Module 11 — Security & compliance

In this module

You'll understand exactly what Claude Code sends to the servers, how to lock down access with sandboxing and granular permissions, set up audit and monitoring, protect secrets, and build a case to convince your CISO.

11.1 — What Claude Code sends (and doesn't send)

The first legitimate question when you introduce Claude Code to a team: what data leaves your machine? The answer is transparent and verifiable.

Claude Code is a local client that communicates with the Anthropic API. Three categories of data are sent: your prompts (what you type and the history of the current conversation), the content of files read (only those Claude consults via the Read tool to accomplish a task), and the outputs of executed commands (result of git diff, test output, etc.). This data constitutes the context the model needs to respond.

What is not sent: your entire codebase at startup (no global scan), your system environment variables, your SSH keys, your global configuration files, or the content of directories outside the project. The context size is limited (up to 1M tokens depending on the model), Claude Code couldn't send gigabytes even if it wanted to.

The flow is controllable in real time. Each tool call (Read, Bash, Grep) is visible in the interface. In default mode, nothing leaves without your explicit approval, it's an "explicit consent" model. And when you close your session, the context disappears. The next conversation starts from scratch.

┌─────────────┐          ┌──────────────────┐
│ Your machine│ ───────► │  Anthropic API   │
│             │  Sent:   │                  │
│  - prompts  │  1. Prompts                 │
│  - files    │  2. Files read              │
│  - terminal │  3. Command outputs         │
└─────────────┘          └──────────────────┘
      ✗ No global scan
      ✗ No system env variables
      ✗ No SSH keys
      ✗ No silent telemetry

Key takeaways

• Only files explicitly read, prompts, and command outputs are sent.

• No global repo scan at startup, Claude reads on demand.

• Every action is visible and requires approval in default mode.

• The context is ephemeral: it disappears at the end of the session.

In this module

  1. 11.1 — What Claude Code sends (and doesn't send) Available
  2. 11.2 — Data policy by Anthropic plan
  3. 11.3 — OS-level sandboxing
  4. 11.4 — Granular permissions: allow, ask, deny
  5. 11.5 — Managed settings: IT governance
  6. 11.6 — Security and audit hooks
  7. 11.7 — Telemetry and monitoring with OpenTelemetry
  8. 11.8 — Protecting secrets and credentials
  9. 11.9 — Guarding against prompt injection
  10. 11.10 — Convincing your CISO: the adoption plan

Locked content

Unlock the full course to access this module.

Unlock

Already purchased? Recover access