GuidesSecurity

Is it safe to run your AI agent on a cloud machine, or should it stay on one you can unplug?

A security writer's case for a Mac mini at home, taken seriously: what a host can and cannot see, what “unplug” maps to on a rented machine, where local genuinely wins, and Everpod's own answer.

September 5, 2026Updated September 8, 2026The Everpod team
The short answer

It depends on what the agent holds and what it is allowed to do, and the objection’s strongest form deserves a straight answer: whoever runs the hardware can, in principle, read what is on it. So the real questions are who that is, what they commit to in writing, and whether your threat model includes them at all. For most agents the likelier dangers are elsewhere: a laptop that also holds your whole life, a page that talks the agent into something, a Gateway left open to the internet. The split one practitioner proposed is the sane middle: “Cloud for drafts. Local for anything that can spend money or talk to a customer.” The point is to make that split deliberately rather than by default.

The objection, stated fairly

A security writer put it well in August 2026, arguing for a Mac mini in a home DMZ over a rented machine: “The agent harness is such an intimate place that I don’t like the idea of it being some VM in some giant hosting provider’s fleet. If you don’t have physical control, you shouldn’t think that you have any other type either.” He is right about the limit case. An agent harness holds your credentials in the clear (it has to, to use them), your conversations, and often a browser signed into your accounts. On someone else’s hardware, the someone else has physical access to all of it, and no encryption the agent can use while running changes that.

Where the argument overreaches is in treating physical control as the only control. Control is also revocation, isolation, and knowing exactly who can look and when. A machine in your house that you administer badly is less controlled than a rented one you can wipe from your phone in a minute.

What a host can see, and what it cannot avoid

Plainly: the disk, the memory, and the network traffic in and out. That is true of any hosting provider for any workload, and it is why the relationship is one of policy rather than cryptography. What you can evaluate is written down. Who may access the machine, for what reasons, and how that access is held. Where the data physically lives and where its backups go. How long things are kept, and what deletion means. Who else is in the chain (the model provider, the chat platform) and what they see. A provider that answers those questions specifically is offering you something checkable; one that answers with “bank-grade security” is not. Who can see an agent’s conversations walks the whole chain, because the host is one party of four and rarely the most exposed one: the model provider reads every message by design, wherever the machine is.

What “unplug” maps to on a rented machine

The physical-control argument has a strong intuition behind it: if things go wrong you pull the cable. The cloud equivalent is a set of levers that, taken together, are faster than a cable and work from another continent.

A Mac mini in your house has none of these by default. You can add them, at which point the difference between it and a well-run cloud machine is the physical-access question alone.

Where local genuinely wins

Three cases. First, the agent holds credentials to money or customers and you want no third party with physical access in the loop, full stop. That is a legitimate line to draw, and it is the “local for anything that can spend money” half of the split. Second, data-residency rules that name the premises. Third, the network itself: an agent that browses from your home address is treated as a person by websites that block datacenter ranges outright, which is the one problem a cloud machine cannot solve alone.

Where the cloud is the safer choice

The commonest agent setup is not a Mac mini in a DMZ. It is the owner’s own laptop, and the laptop is the worse security boundary: it holds your password manager, your signed-in browser and your files beside an agent that reads untrusted web pages all day. A separate machine, anywhere, fixes that. The cloud adds the parts a home setup struggles with: it is always on, it is not on your home network (an agent compromised at home is inside your house’s trust boundary), it is patched and backed up by someone whose job that is, and it can be wiped from anywhere. For research, monitoring, drafting, and anything that reports back to you rather than acting on the world, that is a better position than most homes.

Everpod’s answer

What Everpod commits to, as written in its privacy policy and security overview. Each customer’s agent runs on a machine of its own, hosted in Europe. The machine accepts no incoming connections from the open internet; you reach it through a private, authenticated path tied to your email. We do not access or read a pod’s content except with your permission during support, or where required for security, abuse investigation, or by law. Maintenance access exists (setting up, approving device pairings, security checks, managed updates) and is held tightly: sign-in by cryptographic key, password login disabled, every use approved personally by the founder. Backups are daily and restores are tested. When you cancel, the pod stops at the end of the paid period, and after a short grace window we permanently delete the machine, its contents and its backups and revoke its credentials.

That is one provider’s answer sheet. The point of this page is that you should be able to read one for any AI agent hosting you consider, and that if you cannot, the physical-control argument wins by default. Where you can, weigh the actual commitments against the actual risk of the agent you are running. Drafts and research on a well-run cloud machine; the send button and the bank login wherever you have decided you can live with the answer to “who can look.”

Your own cloud agent, set up for you.

Everpod runs OpenClaw on a private, always-on computer of its own: set up, secured and backed up, with model usage included. You name your agent, and say hello about fifteen minutes later.

Create your agent

First month half price, then $29/mo · model usage included · cancel anytime

Wondering what you’d do with one? See what a cloud agent can do