Security

Security starts with an honest boundary.

MarketingOS does not create security by changing a label. Direct is the current default and accepts trusted local workloads only. OpenClaw Secure adds a Docker protection layer whose complete workload containment is not yet proven. Hermes Secure is unavailable and stops before mutation. These runtime profiles have no general write path; the separate managed Google connector is undergoing live validation only on dedicated reviewer infrastructure and is not a customer release.

DIRECT

Direct is convenient, but not a security boundary

Direct needs no Docker and is intended for crawls, analysis, evidence and local drafts. It accepts trusted local workloads only. A tool allowlist can reduce privileges but cannot contain an already compromised host process.

OPENCLAW SECURE

OpenClaw receives an additional Docker protection layer

The orchestrator and eleven specialists run without network access, with a read only root filesystem, no workspace access and no Linux capabilities. This is defense in depth. It is not yet proven that every relevant agent workload and gateway path stays within that boundary, so the profile is not ready for untrusted or production use.

HERMES DIRECT

Hermes separates roles from data tools

Twelve skills, slash commands and the team bundle carry role logic and the delegate_task mapping. Separately, the native plugin exposes exactly eleven data tools. That tool surface contains no terminal, filesystem, browser, web access, general exec, memory, skill management, Tool Search, MCP or foreign plugin tool. This allowlist is still not process containment.

HERMES SECURE

Hermes Secure is unavailable

A Secure attempt stops before mutation with hermes-secure-whole-process-unavailable and never falls back to Direct. A Docker terminal environment would contain the terminal only, not the Hermes process. A verified wrapper around the whole process is required to close that boundary.

FIVE SERVICES

Five services carry controlled connector boundaries

Policy Authority, Capability Broker, Secret Broker, Audit Service and Secure Executor separate decision, permission, credential reference, evidence and execution. They are built and tested. In the standard local setup, these five services still run under the same operating system account and therefore do not create a hard kernel boundary. The dedicated managed Google review environment adds separate operating system identities for the proxy, callback relay, Local Agent, Secure Profile, Audit Witness, reviewer gateway and OpenClaw.

DEFAULT DENY

Approval alone cannot publish anything

The publicly documented alpha source state has no active production adapter for general writes and no general external write path. A prompt, stored secret or general approved signal cannot open that boundary. Each of the five Google writes needs its exact contract inside the separate managed connector.

GRANT

A permission applies to one action

Capability grants are signed with Ed25519, short lived and usable once. They bind workspace, context, connector, operation, target, payload, risk, approval, expiry and nonce. Changing a bound value makes the grant unusable. Each Google write allows at most one provider attempt and needs a receipt, provider post-check and rollback or explicit recovery.

AUDIT WITNESS

Thirteen tests cover the second Audit boundary

The Audit Service maintains a signed hash chain. A separately operated Witness accepts only the registered key, next sequence and previously witnessed head. Thirteen adversarial tests cover forks, rollback, foreign keys, deleted tails and the same operating system account. A process under the same account does not count as independent.

FAIL CLOSED

An unclear Witness state stops the chain

If acknowledgement is unclear, the Audit Service retains its local entry and blocks later entries until manual reconciliation. The dedicated reviewer deployment runs the Witness under a second operating system identity; that live evidence applies only to the reviewer host, not the standard local setup or a customer release.

PLATFORMS

Real release runs remain open on every platform

Automated tests cover installation, update and removal in isolated Windows test directories. They do not replace a run on a fresh customer machine and do not prove a current signed customer artifact. Real release runs are therefore still missing for Windows, macOS and Linux.

NETWORK

The mobile view belongs on a private network

Private network access needs HTTPS, a narrow firewall rule and a short lived browser session. Public port forwarding, shared master tokens and unencrypted HTTP are outside the intended setup.

NO PROMISE

A compromised computer remains compromised

MarketingOS does not replace patching, backups, endpoint protection or access control on connected platforms. It reduces the reach and reuse of an error. Zero risk or enterprise isolation would not be honest claims today.

Primary sources

The host runtime decides where a real boundary begins.

MarketingOS can narrow permissions. It cannot redefine the security boundary of OpenClaw or Hermes. These vendor documents are therefore part of our security model.

Continue

See what the evidence supports

The Trust Center separates technical evidence, synthetic showcases and open release gates.

Open the Trust Center