AI Coach Assistant · runs OpenClaw, managed
Managed OpenClaw hosting, with the bill in plain sight
A personal AI assistant on your own isolated cell. You message it on Telegram or Slack, it watches what you tell it to watch, and everything it wants to send waits for your tap. We set it up, we patch it, we watch it. You can see what every model call cost.
From $29.00/mo plus metered model spend. Not affiliated with OpenClaw AI.
What people actually use it for
Not a feature list. Three things our own cell does, described the way the person who asked for them described them.
The 7am brief
It reads overnight mail, your calendar and the two repos you care about, and sends one message before you open a laptop. Nothing leaves your account to write it.
Reply drafting
A client mails you. It writes the reply in your voice, with the thread and the invoice history already in mind, and holds it until you tap send.
The thing you keep forgetting
Chase the unpaid invoice on day 31. Nudge the supplier who has gone quiet. It watches, it asks, you decide.
Two tracks, split by who does the setup
The cell is the same. What changes is whether you pair the channels and wire the connections, or we do it with you on a call.
Self-Serve
no setup fee
- 1 cell, 1 channel
- Guided setup wizard and docs
- Email support, best effort
- Critical patches inside 24h
- Isolated container per tenant
- Tracks the current minor version
- Model spend metered, capped at $50.00/mo by default
Managed
plus $199.00 one-time setup
- 1 cell, 2 channels
- We pair, wire and seed it with you
- 8-business-hour support response
- Critical patches inside 24h
- Isolated container per tenant
- Tracks the current minor version
- Model spend metered, capped at $100.00/mo by default
Business
plus $499.00 one-time setup
- 3 cells, 3 channels
- We pair, wire and seed it with you
- 4-business-hour support response
- Critical patches inside 24h
- Hardened runtime (gVisor or Kata)
- Version pinning up to 90 days
- Service credit if we miss cell uptime
- Model spend metered, capped at $300.00/mo by default
Reselling to your own clients, or need more than three cells? That is a conversation, not a checkout. Get in touch.
What it will actually cost you
The cell fee is fixed. Model spend is not, so here is the arithmetic rather than a promise. Drag it to your own usage. It will tell you when a bundled plan would be cheaper.
- Assistant turns / month
- 1,170
- Model spend, at cost
- $47.39
- With 1.3x markup
- $61.61
- Plan fee
- $29.00
Self-Serve, Sonnet class, 1,170 turns. That is $41.61 more than a $49.00 bundled plan. Worth it if you want to see the ledger, or if a bundled plan would throttle you. Otherwise it is not.
Estimates, not a quote. Assumes ~10k input and ~700 output tokens per turn, which is what a turn with memory and tool calls actually costs. Prompt caching cuts input spend substantially in practice, so these run high rather than low.
It cannot send anything without you
Three tiers of authority. Every cell is handed over on Draft, and only you can raise it. This is the part most autonomous-assistant pitches leave out.
Observe
On by default
Reads, summarises, watches, answers. Nothing leaves your account. Most of the value lives here, and it cannot cause an incident.
Draft
Where every cell starts
Writes the email, the reply, the post, then stops and waits for your tap. This is the default for anything outbound, and it is what makes an autonomous assistant safe to buy.
Act
You turn this on, per tool
Sends, books, pays, deletes. Granted one tool at a time, revocable, always logged. Never on when a cell is handed over, whatever was asked for at checkout.
The threat model has a name and a date
In July 2026 a researcher chained three OpenClaw vulnerabilities from a single WhatsApp message to credential theft, a Docker sandbox escape and code execution on the host machine. That is the specific attack this is built against. Any host that will not tell you what they are defending against has not thought about it.
- One cell per customer
- A full Gateway per tenant with its own state directory, credentials, workspace, token and loopback-only port. Never a shared Gateway, because OpenClaw’s trust boundary is the Gateway itself.
- No shell on channel-facing sessions
- exec is removed from the tool allowlist for anything reachable from a message. This is the specific control that breaks the published attack chain.
- Default-deny egress
- Your cell can reach the connections you approved and nothing else. Contains credential exfiltration even after a successful prompt injection.
- Secrets never sit in the cell
- The control plane holds them; the cell gets short-lived scoped tokens. It is a worker that holds no secrets and cannot spend.
- The cap is enforced outside the agent
- Spend limits live in the control plane, so a compromised or looping agent still cannot spend past them.
- Backups are treated as credentials
- A cell state directory is a credential store. Encrypted, access-logged, handled like a token.
If we are ever compromised, affected customers hear within 72 hours, with what happened and exactly what to rotate.
It does not arrive empty
A bare cell is a blank prompt and a docs link. Yours arrives with vetted skills already installed and your MCP connections already wired, drawn from the catalogue AI Coach already runs. Connection config is encrypted at rest and never stored inside the cell.
Where you talk to it
Every channel it supports, including the one we would rather you did not use.
About WhatsApp, before you ask
Automating a personal WhatsApp account breaches Meta’s terms. Numbers do get restricted, sometimes within a week, sometimes never, with no pattern anyone has found. We will pair it if you want it, and we exclude it from every uptime commitment, because nobody can honestly promise a channel that Meta can revoke. For anything your work depends on, use Telegram, Slack or a WhatsApp Business API number.
What happens when OpenClaw ships
Upstream moves fast. Security patches are not optional and are not an imposition; everything else you get notice about.
| Change | What we do | Notice | Opt out |
|---|---|---|---|
| Critical security patch | Applied immediately | within 24h | None |
| Other security patch | Next maintenance window | within 7 days | None |
| Minor version | Weekly window, under 10 min downtime | 48 hours | Defer once |
| Major version | Staged on our own cell first | 14 days | 30 days, then required |
| Upstream breaks a channel | We tell you, with the workaround or an ETA | 1 business day | None |
| Upstream is abandoned | Full export, no lock-in. We track upstream, we do not fork it. | 60 days | None |
Who actually sets it up
AI Coach runs the order, the billing and the monitoring. The deployment and the onboarding are done by a delivery partner, and we say so rather than implying a support team you never meet.
- 01
You order
Pick a plan, tell us what you want it to do, and choose how to pay.
- 02
We introduce you
A delivery partner gets your order by email, with you copied in. Reply-all and you are talking to them.
- 03
They deploy it
You agree the spec with them directly. They build it and hand it over.
- 04
You confirm
Only when you say it works does your plan start, and any balance get charged.
The questions worth asking
Answered plainly, including where the answer is not flattering.
Will my WhatsApp get banned? +
It might. Automating a personal WhatsApp account is against Meta’s terms, accounts do get restricted, and there is no pattern anyone can predict. We will pair it if you want it. We exclude it from every uptime commitment and a ban is not a refundable event. If the channel matters to your work, use Telegram or Slack, or a WhatsApp Business API number, which is permitted.
Can you read my assistant’s messages? +
Not as a matter of course, and not silently. Hosting means we can technically reach the cell, which is true of every managed host and which most of them do not mention. Reaching in requires a window you open, with a reason and a scope, that expires on its own. You can see whether it was used and revoke it at any time.
Why is this more expensive than $2.99 hosting? +
Because $2.99 buys a container. What you are paying for here is the metering, the monitoring, the guardrails and somebody answering. If you want a container and you are comfortable with Docker, self-host it. The software is MIT and free, and we will happily point you at the docs.
Could I pay less on a bundled plan? +
For heavy usage, yes. The calculator above will tell you when, and it does not round in our favour. Bundled credits are simpler; a ledger is honest. Pick the one you actually want.
Who deploys it, exactly? +
A delivery partner. AI Coach takes the order, holds the billing, monitors the running cell and keeps the record; the deployment and the onboarding are done by an independent partner we introduce you to by email. You will be talking to a named person, not a ticket queue, and you will know their name before any work starts.
What if the deployment never happens? +
Then you are not charged for it. On the 25% booking option the remaining balance is only taken when you confirm the handover, and if you never confirm, we never take it. If a partner goes quiet on you, tell us and we reassign it or refund the booking.
What happens if I leave? +
You get a 30-day export window covering the state directory, the memory and the logs. We suspend rather than delete when a subscription ends, precisely so that window is real.
Is this an official OpenClaw product? +
No. OpenClaw is open-source software released by other people under the MIT licence, and its name and logo are their trademarks. We are not affiliated with them. We sell hosting, setup and support for it.
Tell us what you want it to do
The order form asks what you want watched, what it may act on, and how you want to pay. A delivery partner then takes it from there and gets in touch with you directly.
Start your order →Pay in full, book with 25%, or take a free first month. Nothing recurring starts until you confirm your assistant has been handed over.
Assistant service terms · General terms · Privacy
OpenClaw is open-source software published by third parties under the MIT licence. The OpenClaw name and logo are their trademarks. AI Coach is not affiliated with, endorsed by or sponsored by OpenClaw AI, and provides hosting, setup and support services only.