AI Coach Assistant · runs OpenClaw, managed

Managed OpenClaw hosting, with the bill in plain sight

A personal AI assistant on your own isolated cell. You message it on Telegram or Slack, it watches what you tell it to watch, and everything it wants to send waits for your tap. We set it up, we patch it, we watch it. You can see what every model call cost.

From $29.00/mo plus metered model spend. Not affiliated with OpenClaw AI.

What people actually use it for

Not a feature list. Three things our own cell does, described the way the person who asked for them described them.

The 7am brief

It reads overnight mail, your calendar and the two repos you care about, and sends one message before you open a laptop. Nothing leaves your account to write it.

Reply drafting

A client mails you. It writes the reply in your voice, with the thread and the invoice history already in mind, and holds it until you tap send.

The thing you keep forgetting

Chase the unpaid invoice on day 31. Nudge the supplier who has gone quiet. It watches, it asks, you decide.

Two tracks, split by who does the setup

The cell is the same. What changes is whether you pair the channels and wire the connections, or we do it with you on a call.

Self-Serve

$29.00 /month

no setup fee

  • 1 cell, 1 channel
  • Guided setup wizard and docs
  • Email support, best effort
  • Critical patches inside 24h
  • Isolated container per tenant
  • Tracks the current minor version
  • Model spend metered, capped at $50.00/mo by default
Choose Self-Serve
Most people want this

Managed

$79.00 /month

plus $199.00 one-time setup

  • 1 cell, 2 channels
  • We pair, wire and seed it with you
  • 8-business-hour support response
  • Critical patches inside 24h
  • Isolated container per tenant
  • Tracks the current minor version
  • Model spend metered, capped at $100.00/mo by default
Choose Managed

Business

$199.00 /month

plus $499.00 one-time setup

  • 3 cells, 3 channels
  • We pair, wire and seed it with you
  • 4-business-hour support response
  • Critical patches inside 24h
  • Hardened runtime (gVisor or Kata)
  • Version pinning up to 90 days
  • Service credit if we miss cell uptime
  • Model spend metered, capped at $300.00/mo by default
Choose Business

Reselling to your own clients, or need more than three cells? That is a conversation, not a checkout. Get in touch.

What it will actually cost you

The cell fee is fixed. Model spend is not, so here is the arithmetic rather than a promise. Drag it to your own usage. It will tell you when a bundled plan would be cheaper.

Model class
Plan
Assistant turns / month
1,170
Model spend, at cost
$47.39
With 1.3x markup
$61.61
Plan fee
$29.00
Monthly total$90.61

Self-Serve, Sonnet class, 1,170 turns. That is $41.61 more than a $49.00 bundled plan. Worth it if you want to see the ledger, or if a bundled plan would throttle you. Otherwise it is not.

Estimates, not a quote. Assumes ~10k input and ~700 output tokens per turn, which is what a turn with memory and tool calls actually costs. Prompt caching cuts input spend substantially in practice, so these run high rather than low.

It cannot send anything without you

Three tiers of authority. Every cell is handed over on Draft, and only you can raise it. This is the part most autonomous-assistant pitches leave out.

Observe

On by default

Reads, summarises, watches, answers. Nothing leaves your account. Most of the value lives here, and it cannot cause an incident.

Draft

Where every cell starts

Writes the email, the reply, the post, then stops and waits for your tap. This is the default for anything outbound, and it is what makes an autonomous assistant safe to buy.

Act

You turn this on, per tool

Sends, books, pays, deletes. Granted one tool at a time, revocable, always logged. Never on when a cell is handed over, whatever was asked for at checkout.

The threat model has a name and a date

In July 2026 a researcher chained three OpenClaw vulnerabilities from a single WhatsApp message to credential theft, a Docker sandbox escape and code execution on the host machine. That is the specific attack this is built against. Any host that will not tell you what they are defending against has not thought about it.

One cell per customer
A full Gateway per tenant with its own state directory, credentials, workspace, token and loopback-only port. Never a shared Gateway, because OpenClaw’s trust boundary is the Gateway itself.
No shell on channel-facing sessions
exec is removed from the tool allowlist for anything reachable from a message. This is the specific control that breaks the published attack chain.
Default-deny egress
Your cell can reach the connections you approved and nothing else. Contains credential exfiltration even after a successful prompt injection.
Secrets never sit in the cell
The control plane holds them; the cell gets short-lived scoped tokens. It is a worker that holds no secrets and cannot spend.
The cap is enforced outside the agent
Spend limits live in the control plane, so a compromised or looping agent still cannot spend past them.
Backups are treated as credentials
A cell state directory is a credential store. Encrypted, access-logged, handled like a token.

If we are ever compromised, affected customers hear within 72 hours, with what happened and exactly what to rotate.

It does not arrive empty

A bare cell is a blank prompt and a docs link. Yours arrives with vetted skills already installed and your MCP connections already wired, drawn from the catalogue AI Coach already runs. Connection config is encrypted at rest and never stored inside the cell.

Where you talk to it

Every channel it supports, including the one we would rather you did not use.

Telegram Slack Discord Signal iMessage WhatsApp

About WhatsApp, before you ask

Automating a personal WhatsApp account breaches Meta’s terms. Numbers do get restricted, sometimes within a week, sometimes never, with no pattern anyone has found. We will pair it if you want it, and we exclude it from every uptime commitment, because nobody can honestly promise a channel that Meta can revoke. For anything your work depends on, use Telegram, Slack or a WhatsApp Business API number.

What happens when OpenClaw ships

Upstream moves fast. Security patches are not optional and are not an imposition; everything else you get notice about.

Change What we do Notice Opt out
Critical security patch Applied immediately within 24h None
Other security patch Next maintenance window within 7 days None
Minor version Weekly window, under 10 min downtime 48 hours Defer once
Major version Staged on our own cell first 14 days 30 days, then required
Upstream breaks a channel We tell you, with the workaround or an ETA 1 business day None
Upstream is abandoned Full export, no lock-in. We track upstream, we do not fork it. 60 days None

Who actually sets it up

AI Coach runs the order, the billing and the monitoring. The deployment and the onboarding are done by a delivery partner, and we say so rather than implying a support team you never meet.

  1. 01

    You order

    Pick a plan, tell us what you want it to do, and choose how to pay.

  2. 02

    We introduce you

    A delivery partner gets your order by email, with you copied in. Reply-all and you are talking to them.

  3. 03

    They deploy it

    You agree the spec with them directly. They build it and hand it over.

  4. 04

    You confirm

    Only when you say it works does your plan start, and any balance get charged.

The questions worth asking

Answered plainly, including where the answer is not flattering.

Will my WhatsApp get banned? +

It might. Automating a personal WhatsApp account is against Meta’s terms, accounts do get restricted, and there is no pattern anyone can predict. We will pair it if you want it. We exclude it from every uptime commitment and a ban is not a refundable event. If the channel matters to your work, use Telegram or Slack, or a WhatsApp Business API number, which is permitted.

Can you read my assistant’s messages? +

Not as a matter of course, and not silently. Hosting means we can technically reach the cell, which is true of every managed host and which most of them do not mention. Reaching in requires a window you open, with a reason and a scope, that expires on its own. You can see whether it was used and revoke it at any time.

Why is this more expensive than $2.99 hosting? +

Because $2.99 buys a container. What you are paying for here is the metering, the monitoring, the guardrails and somebody answering. If you want a container and you are comfortable with Docker, self-host it. The software is MIT and free, and we will happily point you at the docs.

Could I pay less on a bundled plan? +

For heavy usage, yes. The calculator above will tell you when, and it does not round in our favour. Bundled credits are simpler; a ledger is honest. Pick the one you actually want.

Who deploys it, exactly? +

A delivery partner. AI Coach takes the order, holds the billing, monitors the running cell and keeps the record; the deployment and the onboarding are done by an independent partner we introduce you to by email. You will be talking to a named person, not a ticket queue, and you will know their name before any work starts.

What if the deployment never happens? +

Then you are not charged for it. On the 25% booking option the remaining balance is only taken when you confirm the handover, and if you never confirm, we never take it. If a partner goes quiet on you, tell us and we reassign it or refund the booking.

What happens if I leave? +

You get a 30-day export window covering the state directory, the memory and the logs. We suspend rather than delete when a subscription ends, precisely so that window is real.

Is this an official OpenClaw product? +

No. OpenClaw is open-source software released by other people under the MIT licence, and its name and logo are their trademarks. We are not affiliated with them. We sell hosting, setup and support for it.

Tell us what you want it to do

The order form asks what you want watched, what it may act on, and how you want to pay. A delivery partner then takes it from there and gets in touch with you directly.

Start your order →

Pay in full, book with 25%, or take a free first month. Nothing recurring starts until you confirm your assistant has been handed over.

Assistant service terms · General terms · Privacy

OpenClaw is open-source software published by third parties under the MIT licence. The OpenClaw name and logo are their trademarks. AI Coach is not affiliated with, endorsed by or sponsored by OpenClaw AI, and provides hosting, setup and support services only.