15,200 OpenClaw instances found exposed to the internet
78% running unpatched versions with known CVEs
33.8% correlate with known APT activity
Ekuri users: 0 exposed
OpenClaw: 192K ★ on GitHub
Source: SecurityScorecard STRIKE Report — Feb 2026
Feb 2026 — 15,200 AI agents exposed worldwide

AI agents,
done right.

Hosted for everyone. VPS for tinkerers. Setup service for your hardware. Every path hardened, monitored, and invisible to the internet.

Powered by OpenClaw · Secured by Cloudflare · Zero exposed ports
0
Users exposed
3
Deployment paths
99.9%
Uptime SLA
<60s
Provisioning

One platform, three ways to run it

Whether you want zero setup, full control, or hands-on help with your own hardware — we've got a secure path for you.

app.ekuri.ai
For everyone

Hosted

Zero setup. Zero devops. Sign up, connect, and start your journey. We handle the rest.

from $15/mo
Multiple tiers available
  • Ready in 30 seconds
  • Memory, reminders & web search
  • Telegram, Web & Mac app
  • Completely private instance
  • Automatic updates
  • No technical skills needed
Get Started
setup.ekuri.ai
For self-managers

Setup Service

We set up OpenClaw on a VPS or your own hardware, harden everything, and hand you the keys. You manage it from there.

from $99
One-time · VPS or hardware
  • VPS or your own hardware
  • OpenClaw installed & configured
  • Full security hardening
  • Tunneling & firewall setup
  • Self-managed after handoff
  • Premium tier includes 30-day support
Get Started — from $99

15,200 got hacked.
You won't.

February 2026: SecurityScorecard found thousands of OpenClaw instances exposed to the internet with full remote code execution. Here's why Ekuri users weren't among them.

15,200
OpenClaw instances exposed to the internet
42,900 unique IPs scanned
78% unpatched CVEs
82 countries affected
33.8% APT activity
Exposed — what 15,200 did
// Default config = exposed
{
  "gateway": {
    "bind": "0.0.0.0",
    "port": 18789
  }
}

// Full RCE from the internet
// No auth. Your files. Your keys.
Ekuri — always secure
// Every Ekuri instance
{
  "gateway": {
    "bind": "loopback",
    "port": 18789,
    "auth": { "mode": "token" }
  }
}

// Localhost + token + tunnel
// Zero ports exposed

Localhost binding

Gateway listens on 127.0.0.1 only. Not accessible from the internet.

Zero exposed ports

Cloudflare Tunnel handles access. Nothing for scanners to find.

Automatic updates

CVEs patched before you know they exist. No forgotten servers.

Token authentication

Crypto-random tokens, SHA-256 hashed. Rotated automatically.

Isolated instances

Every user gets their own environment. No shared resources.

API key protection

Real API keys never touch your instance. Proxy tokens with credit limits.

You shouldn't need a sysadmin course
to use AI safely

The DIY path has 8 steps. Most people skip step 4. We've done this hundreds of times.

The DIY path

What the guides tell you to do

  1. 01 Get a VPS from Hetzner
  2. 02 Generate and add SSH keys
  3. 03 Install Tailscale on VPS + laptop
  4. 04 Configure firewall for Tailscale subnet
  5. 05 Install Node.js + OpenClaw
  6. 06 Configure gateway binding + auth
  7. 07 Set up Telegram bot
  8. 08 Keep everything updated forever
Time: 30+ minutes · Ongoing maintenance required
The Ekuri path

What you actually do

  1. 01 Sign up on ekuri.ai
  2. 02 Pick your tier
  3. 03 Start using your AI
Time: Under 2 minutes · We handle the rest

Common questions

Everything you need to know before getting started.

OpenClaw is an open-source AI agent framework with 192K+ stars on GitHub. It gives your AI the ability to browse the web, run code, manage files, search the internet, and much more. Ekuri provides a secure, managed way to run it.

Hosted runs on Cloudflare's edge network with zero setup — sign up and start chatting. Managed VPS gives you a dedicated Hetzner server with full unrestricted OpenClaw, SSH access, and the option to bring your own API keys. Both are secured and maintained by us.

Yes. On VPS plans you can use your own API keys from Anthropic, OpenAI, and other providers. This means unlimited AI usage at no extra credit cost — you only pay your API provider directly.

Every instance runs in complete isolation. Gateway binds to localhost only, access goes through Cloudflare Tunnel with zero exposed ports, and API keys are encrypted at rest. There's no shared infrastructure between users.

Yes. All subscriptions are month-to-month with no contracts. VPS plans come with a 7-day money-back guarantee. Cancel from your dashboard at any time.

Your AI agent is waiting
for you

Pick a path and start using AI the way it should be — powerful, private, and secure.

Choose Your Path

Cancel anytime · No long-term contracts