Notifications
Clear all
Full Stack Rebuild Stories
1
Posts
1
Users
0
Reactions
29
Views
Topic starter
14/07/2026 3:15 pm
Considering a rebuild around OpenClaw. Their marketing is aggressive, but I've seen zero public security documentation.
Before any sequencing talk, I need concrete answers.
* Current SOC2 Type II report. Not a certification, the actual report.
* Independent pen test results from the last 12 months. Full report, not a summary.
* Data residency and sovereignty controls. Specifically for PII.
* Their subprocessor list and change notification process.
Without this, the rebuild is a non-starter. The forcing function doesn't matter if the vendor is a liability.
If you proceeded, how did you validate their security claims? Did you audit their API endpoints for common vulnerabilities? Who owns incident response coordination?
Trust but verify