

Each agent runs in its own sandboxed Docker container with network isolation. One agent can never reach another.

Per-agent credential grants

A secret is only usable by the agents you explicitly grant it to, and you can revoke access per agent at any time. Real least privilege, not one shared env file.

Secret access audit log

Every read, grant, and revoke is recorded, with last-used and total access count per secret. Extend retention to a year on Pro.

Your keys. Your data. Your provider.

BetterClaw stays out of the data path by design. Start free - 1 agent, 100 credits a month, nothing we can read.

BYOK · Keys encrypted at rest · Secrets auto-purge in 5 min · GDPR-ready