Index / IronClaw · updated Oct 2, 2026

IronClaw

nearai/ironclaw · healthy · rank 12 of 43 by stars

A security-first Agent OS in Rust that treats your assistant as a local, encrypted, auditable service rather than a cloud product. Its vibe is paranoid-in-a-good-way: restricted egress, fail-closed pairing, and prompt-injection defenses baked into the runtime.

#agent-os#privacy-first#rust#self-hosted#security
Compare vs OpenClaw
GitHub ↗

Facts

Repository

Contributors120
Open issues1,538
Last commitSep 10, 2026
Release cadence~5 days
Latest releaseironclaw-v1.4.1

Runtime

LanguageRust
Memory18 MB
Boot time35 ms
Deploymentdesktop · self-hosted · cloud
Setup difficultyMedium
Plugin ecosystemEmerging

Posture

LicenseApache-2.0
Local-firstYes
Cloud dependencyOptional
Multi-userYes
Privacy postureStrong

Community

Sentiment78% positive
Reddit mentions22
Web results10

Security breakdown

Composite 92 / 100 · how these are scored

Sandboxing9 / 10

higher is safer

API security9 / 10

higher is safer

Network isolation9 / 10

higher is safer

Telemetry safety9 / 10

higher is safer

Shell access risk4 / 10

higher is riskier

Model access

Read from the repository, not written by a model · 143 files examined

7 providers · runs locally · gateway support

Direct
AnthropicAWS BedrockFireworksGoogleMiniMaxOpenAITogether
Gateway
LiteLLMOpenRouter
Local
LM StudioOllama
Compatible
OpenAI-compatible

Pinned models

gemini-2.5-flash released 2025-06-17 — 16 months old (from the public model catalogue)

Pin last edited 36 days ago

Several defaults are pinned; the project picks one per provider rather than shipping a single default.

Evidence

Decision

Why choose IronClaw over OpenClaw?

Why choose this

  • Rust runtime with lower memory footprint and faster startup
  • Fail-closed egress and pairing model with explicit allowlists
  • Encrypted local credential store and no telemetry by design

Tradeoffs

  • Smaller ecosystem and fewer community skills/plugins
  • Heavier setup and operational model than OpenClaw's simpler flows
  • Some Reddit signals of onboarding friction and task reliability issues

Best fit

  • Privacy-conscious users who want a local-first assistant
  • Operators needing auditable, fail-closed agent security
  • Teams integrating Telegram/WebUI channels with strict egress control

Avoid if

  • You want a zero-config hosted SaaS assistant
  • You need a large third-party plugin marketplace today
  • You are uncomfortable running a background Rust service
High Confidence82%

Strong evidence from README, license, release data, and very active recent commits; community sentiment is moderately positive but partly drawn from the project's own subreddit, so independent validation is thinner.

AI layer reviewed Sep 21, 2026 · how this is written

Star activity

12,637 stars today

Overview

IronClaw is a Rust-based Agent OS from NEAR AI positioned as a secure, personal AI assistant that runs as a local background service with an encrypted credential store and a WebUI. Its philosophy is explicit: data stays local, there is no hidden telemetry, and the system is auditable open source under MIT/Apache-2.0. Onboarding is guided via ironclaw onboard, with installers for macOS, Linux, and Windows/WSL.

Architecturally, IronClaw emphasizes fail-closed security: channel extensions (e.g., Telegram) declare egress allowlists, pairing/binding is checked before command admission, and recent commits show deep investment in prompt-injection defenses, restricted egress lifecycles, subagent approval gates surfaced to owners, and careful handling of LLM cache keys (hashed before leaving the process). The commit history shows a mature engineering culture with contract tests, architecture gates, and performance work like streamed-text coalescing.

Compared to OpenClaw, IronClaw trades ecosystem breadth for a hardened, privacy-first runtime with a smaller footprint and stricter network isolation. It fits users who prioritize control and auditability over plugin variety, though some community reports note onboarding friction and occasional task-execution hiccups.

Nominate a clone

Add a new Claw

Paste a GitHub repository and tell us why it belongs on the tracker.

Opens a prefilled issue on GitHub — every nomination is public. Comfortable with a PR? Adding the repo to projects.json is faster.