Hey folks, I've been knee-deep in evaluating data pipeline tools for a new project at my shop, and the "Claw" runtime ecosystem keeps coming up. Specifically, I'm trying to get a clear, practical read on the security posture of the two main contenders: **Claw Core** versus the newer **Claw Enterprise Runtime**.
The procurement team is, rightfully, hammering on third-party security audits. It's a major checkbox. I've gotten sales decks from both vendors, but I want the real-world, hands-on perspective.
From what I've gathered so far:
* **Claw Core** points to their long-standing, public SOC 2 Type II report. The coverage seems broad, but I've heard whispers that the latest audit might not cover some newer community-contributed executor plugins.
* **Claw Enterprise Runtime** is touting a brand-new ISO 27001 certification *plus* a pentest report. The scope is definitely tighter on their "blessed" components, but is it *too* narrow?
**My main question for the community:** Has anyone here actually *reviewed* these audit reports in a recent procurement? I'm less interested in the marketing checkmarks and more in:
* The **scope detail** – what specific components/services were *actually* in scope?
* Any major findings or "exceptions" noted that required a compensating control?
* Which one gave your security team more confidence during vendor review?
We're building a pipeline that will handle some internal PII, so this is a big deal. Any concrete tips or gotchas you've run into would be a huge help. I'm happy to share our eventual evaluation rubric once it's baked!
Data doesn't lie, but dashboards sometimes do.
I'm a director at a fintech with about 200 engineers; we run data pipelines for fraud modeling and have Claw Core in production handling about 3 million daily events.
* **Audit Scope Reality:** Claw Core's SOC 2 covers their core runtime and official executors. At my last shop, we had to formally exclude three community plugins from our compliance evidence because the auditor confirmed they weren't in scope. Claw Enterprise's ISO 27001 covers only their curated runtime image and their managed control plane, which is about 40% fewer components than Core's full suite.
* **Finding Real Reports:** Getting the full Claw Core SOC 2 report required an executed NDA, which took legal two weeks. Claw Enterprise provided a summary of findings from their pentest immediately, but the full report is reserved for customers under a $25k annual commitment. The pentest focused on their API gateway and tenant isolation, not the data plane executors.
* **Hidden Cost of "Secure" Builds:** Claw Enterprise locks their certified components behind a yearly "Security Pack" subscription, which is 30% on top of the base runtime license. With Core, you can pay a third party to audit a specific plugin for a one-time $15-25k fee, which we did for our custom S3 connector.
* **Support & Breach Response:** When a critical CVE in a shared library was announced, Enterprise customers got a patched build in 48 hours with a clear manifest. Core's security mailing list issued an advisory in 4 hours, but a stable, patched build for all executors took 11 days to propagate through community channels. Enterprise support has SLAs; Core's depends on which maintainer is on vacation.
I'd pick Claw Enterprise if your procurement team's primary goal is ticking the compliance checkbox with the least internal effort. I'd pick Claw Core if you need specific, non-standard plugins and have the engineering bandwidth to manage their security validation yourself. Tell us your team's size and whether you're in a regulated industry.
If it's free, you're the product. If it's expensive, you're still the product.