Guide · Claude Code

How to keep secrets and customer data out of Claude Code

What Claude Code sends to the model provider, and how to take the sensitive parts out before it leaves your machine.

Updated

The short answer. Claude Code runs on your machine and sends each turn of a session to the model provider. That request carries your prompts, the contents of files Claude Code reads, and the output of the commands and tools it runs. A key in a .env file or a customer record in a log travels with it.

SUPERWISE® Sentinel sits between Claude Code and the provider. It replaces emails, phone numbers, account numbers, and API keys with a placeholder before the request leaves, and Claude Code keeps working as before.

What reaches the model provider without a gateway

Anthropic’s documentation is direct about it. Claude Code runs locally, and to interact with the model it sends data over the network, including all user prompts and model outputs, encrypted in transit (Data usage). What the model sees is the session’s context window, which holds your conversation history, file contents, command outputs, and your CLAUDE.md (How Claude Code works).

  • Your prompts. Everything you type or paste, including a stack trace with a connection string in it.
  • Files it reads. Claude Code reads files in your project to do the task. A file it opens becomes part of the context.
  • Tool and command output. Test runs, logs, query results, and anything an MCP server returns feed back into the next request.

On the provider side, Anthropic states a standard 30-day retention period for commercial accounts (Team, Enterprise, and API), and 30 days or five years for consumer accounts depending on the model-improvement setting (Data usage). Claude Code also supports routing through an LLM gateway, which it reaches through the ANTHROPIC_BASE_URL variable (Other LLM gateways). Sentinel is that kind of gateway.

With the Windows app

For Windows 10 and 11. The app runs a local Sentinel gateway as a background service, points your AI tools at it, and adds a tray icon that shows whether you are protected. It needs no Python and no Docker (Sentinel for Windows guide).

  1. Download and install. Get the installer from Sentinel for Windows and run it. It installs just for you, with no admin rights needed.
  2. Sign in. Open SUPERWISE Sentinel from the Start menu and click Connect. Your browser opens once: sign in, or create your free account.
  3. Approve this PC. Confirm the device in the browser. You see Access Approved, and there is no API secret to copy.
  4. Check the banner. Back in the app, the Dashboard shows a green Protected banner and your connected Sentinel. The Tools tab lists the AI tools it found on the PC, Claude Code among them, and whether Sentinel is enforcing for each.
  5. Run Claude Code. Open a new terminal and run claude. Its traffic is inspected and the guardrails applied before anything leaves the machine.

With the CLI on Windows, macOS, or Linux

You need a SUPERWISE account and Python 3.11 or later with pip. Docker Desktop is needed only to run a gateway on your own machine (Get started).

  1. Install the CLI.
    pip install superwise-sentinel-cli
    sentinel --version
  2. Run the guided setup.
    sentinel quickstart
    Answer N to start a local gateway in Docker, or y to connect to a Sentinel your team already runs and paste its address. Press Enter to proxy for every provider. The CLI then sets ANTHROPIC_BASE_URL to point at the gateway (Sentinel CLI proxy).
  3. Test a prompt.
    sentinel test --text "My email is john.doe@example.com and my key is sk-proj-abc123"
    It prints whether the prompt passed, was redacted, or was blocked, with the redacted text, and never calls the model.
  4. Run Claude Code. The setting applies to new shells, so open a fresh terminal and run claude. To route directly to the provider again, run sentinel proxy off.

For a shared gateway in your own AWS, GCP, or Azure account, see the Sentinel deployment guide.

What Sentinel replaces

Each guardrail either replaces what it finds with placeholder text and forwards the request, or blocks the request outright. You choose per guardrail, and you can change the placeholder text (Guardrails).

WhatExamplesDocumented in
Email addressesA customer email in a log line or a support ticketPII redaction
Phone numbersUS and international numbersPII redaction
Account numbersBank account numbers, IBANs, and credit card numbersPII redaction
API keys and credentialsOpenAI, Anthropic, and Google API keys, AWS access keys, GitHub and Slack tokens, Stripe keys, JWTs, and bearer tokensSecret and credential detection
Government IDsSocial Security numbers, passport numbers, and tax IDsPII redaction

Before and after

A prompt as Claude Code would send it, and as the provider receives it through Sentinel.

Sent by Claude Code

Why does the export fail for jane.doe@example.com?
She called from 415-555-0132.
The job uses AWS_ACCESS_KEY_ID=AKIAIOSFODNN7EXAMPLE

Received by the provider

Why does the export fail for REDACTED?
She called from REDACTED.
The job uses AWS_ACCESS_KEY_ID={{REDACTED}}

Placeholders shown are the documented defaults. Your raw prompts and responses are never sent to SUPERWISE; the control plane receives counts, which rule fired, and latency (Data privacy).

Also worth setting in Claude Code

Sentinel cleans what is sent. Claude Code’s own permission rules decide what it may read in the first place. A deny rule such as Read(./.env) or Read(./secrets/**) blocks its file tools from reading those paths (Configure permissions). Anthropic’s security page covers permission modes, sandboxing, and prompt injection.

Next steps

Sources

All read on 2026-10-05.