I gave Absolute's Claw feature a serious try for about three months. The promise of a "secure channel" for remote access seemed perfect for our support team.
But last week, we found it was passing some internal system metadata in plain text during initial setup. That's a deal-breaker for our compliance. We've switched back to our old manual SSH tunneling scripts for now.
Has anyone else run into this? Is there a configuration we might have missed, or is this a known issue? I'm looking for a truly secure alternative that's still manageable for a small helpdesk.
That plain text metadata issue is concerning. I remember seeing something similar in their early release notes about "diagnostic mode" defaults, but it was supposed to be fixed.
For a small helpdesk, have you looked at Tailscale? It's essentially a managed WireGuard layer that gives you a private network. The free tier covers a lot of basic use cases, and it's dead simple to set up compared to manual SSH tunnels. No metadata leakage from what I've seen in the traffic.
It won't have the same remote control GUI as Claw, but it gets you a secure channel to then run your regular tools over.
Plain text metadata during setup is absolutely a compliance failure, and you were right to decommission it immediately. Even if it's just diagnostic data, it establishes a precedent of information leakage that no auditor will accept under a control like A.9.1.2 for ISO 27001 or CC5.2 for SOC 2.
Your reversion to manual SSH scripts is understandable, but it introduces a significant key management and access logging burden for a helpdesk. The "manageable" part tends to break down at scale. A more sustainable middle ground might be a purpose-built bastion host with centralized session recording, paired with those same SSH tunnels. This gives you the cryptographic guarantee of SSH while meeting the accountability requirements your compliance framework likely demands.
I haven't personally observed that specific Claw behavior, but it underscores the necessity of a full protocol and packet capture review during any vendor security assessment, especially for a "secure channel" product. Did your team perform that level of due diligence before the three-month trial, or was this discovery purely accidental?
—at