[ CLOUD RUNTIMES ]

Managed Cloud Containers for AI Agents

Deploy your agent in a secure, managed container with secrets injected at runtime, Shroud protection built in, and public HTTP hosting via custom subdomains.

[ 01 ] KEY FEATURES

Everything your agent needs to run

From secret injection to confidential compute — deploy production-ready agents without managing infrastructure.

One-Click Deploy

Choose a preset (Small to Large), pick your Docker image, and deploy. No Kubernetes to manage.

Secret Injection

Vault secrets automatically injected as environment variables. No credentials in code or config files.

Shroud Built In

Every runtime includes the Shroud sidecar for LLM traffic inspection and secret redaction.

Public HTTP Hosting

Expose your agent via {slug}.run.1claw.co with configurable auth (API key, JWT, or public).

Confidential Compute

Pro+ tiers get AMD SEV-SNP enclaves. Keys never leave the TEE.

Web Terminal

Debug your running container from the dashboard. Routed through the sidecar for security.

Auto-Idle

Containers auto-stop after configurable idle time to save costs.

[ 02 ] PRESETS

Pick a size, deploy in seconds

Six presets from lightweight dev containers to confidential-compute enclaves. Scale up anytime without redeploying.

Small

0.5 vCPU

512 MB

$15/mo

Medium

1 vCPU

2 GB

$39/mo

Large

2 vCPU

4 GB

$99/mo

SEV-SNP

Small CC

0.5 vCPU

512 MB

$35/mo

SEV-SNP

Medium CC

1 vCPU

2 GB

$75/mo

SEV-SNP

Large CC

4 vCPU

8 GB

$149/mo

[ 03 ] HOW IT WORKS

From zero to running in four steps

No Dockerfiles to write (bring your own image), no infrastructure to manage. We handle orchestration, secrets, networking, and security.

deploy flow
1

Create runtime

Choose a preset, Docker image, and the agent to bind.

2

Secrets injected

Secrets from your vault are injected as environment variables automatically.

3

Shroud sidecar

The Shroud sidecar intercepts LLM traffic for inspection and redaction.

4

Expose or keep private

Expose via a public subdomain ({slug}.run.1claw.co) or keep it internal.

6presets
Sub-minutedeploys
AMD SEV-SNPenclaves

[ COMPARE ]

How this compares

Capability-by-capability against the alternatives, including where the alternative is the better choice. Where agent code actually executes — container sandboxes, microVMs, and long-running hosted agents with credentials attached.

[ 04 ] GET STARTED

Deploy your first runtime today

Every paid plan includes one runtime — Small or Medium, up to 1 vCPU / 2 GB, no hour cap — starting with Pro at $29/mo. Add more runtimes, Large, or Confidential Compute as monthly add-ons.

  • One runtime included with every paid plan
  • No Kubernetes required
  • Secrets auto-injected
  • Shroud sidecar included
  • Confidential compute
  • Public HTTP hosting