Security

Your Privacy is Our Priority

MicClaw is designed from the ground up to protect your data and privacy. Here's how we keep your information safe.

Core Security

Built for

Security isn't an afterthought - it's built into every aspect of MicClaw.

Local-First Architecture

Your conversations and data stay on your device. When using BYOK, we never see or store your interactions.

Encrypted API Keys

API keys are encrypted using AES-256 and stored in your OS secure credential storage (Keychain, Credential Manager, or Secret Service).

No Telemetry by Default

We don't collect usage data or analytics by default. Optional anonymous telemetry requires explicit opt-in.

Zero Data Retention

When using our managed cloud, conversations are processed in real-time and not stored on our servers.

Transparency

Open Source

MicClaw is fully open source under the MIT license. This means you can:

  • Review every line of code for security issues
  • Verify our privacy claims independently
  • Build from source for complete control
  • Contribute security improvements

Security Audit Status

We regularly conduct security reviews and work with the community to identify vulnerabilities.

SOC 2 Type IIIn Progress
GDPR CompliantYes
CCPA CompliantYes
HIPAAAvailable for Enterprise
Data Practices

What Happens to Your

We believe in radical transparency about data collection and usage.

What We Don't Collect

  • Your conversations or prompts
  • Your API keys or credentials
  • Files you work with
  • Screen content or voice recordings
  • Personal identification data

What We May Collect (Opt-in Only)

  • Anonymous usage statistics
  • Error reports for debugging
  • Feature usage patterns
  • Performance metrics
  • pages.security.data_practices.may_collect.items.4

Found a Vulnerability?

We appreciate responsible disclosure. If you discover a security vulnerability, please report it privately so we can address it promptly.

We aim to respond to security reports within 48 hours.