Security

Powerful agents.
Locked down by default.

Apex gives you a team of agents that can actually do things in your tools, which means security can't be an afterthought. So we built it in. Every instance runs sealed in its own hardened box, behind encrypted tunnels, with every action on the record. You get the power without having to be a security engineer.

Hardened by default · self-hosted option · your credentials never leave your environment
Battle-tested

We got attacked.
Nothing broke.

Hackers flooded us with 90,000+ fake login attempts. Our defenses blocked every one and the site never went down.

90K+fake logins blocked
278attackers auto-banned
0breaches
100%uptime
OpenClaw vs Apex

Built on OpenClaw.
Hardened by Apex.

OpenClaw is a powerful open foundation that hands you full control, and with it, full responsibility for locking things down. Apex runs that same foundation fully hardened out of the box. The isolation, the encryption, the locked-down access: it's already built in. You own your data; the security is done.

Defense in depth

Every layer, hardened.

Real security isn't one wall, it's many. Here's what's protecting your agents at every level. Each card has the plain-English version up top and the technical detail underneath.

You're always in the loop.

Agents move fast, but you stay in control of the moments that matter. Risky actions wait for your sign-off, you choose which tools each agent can touch, and everything that happens is written down.

Approvals on the risky stuffSensitive actions pause for a one-tap yes or no.
🎛️
Tool allow / deny listsDecide exactly what each agent is allowed to use.
📓
A full audit trailEvery action logged with who, what, when, and the result. 90 days.
🤝

Straight talk on what keeps agents in check

No one can promise an AI agent will never be tricked by a cleverly worded input. So we don't rely on hope. Agents are boxed in by what they're actually allowed to do: tool permissions, approval gates, isolated containers, and constant monitoring. If something does go sideways, it's contained, logged, and visible, not loose on your systems.

Secure by
default.

Every instance is hardened, isolated, and locked down before you send your first message. You just build.

Self-hosted optionFull data ownershipYour credentials stay yours