TrustKernel ships a $149 AI computer designed to keep agents off your phone

Li Wenhao's PlugClaw pairs a USB-C Android computer with cloud inference inside a hardware-protected environment that TrustKernel says keeps data hidden from both itself and the cloud provider.

By · Published

Primary source: PR Newswire

Why it matters

PlugClaw turns agent security into a hardware purchase: isolate credentials and workflows first, then call larger cloud models only when needed.

A minimalist dark computer device plugs into a smartphone on a desk, casting a contained glow while subtle light wisps extend from the screen.

Li Wenhao, the operating-system security researcher who founded TrustKernel out of Shanghai Jiao Tong University, began worldwide shipments of PlugClaw on September 4th, giving his decade-old security research a new job: containing AI agents before they gain access to a user's primary computer.

The PlugClaw device is a complete Android and Ubuntu computer built into a USB-C stick. TrustKernel lists a $149 starting price, with no required subscription, and includes credits for cloud model usage. Buyers can also supply their own API keys.

TrustKernel first announced PlugClaw on August 12th. The September 4th shipping announcement moves it from preorder into general availability and adds free access to confidential-model inference running on newly deployed servers.

PlugClaw measures 50 x 19 x 8 millimeters. TrustKernel's product page lists a weight of 14.3 grams, while the shipping announcement rounds that to 15 grams. Inside are a MediaTek Helio G80 processor, up to 6 GB of memory, and as much as 128 GB of encrypted storage. PlugOS, TrustKernel's hardened Android system, handles applications, while Ubuntu runs the agent environment.

That hardware is modest by workstation standards. It is enough to run the agent, its Android apps, credentials, files, memory and workflows in a separate physical environment. Larger models remain in the cloud.

Li takes TrustKernel's security stack to consumers

PlugClaw follows a path Li started as a student rather than a quick turn into the AI-device market. His Shanghai Jiao Tong University profile lists research in operating systems, virtualization, mobile security and ARM TrustZone, along with internships at Intel Asia-Pacific Research and Development and the KEEN security group.

Li earned a software engineering degree and a second bachelor's degree in business administration at Shanghai Jiao Tong University before entering its master's program. His published work covered trusted execution environments, mobile attestation and virtualization. TrustKernel says Li and other university researchers developed the T6 secure operating system before commercializing their work through TrustKernel in 2015.

TrustKernel spent the following decade selling trusted execution environments and secure operating-system technology to device makers and application developers. TrustKernel says its products have appeared in thousands of device models from over 100 manufacturers. TrustKernel also claims its security technology has reached over one billion smartphones, vehicles and connected devices, though that cumulative figure has not been independently audited.

The records disagree on the size of TrustKernel's January 2019 Series A. A 36Kr funding database lists approximately RMB10 million, while 36Kr's coverage of the financing described it as several tens of millions of yuan. Both identify QF Capital as the lead investor. TrustKernel has not attached a valuation or fresh financing announcement to the PlugClaw rollout.

PlugClaw pushes that enterprise and embedded-device experience into a direct hardware product for individual users. Li's thesis is that an autonomous agent should get a separate computer instead of receiving broad permissions on the laptop or phone where its owner keeps personal accounts, files and photographs.

The host becomes a screen, not the agent's home

When PlugClaw connects to a phone, tablet or computer, the host supplies its display and input. TrustKernel says the agent operates inside the stick and does not need administrator access to the host. A controlled shared folder can move selected files between the two environments.

TrustKernel says PlugClaw supports Android devices, iPhone 15 and later, iPads, Apple Silicon Macs, Windows and Linux computers. The shipping announcement also names HarmonyOS. The user's agent environment, applications and stored memory travel with the stick rather than remaining on each host.

OpenClaw provides the agent runtime. TrustKernel has extended it with an Android graphical-interface agent and Android-Use, enabling PlugClaw to operate Android apps, fill forms, handle messages and run scheduled workflows. TrustKernel's product page also describes integrations with messaging services including WhatsApp, Telegram, WeChat, DingTalk and Feishu.

Security around OpenClaw is becoming its own product category. Nvidia's NemoClaw wraps OpenClaw deployments with policy controls, lifecycle management and software sandboxing. TrustKernel is making a hardware version of the isolation argument, placing the agent on a physically separate Android computer that can move between hosts.

Confidential inference moves frontier-model requests into a protected environment

PlugClaw uses a hybrid design. Conversations, files, knowledge bases and agent state are stored on the USB-C device, according to TrustKernel. When a task needs a frontier model, TrustKernel says the request is processed inside a cloud-based hardware Trusted Execution Environment, or TEE, designed to prevent both TrustKernel and the cloud provider from reading the data.

TrustKernel has not identified the cloud provider or published an independent security audit, hardware-attestation details or a technical account of how frontier models operate inside that confidential environment. Its privacy claim therefore rests on TrustKernel's description of the architecture rather than independently disclosed test results.

TrustKernel says preview users selected confidential models much more often than a cheaper conventional option. The announcement supplies no participant count, percentage or testing method, so the claim says little about demand. The free inference offer also has undefined usage limits and duration in the shipping announcement.

The strongest case for PlugClaw does not depend on replacing a laptop or running a frontier model locally. Li is selling a boundary: a small computer where an agent can hold credentials, install apps and make mistakes without inheriting unrestricted access to the device its owner uses every day. Shipping hardware gives TrustKernel a chance to prove that boundary outside the laboratory and the OEM contracts where Li built the underlying technology.

Reader comments

Conversation for this story loads after sign-in.