Run your agent without friction. Keep control before it acts.

LaunchZero installs and configures Hermes or OpenClaw through guided setup in minutes, then policy-gates monitored tools and managed integrations.

Proposed

Write notes.md

Monitored toolFilesystem.WriteText

The agent asks to create one file.

Decision gate

Writes need approval

  • AllowRuns without review
  • Require ApprovalPauses for your decisionThis request
  • DenyStops before execution

Your decision

Review the exact file and content before anything runs.

Approve exact action · Deny request

Submit for Execution

Only the approved write is submitted.

Executed

The approved action runs once.

Audit receipt

Approved · executed · recorded

The request, decision, and result stay together.

unbroken chain

What does running look like?

One local workspace for protection, agents, policy, and activity.

The dashboard keeps the operational state visible: protection active, agents connected, policy supervised, and the local system healthy. It is the control surface for the gateway already running on your machine.

LaunchZero Home dashboard showing protected files, commands, and websites, OpenClaw and Hermes connected, no pending approvals, and host integrity status
The local Home dashboard brings protection, agent, policy, and system health into one status view.

How quickly can I get running?

From download to Launch in minutes.

Choose Hermes, OpenClaw, or both. LaunchZero handles the setup that normally means terminal commands and hand-edited configuration, then starts your secure AI workspace with protection already on.

  1. Choose
  2. Connect
  3. Model
  4. Launch

Local secrets

Your keys stay encrypted on this machine.

Keys managed through LaunchZero live in its local encrypted store rather than plaintext LaunchZero-managed configuration. Model setup connects the selected agent to that store.

LaunchZero Model phase, step 6 of 8, with provider, encrypted API key, and model fields
The Model phase keeps provider credentials in LaunchZero’s encrypted local secret store.

Use the common settings form, open the advanced JSON/YAML editor when you need it, and switch the default agent immediately when both are running.

Explore the complete product journey →

What stays under my control?

The agent acts inside boundaries you can inspect.

LaunchZero keeps the consequential moments legible: what the agent is asking for, which rule applies, what you decided, and what actually ran.

Before it acts

Requests through monitored tools and managed integrations are policy-gated. Under the recommended Balanced posture, selected writes pause for your review.

Read the security model →

On your machine

Keys managed through LaunchZero stay in its local encrypted store instead of plaintext LaunchZero-managed configuration. The gateway is open source and requires no account.

Inspect the source →

After it runs

Activity records what was proposed, approved, denied, executed, or failed, with the correlation and hash evidence that closes the unbroken chain.

See how activity is verified →

Agent/model spend stays visible, too.

Review collected usage and spend estimates without confusing them with product pricing.

Explore agent spend →

Your agent, ready to work. You still decide what runs.

Free, open source, local-first. Guided setup gets you to Launch in minutes.