OpenClaw promised a self-hosted AI assistant I could actually leave running, but Hermes Agent is the one that delivers it
… The repo has a SECURITY.md with a 90-day coordinated disclosure window, a private security inbox, and an explicit list of what is in and out of scope. Hermes moves fast too, but it has explicit guardrails around review, CI, dependency pinning, disclosure, and runtime boundaries. …