Evidence for agent safety review
PII checksScope checksApproval checks

Features

Compliance without the hardware lock-in

PII stripping, audit logging, and data residency controls that work on any infrastructure — not just NVIDIA.

🛡️Find Sensitive Data Before Review
Scan AGENTS.md, SOUL.md, skills, and config snippets for personal data, provider tokens, and secret-looking values before they reach agents, logs, or model providers.
📋Produce Control Evidence
Generate a downloadable evidence report with line numbers, severity, recommendations, and control references for security and compliance review.
Catch Risky Agent Permissions
Flag broad write, execute, filesystem, network, and scope permissions before an autonomous agent can use them.
🔒Check High-Impact Actions
Detect payment, email, deploy, write, delete, and other high-impact actions that lack nearby approval or dry-run language.

How it works

From non-compliant to audit-ready in 4 steps

No NVIDIA hardware. No months-long integration. Just wrap your existing OpenClaw setup.

01

Paste an OpenClaw artifact

Start with AGENTS.md, SOUL.md, a skill manifest, or a config snippet from an OpenClaw workspace.

02

Run the safety scan

ClawPine checks sensitive data, secrets, broad permissions, dangerous commands, and missing approvals.

03

Review the evidence

Use line-level findings, severity, and recommendations to decide what must change before release.

04

Export the report

Download JSON evidence for CI gates, registry badges, or security review tickets.

Compare

What changes with ClawPine

Without ClawPineWith ClawPine
Review evidenceManual grep and screenshotsDownloadable findings with line numbers
Agent permissionsBroad scopes hide in configRisky scopes flagged
PII ProtectionIdentifiers mixed into prompts and examplesSensitive literals detected before release
ApprovalsHigh-impact actions rely on conventionMissing approval language is visible

Trusted by compliance teams

What regulated teams are saying

We were blocked from deploying agents in our healthcare org until we had PII stripping and audit logs sorted. The compliance profiles made it straightforward.

Maria, CTO

The industry starter packs cut months off our compliance timeline. Went from evaluation to production in two weeks.

Thomas, Head of IT

Running on our existing infrastructure without NVIDIA lock-in was the deciding factor. ClawPine just wraps what we already have.

Yuki, DevOps Lead

FAQ

Common questions

  • ClawPine is an OpenClaw policy and evidence scanner. It checks configs and skills for sensitive data, secrets, broad permissions, risky commands, and missing approvals.
  • No. ClawPine generates review evidence and control references, but it is not a legal certification or a substitute for your compliance program.
  • Start with AGENTS.md, SOUL.md, OpenClaw skill manifests, permission snippets, shell setup notes, and workflow configs.
  • The report includes a verdict, risk score, line-level findings, severity, matched text, recommendations, and control references.
  • Yes. You can run the interactive scanner and download evidence reports during the public beta.

Scan your code now

Find PII risks in 30 seconds. Get instant GDPR, HIPAA, and SOC2 findings with remediation steps — no signup required.

Scan your code now →