Index / IronClaw · updated Oct 2, 2026
IronClaw
nearai/ironclaw · healthy · rank 12 of 43 by stars
A security-first Agent OS in Rust that treats your assistant as a local, encrypted, auditable service rather than a cloud product. Its vibe is paranoid-in-a-good-way: restricted egress, fail-closed pairing, and prompt-injection defenses baked into the runtime.
Facts
Repository
Runtime
Posture
Community
Security breakdown
Composite 92 / 100 · how these are scored
higher is safer
higher is safer
higher is safer
higher is safer
higher is riskier
Model access
Read from the repository, not written by a model · 143 files examined
7 providers · runs locally · gateway support
Pinned models
gemini-2.5-flash released 2025-06-17 — 16 months old (from the public model catalogue)
Pin last edited 36 days ago
Several defaults are pinned; the project picks one per provider rather than shipping a single default.
Evidence
Decision
Why choose IronClaw over OpenClaw?
Why choose this
- Rust runtime with lower memory footprint and faster startup
- Fail-closed egress and pairing model with explicit allowlists
- Encrypted local credential store and no telemetry by design
Tradeoffs
- Smaller ecosystem and fewer community skills/plugins
- Heavier setup and operational model than OpenClaw's simpler flows
- Some Reddit signals of onboarding friction and task reliability issues
Best fit
- Privacy-conscious users who want a local-first assistant
- Operators needing auditable, fail-closed agent security
- Teams integrating Telegram/WebUI channels with strict egress control
Avoid if
- You want a zero-config hosted SaaS assistant
- You need a large third-party plugin marketplace today
- You are uncomfortable running a background Rust service
Strong evidence from README, license, release data, and very active recent commits; community sentiment is moderately positive but partly drawn from the project's own subreddit, so independent validation is thinner.
AI layer reviewed Sep 21, 2026 · how this is written
Star activity
12,637 stars today
Overview
IronClaw is a Rust-based Agent OS from NEAR AI positioned as a secure, personal AI assistant that runs as a local background service with an encrypted credential store and a WebUI. Its philosophy is explicit: data stays local, there is no hidden telemetry, and the system is auditable open source under MIT/Apache-2.0. Onboarding is guided via ironclaw onboard, with installers for macOS, Linux, and Windows/WSL.
Architecturally, IronClaw emphasizes fail-closed security: channel extensions (e.g., Telegram) declare egress allowlists, pairing/binding is checked before command admission, and recent commits show deep investment in prompt-injection defenses, restricted egress lifecycles, subagent approval gates surfaced to owners, and careful handling of LLM cache keys (hashed before leaving the process). The commit history shows a mature engineering culture with contract tests, architecture gates, and performance work like streamed-text coalescing.
Compared to OpenClaw, IronClaw trades ecosystem breadth for a hardened, privacy-first runtime with a smaller footprint and stricter network isolation. It fits users who prioritize control and auditability over plugin variety, though some community reports note onboarding friction and occasional task-execution hiccups.