DeClaw
DeClaw is a macOS-native local firewall for AI agents — a 100% local binary that sits between OpenClaw (or any AI app) and external AI providers, redacting PII before requests leave your machine and d
About
DeClaw is a macOS-native local firewall for AI agents — a 100% local binary that sits between OpenClaw (or any AI app) and external AI providers, redacting PII before requests leave your machine and de-anonymizing responses on return. Detects SSNs, credit cards, emails, phone numbers, names, and prompt injection attempts. Pro tier adds invisible text detection and a skill scanner. Free tier available; Pro "coming soon." Apple Silicon-native, signed and notarized by Apple.
Individual developers on macOS who run OpenClaw or other AI assistants locally and want to prevent accidental PII exposure in their AI conversations — particularly anyone who regularly shares sensitive documents or data with AI assistants and doesn't want raw personal information sent to cloud providers.
Pros & Cons
Pros
- check 100% local processing — no cloud, no servers, no middlemen; scanning and redaction happen in memory only
- check Seamless PII loop: data redacted on the way out, de-anonymized on the way back — AI response feels unchanged to the user
- check Prompt injection defense intercepts indirect injections (hidden in websites) before the agent acts on them
- check Apple-signed and notarized — passes macOS security verification, reducing installation friction
- check Works across all major AI providers (OpenAI, Anthropic, Gemini, Azure AI) — not OpenClaw-specific
Cons
- close macOS only — no Windows or Linux support; blocks adoption for developers on other platforms
- close Local-first means protection only applies on the local machine — not useful for cloud-based or server-side agent deployments
- close Pro tier (skill scanner, invisible text detection) is "coming soon" — current free tier is limited in scope
- close PII detection is pattern-based — atypical formats or international PII patterns may escape detection
- close Middleware approach adds a dependency in the request chain that could cause issues with some integrations
More Security
Other tools in the same category.