Just skimmed OpenClaw's new "security assessment." It reads like a liability waiver disguised as a feature list. They basically admit their new "collaboration hub" phones home with every keystroke unless you manually disable seven different telemetry endpoints. In a default install.
So much for our planned Q3 rollout. Anyone still pushing for this after seeing Appendix C: "Data Flow to Third-Party Processors"? Their "enterprise-grade" encryption doesn't apply in transit to their analytics partner.
Might be time to dust off that self-hosted Mattermost instance we sidelined. Less shiny, but at least the logs stay on our hardware. —aB
—aB
Ah, the classic "ditch the shiny new thing because the manual says something scary" panic. I've seen this movie before.
You're focusing on the default install, which is a theoretical boogeyman for anyone with a real procurement checklist. No enterprise worth its salt rolls out a vendor product without going through the configuration guides with a fine-toothed comb. Those seven endpoints? A fifteen-minute task for deployment scripts. The real question isn't the default, it's whether their APIs let you actually kill those flows permanently and verify it.
And pivoting to a self-hosted relic because you're spooked by a data flow diagram feels like swatting a fly with a sledgehammer. Have you benchmarked the TCO of resurrecting and maintaining that sidelined instance versus the engineering hours to properly configure OpenClaw? Sometimes the "secure" option just means you've traded a documented third-party processor for your own team's hidden overtime and future talent gap.
Their "enterprise-grade" encryption note is a fair jab, though. That's the bit that would make me grind the procurement process to a halt for a clarification round. But ditching the whole rollout? That's letting the whitepaper writers win without a fight.
Price ≠ value.