Everything OpenClaw promised — done properly.
OpenClaw proved AI agents should live in your messaging apps, remember your preferences, and actually do things. But 49,500 instances are vulnerable to remote code execution. We built what they actually need.
Feature-by-feature comparison
How Erys stacks up against OpenClaw on the things that matter.
Setup
Docker, OAuth, webhook routing, port forwarding
Sign up, configure, connect channels
Hosting
Self-hosted on your server
Fully managed on GKE (EU)
Security
49,500 instances vulnerable to RCE
8 layers of defence in depth
Monthly cost
$300–750/mo in API + hosting costs
€10/agent/month, unlimited usage
Channels
Telegram, Discord (community plugins)
7 channels: Telegram, Slack, WhatsApp, Discord, Email, SMS, WebChat
Skills / Plugins
400+ unvetted community skills (malware found)
Curated plugin system with sandboxed execution
Memory
RAG-based, inconsistent recall
Persistent memory with structured categories
Code execution
Runs on your machine, no isolation
Dedicated Kubernetes pod with gVisor sandboxing
Preview URLs
Not available
Ephemeral preview URLs for agent-built apps
Data residency
Wherever you host it
EU (Netherlands) with GDPR compliance
Reliability
You maintain uptime
Managed infrastructure with auto-scaling
Desktop app
Not available
Electron app with MCP support
Security isn't a feature. It's the feature.
OpenClaw's security model has been publicly scrutinised. Here's how we're different.
OpenClaw's risks
- Remote code execution in 49,500+ instances
- Plaintext credential storage
- No action confirmation by default
- 400+ unvetted community skills (malware found)
- No container isolation
- No network policies
Erys's 8 layers
- gVisor kernel-level sandboxing
- UID/GID process isolation
- Non-root containers
- Namespace Pod Security Standards
- Network policies (default deny)
- Read-only root filesystem
- External Secrets Operator (AES-256)
- TLS 1.3 encryption in transit
“A lethal trifecta of remote code execution, credential theft, and unvetted third-party skills.”
Palo Alto Networks (Unit 42)
Security research on OpenClaw agent framework vulnerabilities
“A security nightmare for organisations that deploy it without understanding the attack surface.”
Cisco Talos Intelligence
Analysis of OpenClaw deployment risks in enterprise environments
“Found unsafe for use in any environment handling sensitive data.”
Kaspersky Labs
Independent security audit of AI agent platforms
€10/month. Full stop.
OpenClaw is free. Until you try to use it.
| Cost | OpenClaw | Erys |
|---|---|---|
| Software licence | Free (open source) | €10/agent/month |
| API costs | $300–750/month | Included |
| Server hosting | $20–100/month | Included |
| Maintenance | Your time | Included |
Get started free
Set up your first agent in minutes. 100 free AI credits — no API keys needed.
100 free AI credits included.

