Skip to content
TIL: Claw's 'air-ga...
 
Notifications
Clear all

TIL: Claw's 'air-gapped' deployment option still phones home for license checks.

2 Posts
2 Users
0 Reactions
0 Views
(@martech_ops_sarah)
Trusted Member
Joined: 4 months ago
Posts: 30
Topic starter   [#5759]

Hey everyone, I had quite the experience this week that I think is worth sharing, especially for anyone considering or already using Claw in a sensitive environment.

My team is evaluating compliance automation platforms to help streamline our ISO 27001 audit prep. Claw came highly recommended, and their "air-gapped" deployment option seemed like a perfect fit for some of our more isolated environments handling sensitive customer data. The sales rep really emphasized that this was a fully offline, self-contained deployment.

Well, during our technical deep-dive, I asked our infrastructure engineer to set up a test instance in our isolated staging network (literally no outbound internet access). Everything installed fine, but the platform threw a persistent error about a "license heartbeat" failure. After some digging with their support, we learned the hard way: **their so-called 'air-gapped' deployment still requires periodic outbound calls to their license server.** It's not truly offline.

This was a huge red flag for our use case. The whole point of our air-gapped segment is to have zero egress traffic to the public internet for security and compliance evidence. If we can't prove that system is completely isolated, it creates a whole new set of control requirements and audit artifacts we'd have to manage.

I wanted to share this because:
* For anyone in regulated industries (HIPAA, certain PCI DSS requirements, etc.), this is a critical detail. "Air-gapped" shouldn't mean "mostly offline."
* It really underscores the importance of asking *very* specific questions during vendor evaluations. Don't just ask "can it run offline?" Ask: "Does the software initiate ANY outbound network connections, for any reason, including license validation, telemetry, or support? Please provide the exact domains/IPs and the protocol."
* We're now back to evaluating other options, and this has become a key question in our RFP. It also makes me wonder how many other vendors have similar "gotchas" in their deployment models.

Has anyone else run into this with Claw or similar GRC platforms? How did you handle it, or what truly offline alternatives have you found workable? I'd love to compare notes, as this set our timeline back a few weeks.

~Sarah


Data is the new oil


   
Quote
(@marketing_ops_maven)
Trusted Member
Joined: 1 month ago
Posts: 44
 

That's not an air gap, that's a turnstile they forgot to mention. The sales pitch of "fully offline, self-contained deployment" is completely at odds with a periodic license check.

This is exactly the kind of thing that turns a procurement process into a compliance nightmare. You'd have to explain the unauthorized egress traffic in your audit evidence, and good luck getting a satisfactory letter of attestation from their security team about what data that "heartbeat" is actually transmitting.

We saw similar obfuscation from a webinar platform a few years back that promised an on-premise version. Their license validation pinged home every 24 hours with a packet full of usage metadata they'd previously claimed was only stored locally. The whole point of these environments is having a verifiable, immutable boundary.


MQLs are a vanity metric.


   
ReplyQuote