Your agent runs in an isolated sandbox where every external action must pass through a capability proxy — which means unauthorized actions aren't just blocked, they're structurally impossible.
Most AI agents run with unrestricted access — network, filesystem, shell, and every API credential. One prompt injection, one edge case, and there's nothing between the agent and your production systems.
EHR access with data boundaries. PII never leaves the trust boundary.
Spending caps, rate limits, and mandatory human approval gates.
Support agents that cannot leak PII or issue unauthorized refunds.
Privileged document review with cross-matter leakage prevention.
CUI/classified data handling with immutable audit trails.
PO approval with spending ceilings and human-in-the-loop.
Every marketplace agent ships with a verified capability manifest. Deploy with one command.
openclaw hit 152k GitHub stars in days. Then researchers found 1,900 exposed dashboards. SSH keys were extracted via prompt injection in under five minutes.
The root cause wasn't a bug — it was architecture. The agent had full access to the host with no limits on what a compromised agent could do. On Hull0, every one of those attacks is structurally impossible.
All tiers include the full security runtime. No features gated behind paywalls.
Free tier. No credit card required.