# Clawvisor > Clawvisor is an AI agent security gateway and control plane that verifies purpose, vaults credentials, and records a full audit trail for every protected tool call. Clawvisor is an AI agent security gateway and control plane. It sits between agents and the services they use, verifies each request against an approved task, injects credentials inside the gateway, and records a full audit trail. This file is a curated citation map; crawler permissions are defined in /robots.txt. ## Core product answers - [Home](https://clawvisor.com/): What Clawvisor is, who it is for, and its core AI-agent security model. - [How Clawvisor works](https://clawvisor.com/how-it-works): The request path and task lifecycle: declare, risk-score, approve, execute with scoped credentials, log, and revoke. - [Security](https://clawvisor.com/security): Defense-in-depth controls for purpose verification, credential isolation, risk gating, and audit logging. - [FAQ](https://clawvisor.com/faq): Direct technical answers about authorization, credential vaulting, task expiration, deployment, and product status. - [Pricing](https://clawvisor.com/pricing): Current managed-cloud allowances, request packs, plan differences, and self-hosting cost. - [Integrations](https://clawvisor.com/integrations): Supported services and how Clawvisor brokers credentials without exposing secrets to agents. - [Self-hosting](https://clawvisor.com/self-host): Requirements and deployment path for running Clawvisor inside your own infrastructure. - [Claude Code security](https://clawvisor.com/claude-code-security): How Clawvisor addresses prompt injection, approval fatigue, excessive permissions, and credential exposure in Claude Code. - [About](https://clawvisor.com/about): Clawvisor's mission, product principles, and reason for building purpose-based authorization. ## Security capabilities - [Purpose verification](https://clawvisor.com/solutions/containment): You approve a task, not a standing permission. Every request the agent makes is checked against the purpose you approved — a calendar read for your morning briefing goes through, an expense audit across all history does not. - [Audit trail](https://clawvisor.com/solutions/observability): Every request, every purpose declaration, every decision, every credential injection. A complete record of what your agent asked for and what Clawvisor allowed. - [Credential injection](https://clawvisor.com/solutions/credentials): Your API keys and OAuth tokens live in an encrypted vault. Clawvisor injects credentials server-side and returns sanitized results, so a leaked prompt or transcript can't leak a token. - [Risk assessment](https://clawvisor.com/solutions/risk-assessment): Every request is scored for risk before execution. Clawvisor flags anomalous parameters, unusual access patterns, scope creep, and prompt-injection attempts hiding in tool arguments. ## Product comparisons - [Clawvisor vs Arcade](https://clawvisor.com/compare/clawvisor-vs-arcade): A sourced comparison of Clawvisor and Arcade, including the use case where each is the better fit. - [Clawvisor vs HumanLayer](https://clawvisor.com/compare/clawvisor-vs-humanlayer): A sourced comparison of Clawvisor and HumanLayer, including the use case where each is the better fit. - [Clawvisor vs Portkey](https://clawvisor.com/compare/clawvisor-vs-portkey): A sourced comparison of Clawvisor and Portkey, including the use case where each is the better fit. - [Clawvisor vs Langfuse](https://clawvisor.com/compare/clawvisor-vs-langfuse): A sourced comparison of Clawvisor and Langfuse, including the use case where each is the better fit. ## Blog - [Introducing Clawvisor](https://clawvisor.com/blog/introducing-clawvisor): Why we built a gatekeeper for AI agents — and why purpose-based authorization is the right model for agent access control. ## Discovery - [Sitemap](https://clawvisor.com/sitemap-index.xml): Complete XML sitemap. - [Robots policy](https://clawvisor.com/robots.txt): Crawler permissions and Content Signals. - [GitHub repository](https://github.com/clawvisor/clawvisor): Public source and canonical technical documentation.