Your integrations touch real credentials and production systems. MegaClaw is designed so they act usefully without ever becoming a liability.
Security features
Every plan includes all security features. Security is not a premium add-on.
๐
AES-256 encrypted credentials
Every API key, token, and password is encrypted at rest with AES-256. Nothing sensitive is ever stored in plaintext or exposed in API responses, logs, or the UI.
๐ข
Multi-tenant isolation
Each company has its own isolated database, credentials, and API key. One tenant can never reach another's data or integrations under any circumstance.
๐ฅ
Role-based access control
Four roles: Superadmin, Admin, User, and Demo โ each with granular permissions. Sensitive actions require elevated access. No shared credentials.
๐
Full audit logs
Every task execution, integration change, token operation, and login is recorded with timestamp and user identity. Retention scales with your plan.
๐ช๐บ
GDPR-ready
Data-processing controls and retention policies designed for regulated, privacy-sensitive workloads in the EU. Your data stays where you put it.
๐
Self-hosted option
Run MegaClaw on your own infrastructure. Your data never leaves your servers. Full control, zero vendor lock-in, no surprise egress fees.
Security architecture
How MegaClaw protects your data at every layer.
Data protection details
Encryption at rest
AES-256 for all credentials. Database-level encryption for tenant data. No plaintext storage.
Encryption in transit
TLS 1.2+ for all API, Webhook, and MCP Server communications.
Tenant isolation
Separate database per tenant. API keys are scoped to a single tenant. Cross-tenant queries are architecturally impossible.
API key format
All keys use the mc_ prefix. Keys are hashed server-side and never returned after creation.
Audit log retention
Starter: 7 days ยท Basic: 30 days ยท Pro: 90 days ยท Enterprise: unlimited
BYOK (Bring Your Own Key)
AI provider keys are used directly from your account. They are encrypted, never proxied through MegaClaw's own models, and consume zero tokens.
Self-hosting
On-premise deployment available on Enterprise. Full infrastructure control, no egress to external MegaClaw servers.
What's covered on every plan
AES-256 credential encryption
Multi-tenant database isolation
Role-based access control (4 roles)
Audit logs (retention varies by plan)
TLS in transit for all endpoints
API key scoping per tenant
BYOK with zero inference markup
GDPR-aligned data handling
Questions about security?
Contact us directly for security reviews, penetration testing, or enterprise security questionnaires.