PrivateClaw
AI agents running in confidential VMs you can verify
Details
- External ID
- 47891569
- Source
- HN
- Company
- —
- Product
- PrivateClaw
- Website domain
- privateclaw.dev
- Launched
- April 24, 2026
- Cohort
- —
- Upvotes
- 6
- Upvotes percentile
- 0.2808483290488432
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
We built PrivateClaw because the hosted OpenClaw platforms on the market today require you to trust them with plaintext. PrivateClaw removes that requirement at the hardware layer.PrivateClaw runs AI agents inside Trusted Execution Environments (TEEs), backed by AMD’s SEV-SNP standard. This means that your data is encrypted at the hardware level, enforced by the AMD Secure Processor outside the host OS trust boundary.PrivateClaw comes with inference that also runs inside TEEs, which means your prompts and completions are private as well.How it works:Each user gets a dedicated CVM (Confidential VM) — no shared tenancy. SEV-SNP provides hardware-enforced memory encryption with a per-VM key managed by the AMD Secure Processor, outside the host OS trust boundary. The hypervisor cannot read guest memory.Onboard now by running ssh privateclaw.dev in your terminal of choice.How you verify it:Our open-source CLI https://github.com/lunal-dev/privateclaw-cli is installed by default on all user CVMs and enables users to perform a 5-step verification:1. SEV-SNP attestation — fetches a signed attestation report from the AMD PSP and validates it against AMD's root of trust 2. vTPM verification — confirms the virtual TPM's endorsement key is bound to the CVM's attestation 3. Host key binding — verifies the SSH host key you're connecting to is the one measured in the attestation report 4. Inference endpoint check — confirms the inference and inference proxy cert is bound to their respective TEE measurements 5. Access control audit — validates that only your SSH key is authorized and the cloud’s guest agent is disabledEvery step is transparent and auditable, and the CLI that does this for you is open source.Today, we enable you to verify that your agent is running inside a TEE. Attestable builds are on our roadmap, which will also enable users to verify what software is running inside the TEE.Architecture:PrivateClaw runs the user CVM and inference gateway on Azure Confidential Compute, and inference itself is powered by Confidential AI's TEE-backed vLLM deployment. The launch digest for each CVM is in the attestation report, so you can verify the boot state. Binding specific userland binaries to published source is on our reproducible build roadmap.Pricing:Free tier available. Pro, with greater limits, is $69/mo.Try it: ssh privateclaw.dev
Enrichment
- Theme
- lightweight and on-device AI runtimes
- Vertical
- Security
- Function
- Agent / copilot
- Audience
- B2B
- AI stance
- AI-native
- Project type
- Commercial product
- Normalized one-liner
- verifiable ai agents in confidential vms
- Manually corrected
- False
Could you build this?
No Deploying verifiable confidential VMs requires deep systems engineering with AMD SEV-SNP hardware attestations, hypervisor-level security, cryptographic measurements, and secure key provisioning.
What it would actually take: A production implementation requires physical or cloud bare-metal infrastructure supporting AMD EPYC SEV-SNP or Intel TDX, running custom hypervisors (e.g., QEMU/KVM with libvirt or Cloud Hypervisor). Hard engineering parts include generating and verifying cryptographic hardware attestation reports against AMD's cert chain before injecting decrypted API keys or code. This demands specialized expertise in low-level Linux systems programming, cryptography, and confidential computing primitives.
Discussion
No comments on this launch.
Competitors
Other products that read as similar to this one — 170 launches clear the similarity bar, closest 8 shown.
Attention rank: #145 of 171 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 176 days after the earliest competitor.
- My agents are building a secure fork of OpenClaw · hn · 2026-02-13 · 9 upvotes · similarity 0.51
- FireClaw · hn · 2026-03-17 · 5 upvotes · similarity 0.49
- OpenClaw-class agents on ESP32 (and the IDE that makes it possible) · hn · 2026-03-12 · 31 upvotes · similarity 0.47
- TrustClaw by Composio · ph · 2026-05-15 · 152 upvotes · similarity 0.46
- Klaus · hn · 2026-03-11 · 160 upvotes · similarity 0.44
- ClawShell, Process-Level Isolation for OpenClaw Credentials · hn · 2026-02-19 · 10 upvotes · similarity 0.44
- OneCLI · hn · 2026-03-12 · 161 upvotes · similarity 0.44
- I put an AI agent on a $7/month VPS with IRC as its transport layer · hn · 2026-03-26 · 340 upvotes · similarity 0.43
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a agent / copilot tool for Agriculture yet.