Back to the registry
Agent passport

OpenClaw AI Agent - Hardened Ubuntu AMI

Software Sushi · Cybersecurity & IT

Partial captureNo attestation published

Certification per AWS Marketplace.

Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 4 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownVirtual machine
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

OpenClaw is an AI agent framework that turns an EC2 instance into a personal AI assistant. Connect it to the channels your users are already on and the AI providers you prefer. This AMI gives you a hardened, production-ready foundation. Add your credentials, configure your channels, and your agent is live. Your data stays on your instance, your keys stay in your account, and you control the infrastructure.

Channels: Telegram, Slack, Discord, WhatsApp, web, and more. Connect one or many. OpenClaw handles routing, conversation state, and memory across all of them.

Show the rest of the publisher’s description (19 more lines)

AI providers: OpenAI, Anthropic, AWS Bedrock, Google Vertex AI, OpenRouter, and more. Bring your own keys, no vendor lock-in, no per-message fees from us.

What's pre-installed:

  • Ubuntu 24.04 LTS (Canonical official base)
  • Node.js v22 (LTS) via NodeSource
  • OpenClaw AI agent framework
  • 4 GB swap file (prevents OOM on smaller instances)
  • Complete directory structure ready for configuration

Security hardening included:

  • UFW firewall: default deny inbound, SSH (22) and gateway port (18789) allowed
  • Fail2ban: bans IPs after 5 failed SSH attempts (1-hour ban)
  • SSH hardened: key-only authentication, no password login, no X11, max 3 auth tries
  • Kernel hardening: ICMP redirects disabled, IP forwarding disabled
  • Unattended upgrades: daily automatic security patches (no auto-reboot)
  • Log rotation: daily rotation with 7-day retention for OpenClaw logs

Getting started after launch:

  • SSH in as the ubuntu user: ssh -i your-key.pem ubuntu@<public-ip>
  • Run: openclaw onboard
  • Follow the onboard wizard to configure your AI provider, channels, and agent settings

Recommended instance type: t3.medium (2 vCPU, 4 GB RAM) or larger. Root volume: 20 GB gp3 (default).

Highlights

Highlighted by the publisher on AWS Marketplace.

Ready in minutes: SSH in, run "openclaw onboard", and follow the wizard. OpenClaw, Node.js v22, swap, firewall, and log rotation are all pre-configured. No manual config files needed, the onboard wizard walks you through AI provider, channels, and agent setup.

Security-hardened from the start: UFW firewall with default-deny policy, fail2ban SSH brute-force protection, key-only SSH authentication, kernel-level network hardening. No additional configuration needed. Hardening is baked into the AMI and active on first boot.

Works with your stack: connect to OpenAI, Anthropic, AWS Bedrock, Google Vertex AI, OpenRouter, or any compatible provider. Reach users on Telegram, Slack, Discord, WhatsApp, and more. Bring your own keys, no vendor lock-in, no per-message fees from us.

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Refund terms

As stated by the publisher on AWS Marketplace.

We offer a full refund of software charges for the first 48 hours billing starts if the product does not perform as described. To request a refund, email info@softwaresushi.com with your EC2 instance ID and a description of the issue. AWS infrastructure costs (EC2, EBS, data transfer) are billed by AWS and are not eligible for refund by us.

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource
StandardEulaStandardEulaSource

Linked repositories

1 repo
openclaw/openclawgithub · AWS MarketplaceSource

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Paid
Rate card pricing
Delivery
Virtual machine
For AMI-specific questions (hardening, configuration, deployment): - Email: info@softwaresushi.com OpenClaw community support: - Documentation: https://docs.openclaw.ai - Issues & bug reports: https://github.com/openclaw/openclaw/issues - FAQ: https://docs.openclaw.ai/start/faq
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.