If Docker runs on your machine, ThreatClaw runs on your machine.

Four profiles based on your infrastructure size.

SMALL

< 50 assets

RAM16 GB
CPU4 cores
Storage80 GB SSD
Network100 Mbps
Recommended

MEDIUM

50–200 assets

RAM32 GB
CPU8 cores
Storage200 GB NVMe
Network500 Mbps

LARGE

200–500 assets

RAM64 GB
CPU16 cores
Storage500 GB NVMe
Network1 Gbps
GPU required

XL

500–1000 assets

RAM128 GB
CPU32 cores
GPU1× RTX 4090 / A6000 (24 GB VRAM)
Storage1 TB NVMe
Network1 Gbps
💾PostgreSQL compresses logs ×20. 500K logs/day = ~25 MB/day stored. 90 days history ≈ 2.5 GB.

Supported OS

RecommendedDebian 12 (Bookworm)
TestedUbuntu 22.04/24.04 LTS · Rocky Linux 9 · AlmaLinux 9
Dev/testWindows 10/11 Pro (Docker Desktop + WSL2) · macOS (Docker Desktop)
Docker ≥ 24.0 · Docker Compose ≥ 2.0 · Kernel Linux ≥ 5.4 · x86_64 ou ARM64

2 commands. Installed.

ThreatClaw installs in minutes on Linux. Then configure it to match your infrastructure.

bash
# Install ThreatClaw
$ curl -fsSL https://get.threatclaw.io | sudo bash
# Start ThreatClaw
$ threatclaw run

Supported platforms

LinuxmacOSWindowsDocker

A security tool must be auditable. Period.

AGPL v3 license, no one can close what protects your data
100% source code on GitHub
Zero telemetry, no data phones home
Zero backdoor possible, the code is public
Contribute, audit, fork
99% of SMB users are not affected by AGPL. The sharing obligation only applies if you redistribute ThreatClaw as a service. See license FAQ →
View source code

Built on trust.

Open Source AGPL v3

100% auditable source code on GitHub. AGPL v3 license, no one can take your security and close it. Commercial dual-license available.

Local data

Your data never leaves your infrastructure. If you use a cloud LLM, it's anonymized before sending.

Total auditability

Every agent decision is logged in an immutable audit log (cryptographic signature chain). Complete traceability.

Verifiable security

0 CVE in the binary. 5 security pillars compiled into the code. Third-party audit planned before v1.0.