Updated
The short answer. Claude Code runs on your machine and sends each turn of a session to the model provider. That request carries your prompts, the contents of files Claude Code reads, and the output of the commands and tools it runs. A key in a .env file or a customer record in a log travels with it.
SUPERWISE® Sentinel sits between Claude Code and the provider. It replaces emails, phone numbers, account numbers, and API keys with a placeholder before the request leaves, and Claude Code keeps working as before.
What reaches the model provider without a gateway
Anthropic’s documentation is direct about it. Claude Code runs locally, and to interact with the model it sends data over the network, including all user prompts and model outputs, encrypted in transit (Data usage). What the model sees is the session’s context window, which holds your conversation history, file contents, command outputs, and your CLAUDE.md (How Claude Code works).
- Your prompts. Everything you type or paste, including a stack trace with a connection string in it.
- Files it reads. Claude Code reads files in your project to do the task. A file it opens becomes part of the context.
- Tool and command output. Test runs, logs, query results, and anything an MCP server returns feed back into the next request.
On the provider side, Anthropic states a standard 30-day retention period for commercial accounts (Team, Enterprise, and API), and 30 days or five years for consumer accounts depending on the model-improvement setting (Data usage). Claude Code also supports routing through an LLM gateway, which it reaches through the ANTHROPIC_BASE_URL variable (Other LLM gateways). Sentinel is that kind of gateway.
With the Windows app
For Windows 10 and 11. The app runs a local Sentinel gateway as a background service, points your AI tools at it, and adds a tray icon that shows whether you are protected. It needs no Python and no Docker (Sentinel for Windows guide).
- Download and install. Get the installer from Sentinel for Windows and run it. It installs just for you, with no admin rights needed.
- Sign in. Open SUPERWISE Sentinel from the Start menu and click Connect. Your browser opens once: sign in, or create your free account.
- Approve this PC. Confirm the device in the browser. You see Access Approved, and there is no API secret to copy.
- Check the banner. Back in the app, the Dashboard shows a green Protected banner and your connected Sentinel. The Tools tab lists the AI tools it found on the PC, Claude Code among them, and whether Sentinel is enforcing for each.
- Run Claude Code. Open a new terminal and run
claude. Its traffic is inspected and the guardrails applied before anything leaves the machine.
With the CLI on Windows, macOS, or Linux
You need a SUPERWISE account and Python 3.11 or later with pip. Docker Desktop is needed only to run a gateway on your own machine (Get started).
- Install the CLI.
pip install superwise-sentinel-cli sentinel --version - Run the guided setup.
Answersentinel quickstartNto start a local gateway in Docker, oryto connect to a Sentinel your team already runs and paste its address. Press Enter to proxy for every provider. The CLI then setsANTHROPIC_BASE_URLto point at the gateway (Sentinel CLI proxy). - Test a prompt.
It prints whether the prompt passed, was redacted, or was blocked, with the redacted text, and never calls the model.sentinel test --text "My email is john.doe@example.com and my key is sk-proj-abc123" - Run Claude Code. The setting applies to new shells, so open a fresh terminal and run
claude. To route directly to the provider again, runsentinel proxy off.
For a shared gateway in your own AWS, GCP, or Azure account, see the Sentinel deployment guide.
What Sentinel replaces
Each guardrail either replaces what it finds with placeholder text and forwards the request, or blocks the request outright. You choose per guardrail, and you can change the placeholder text (Guardrails).
| What | Examples | Documented in |
|---|---|---|
| Email addresses | A customer email in a log line or a support ticket | PII redaction |
| Phone numbers | US and international numbers | PII redaction |
| Account numbers | Bank account numbers, IBANs, and credit card numbers | PII redaction |
| API keys and credentials | OpenAI, Anthropic, and Google API keys, AWS access keys, GitHub and Slack tokens, Stripe keys, JWTs, and bearer tokens | Secret and credential detection |
| Government IDs | Social Security numbers, passport numbers, and tax IDs | PII redaction |
Before and after
A prompt as Claude Code would send it, and as the provider receives it through Sentinel.
Sent by Claude Code
Why does the export fail for jane.doe@example.com?
She called from 415-555-0132.
The job uses AWS_ACCESS_KEY_ID=AKIAIOSFODNN7EXAMPLEReceived by the provider
Why does the export fail for REDACTED?
She called from REDACTED.
The job uses AWS_ACCESS_KEY_ID={{REDACTED}}Placeholders shown are the documented defaults. Your raw prompts and responses are never sent to SUPERWISE; the control plane receives counts, which rule fired, and latency (Data privacy).
Also worth setting in Claude Code
Sentinel cleans what is sent. Claude Code’s own permission rules decide what it may read in the first place. A deny rule such as Read(./.env) or Read(./secrets/**) blocks its file tools from reading those paths (Configure permissions). Anthropic’s security page covers permission modes, sandboxing, and prompt injection.
Next steps
Sources
All read on 2026-10-05.
- Anthropic, Claude Code docs: Data usagehttps://code.claude.com/docs/en/data-usage
- Anthropic, Claude Code docs: How Claude Code workshttps://code.claude.com/docs/en/how-claude-code-works
- Anthropic, Claude Code docs: Securityhttps://code.claude.com/docs/en/security
- Anthropic, Claude Code docs: Configure permissionshttps://code.claude.com/docs/en/permissions
- Anthropic, Claude Code docs: Other LLM gatewayshttps://code.claude.com/docs/en/llm-gateway
- SUPERWISE docs: Get startedhttps://docs.superwise.ai/docs/getting-started
- SUPERWISE docs: Sentinel for Windowshttps://docs.superwise.ai/docs/sentinel-for-windows
- SUPERWISE docs: Sentinel CLI proxyhttps://docs.superwise.ai/docs/sentinel-cli-proxy
- SUPERWISE docs: Data privacyhttps://docs.superwise.ai/docs/data-privacy
- SUPERWISE docs: PII redactionhttps://docs.superwise.ai/docs/pii-redaction
- SUPERWISE docs: Secret and credential detectionhttps://docs.superwise.ai/docs/secret-credential-detection