remoteagent.online   The control plane for secure, cost-controlled autonomous agents
AI agent security & cost control plane

Agents that move fast.
Boundaries that hold.

remoteagent.online is the technical layer between your AI agent and the real world. It evaluates intent, enforces policy, isolates execution, controls spend — and records every decision in a tamper-evident audit trail. Your API keys stay in the vault. Your budget stays on track. Nothing runs in the dark.

Policy-driven executionmTLS component identityToken budgets per agentHash-chained evidence
remoteagent.online / control room
Agent operations · live4 agents online
127Allowed today
€42.10Saved this week
08Blocked attacks
sentinel · monitoringONLINE
assistant · budget 62%ONLINE
openclaw · budget 18%ONLINE
research-agent · last seen 2h agoOFFLINE
Agentintent
Control planepolicy + guard + budget
Worldtool + API
12:42:18policy.check / file.readALLOWED
12:42:14file.delete / high riskBLOCKED
See the console

This is what you operate.

The platform dashboard — live status, per-agent budgets, audit evidence, and spend insight in one control room. Every view below is real: connect an agent and you get exactly this.

remoteagent.online / console — logged in as operator
4Agents Online
6Total Fleet
3Vault Credentials
€42.10Saved this week
AgentModelStatusBudgetLast Active
sentinelclaude-sonnetONLINEnow
assistantclaude-sonnetONLINEnow
openclawclaude-opusONLINE2 min ago
research-agentgpt-4oOFFLINE2h ago
▸ sentinelpolicy.check file.readALLOWED· 12:42:18chain 8f2a…c91e
▸ assistantfile.delete high riskBLOCKED· 12:42:14chain 8f2a…c91d
6Agents
4Online
3Tenants
2Near budget cap
sentinel · monitoring · tenant:coreONLINEtools: shell(ro), files(ro), net, notifyrisk: lowapproval: autobudget: €20/day
assistant · daily ops · tenant:coreONLINEtools: shell, files, web, browserrisk: mediumapproval: confirmbudget: €50/day
openclaw · general daemon · tenant:coreONLINEtools: full registryrisk: mediumapproval: confirmbudget: €80/day
Each agent has its own manifest: tools, risk tier, tenant, approval rules, budget.Manage agents →
127Allowed today
08Blocked attacks
3,481Hash-chained entries
Chain verified
TimeAgentActionDecisionReasonHash
12:42:18sentinelfile.read /var/logALLOWEDallowlist match8f2a…c91e
12:42:14assistantfile.delete ~/docsBLOCKEDhigh risk8f2a…c91d
12:41:59openclawshell curl api.evil.ioBLOCKEDinjection pattern #148f2a…c91c
12:41:37sentinelnet GET status.remoteagent.onlineALLOWEDallowlist match8f2a…c91b
Append-only. SHA-256 chained. The database refuses UPDATE and DELETE.Open audit history →
€42.10Saved this week — blocked attempts never billed
€18.40Spent this week across 4 agents
€2.30Avg daily cost per agent
Per-agent token budgets & daily caps keep the bill predictable. Unused budget stays yours.Open insights →
12:42:18policy.check / file.read / sentinelALLOWED
12:42:14guard.deny / file.delete / assistantBLOCKED
12:41:59injection.score 0.92 / shell / openclawBLOCKED
12:41:37policy.check / net / sentinelALLOWED
12:40:52budget.tick / assistant / 62%WARN
Every decision streams here — nothing runs silent.Open live log →
openclaw· claude-opus · tenant:coreagent chat · live
▶ demo looppicking next example…
User message → thought process → tool execution → verified answer. Every step recorded in the audit trail.Open the real chat →
Shown with sample data. Your console looks like this with your agents connected.
The technology

A serious control layer for serious agents.

Not another chat wrapper. remoteagent.online is a composable runtime for governing tool calls, identity, execution, spend, and evidence across autonomous workflows.

01

Injection Guard

Inspect prompts, retrieved content, tool outputs, and encoded payloads for instruction-takeover patterns before they reach the model or the next action.

pattern scoring · normalization · deny path
02

Policy Engine

Every agent gets an explicit allowlist, risk tier, tenant boundary, and approval rule. Deny-by-default keeps authority deliberate.

tool registry · scopes · review gates
03

Cost & Token Control

LLM usage is tracked per agent and per tenant. Set daily token budgets and rate limits — spend stays visible and capped.

token budgets · spend tiles · rate limits
04

Audit & Telemetry

Record decisions, reasons, risk, latency, sessions, and outcomes in a readable, tamper-evident operational trail.

SHA-256 chain · live feed · alerts
Request lifecycle

Every action gets a moment of truth.

The agent stays fast because the control path is explicit, narrow, and observable.

01

Receive & normalize

Accept an agent request over the gateway and normalize text, tool, arguments, identity, and context.

02

Inspect for injection

Score the request and relevant content against attack classes, encoding tricks, and instruction conflicts.

03

Evaluate policy & budget

Match the action to the agent manifest, scopes, tenant rules, risk tier — and check the token budget.

04

Decide, execute, explain

Allow, hold, or block; execute through the permitted adapter; emit the reason and evidence.

Decision pipeline / live path
Agent requestprompt · tool · arguments · identity
Guard + policy + budgetnormalize · score · allowlist · approval · spend
Decision pointallowed · held · denied
Adapter + auditexecute safely · record immutably
No silent action. No invisible authority. No unbudgeted spend.
Why teams run it

Security, savings, and visibility — in one layer.

Every advantage is a concrete control: what the agent may do, what it costs, and what it actually did.

🔐

Your API keys can't be stolen

Keys live in an encrypted vault on the platform — never in the agent, never in your prompts, never in your logs. The agent only ever talks to the proxy. A compromised agent gets nothing to exfiltrate.

💰

You save money on every agent

Token budgets, daily caps, and spend tiles make LLM cost visible per agent. Blocked prompt-injection attempts don't burn tokens, and unused budget stays yours. Stop paying for runaway loops.

🛡️

Prompt injection is stopped

22 weighted detection patterns catch instruction takeover, encoded payloads, and role-play bypasses — before the model or the tool sees them.

📜

Every action is provable

Hash-chained SHA-256 audit log. The database refuses UPDATE and DELETE. You can prove what happened — to yourself, to auditors, to regulators.

🧩

Per-agent configuration

Each agent gets its own manifest: tools, risk tier, tenant, approval rules, and budget. Add an agent, connect it, watch its status — active if running, offline when it's not.

🌍

Self-hosted or connected

Run fully local (nothing leaves your machine) or connect to the hosted console for remote overview and team features. Open source, MIT license — no lock-in.

Built with the agent

Proof looks like useful software.

The mona.expert projects are examples of what this architecture can power: focused products where an agent understands context, makes a decision, and stays inside a visible boundary.

remoteagent.online / composition
same control plane · different products
Contextuser + world
Agent runtimereason + govern
Experienceuseful outcome
The agent is the technology. The projects are the examples.
Real runs, straight from the control plane
more traces in the docs →
“Open Safari and go to YouTube's most played song”
donedeepseek-chat9.9k tokens · ≈ $0.003
🧠 think — user wants Safari → YouTube, find the most played song🛠 tool.call · apps✔ tool.result · exit 0🛠 tool.call · browser✔ opened youtube.com🛠 tool.call · browser✔ search: most played song💬 answer — “Baby Shark Dance”, 14B+ views✅ verify — results checked, task complete
“Open a 200×200 Python window with a clock”
donedeepseek-chat27.4k tokens · ≈ $0.008
🧠 think — plan a tkinter clock UI, write the code, run it🛠 tool.call · shell✔ python wrote clock.py🛠 tool.call · shell✔ python clock.py → window 200×200✅ verify — window rendered, seconds ticking
Deployment model

From one local agent to an enterprise fleet.

Start with a local wrapper, connect services through the gateway, then add team and tenant controls as the operation grows.

LOCAL / SELF-HOSTED

Run beside the agent

Keep prompts, policies, and audit data on the machine or private network. Useful for development, sensitive data, and rapid iteration.

Read the docs ↗
TEAM / CONNECTED

Operate through a gateway

Put a single policy, telemetry, and budget boundary in front of multiple agents, services, and environments.

Open the control console ↗
ENTERPRISE / GOVERNED

Scale with evidence

Separate tenants, rotate keys, enforce scopes, stream events, and give operators the context to approve or stop work.

View audit history ↗
FAQ

Questions, answered.

How does this save money with AI? +

Every decision is checked before it consumes tokens: prompt-injection attempts are blocked instead of billed, runaway loops hit their budget cap, and per-agent token budgets make spend visible and controllable. The result is fewer wasted LLM calls and a predictable bill.

Can my API keys really not be stolen? +

Keys are stored in an encrypted vault on the platform and are never passed to the agent, embedded in prompts, or written to logs. The agent calls a local proxy that holds the keys. Even a fully compromised agent has no key material to exfiltrate.

Does it only work with OpenClaw? +

No. The platform speaks HTTP and exposes a simple agent API. Any agent system — OpenClaw, custom code, LangChain-style tool loops, CI scripts — can connect through the gateway.

Is my data sent to the cloud? +

Only if you connect to the hosted console. In local mode everything stays on your machine. The code is open source (MIT) — you can verify exactly what leaves your system.

What does it cost? +

The core platform is free and open source under the MIT license. You pay only for the LLM tokens your agents actually use — and the platform makes sure you use fewer of them.

How do I see whether an agent is running? +

The dashboard shows every agent with a live status: online while its heartbeat is fresh, offline when it stops. You get active-if-running visibility plus per-agent budget and activity at a glance.

Build the agent. Keep the boundary. Watch the budget.

Open the console to inspect the platform, or explore the examples it enables.