Ideas from the work, sent by email. Sign up for the newsletter →
runpoint.
← All ideas
Field noteFeb 16, 2026Sam Gaddis

Is Claude Code Safe? The Practical Answer.

What Claude Code sends, whether Anthropic trains on your code, and the settings that matter for confidential business work.

If you've read our guide to using Claude Code without becoming a developer, you know we think it is one of the most useful AI tools a businessperson can learn.

The question we hear next is reasonable: what happens to my data?

Here is the practical answer. Claude Code is safe enough for ordinary business work when you use the right account, understand what it sends to the model, and keep its permissions under control. It is still a cloud service. You should not treat it like an offline vault.

Last reviewed August 12, 2026. Anthropic changes this product often, so we link to its current documentation throughout.

What Claude Code sends

Claude Code runs on your computer, but the model does not. Your prompts, the model's responses, and the file contents or command output Claude uses are sent to your model provider so the model can do the work.

That does not mean Claude uploads your whole computer. It works with the files and tools available to the session. But if Claude reads a confidential document to answer your question, you should assume the relevant contents were sent to the provider.

Anthropic says this traffic is encrypted in transit. Storage and encryption at rest depend on whether you connect through Anthropic, Amazon Bedrock, Google Cloud, Microsoft Foundry, or another supported provider. The details are in Anthropic's current Claude Code data usage documentation.

Does Anthropic train on your code?

It depends on the account you use.

For Free, Pro, and Max accounts, Anthropic gives you a setting that controls whether new chats and coding sessions can be used to improve future models. You can review it under Data Privacy Controls. If model improvement is on, Anthropic says that data may remain in a de-identified training pipeline for up to five years. If it is off, the standard retention period is 30 days.

For Team, Enterprise, and API customers, Anthropic says it does not train generative models on code or prompts under its commercial terms unless the customer deliberately opts into a program that allows it.

That distinction matters more than the logo on the app. A Max subscription is a consumer account with consumer controls. Team and Enterprise are commercial accounts with organization-level terms and administration.

The setup we recommend for an individual

If you use Free, Pro, or Max:

  1. Open Data Privacy Controls and turn off model improvement.
  2. Do not send /feedback, /bug, or /share reports from a sensitive session. Those reports can include conversation history and code, and Anthropic says submitted feedback is retained for five years.
  3. If you do not need telemetry, error reports, or surveys, set:
CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1

That environment variable does not stop the model request itself. Claude still needs to send the work you ask it to do. It shuts off the optional traffic described in Anthropic's data usage guide.

For especially sensitive work, use a separate project folder and give Claude only the files it needs. Do not leave credentials in plain text inside that folder.

The setup we recommend for a company

Use a commercial account when employees are working with client information, internal financials, contracts, or proprietary code. Team is the simplest starting point for a small company. As of this review, Anthropic lists a two-person minimum, with Standard seats at $20 per person per month when billed annually or $25 monthly, and Premium seats at $100 per person per month when billed annually or $125 monthly. Check the current Team plan page before buying because these prices and limits change.

Enterprise adds stronger administrative and compliance controls. Companies with stricter requirements can also run Claude Code through an approved Anthropic API organization, Amazon Bedrock, Google Cloud, or Microsoft Foundry.

Whichever route you choose, write down four decisions:

  1. Which account or model provider employees should use.
  2. Which folders and repositories Claude may access.
  3. Which commands can run without asking.
  4. Which categories of data should never go into an AI session.

That policy can fit on one page. The point is to make the decision once instead of asking every employee to invent a security policy at their desk.

Claude Code asks before it acts

Claude Code starts with read-only permissions. It can inspect common files and run certain read-only commands, then asks before it edits files or runs commands that can change your system.

You can loosen those controls. Accept Edits mode automatically approves file changes and some filesystem commands. Teams can allow specific commands, and there is also a bypass mode intended for controlled environments. Anthropic's security documentation explains the current permission model.

So the useful rule is not “Claude can never act without approval.” The useful rule is: Claude starts cautiously, and you decide how much authority it gets.

For everyday work, stay in the default permission mode until you understand the commands Claude is proposing. Use Plan mode when you want analysis without changes. Review the work before you approve it.

What about confidential or privileged work?

Claude Code can be used with confidential business information, but the account and configuration should match the sensitivity of the work.

We would not paste an acquisition agreement, a complete customer database, or a folder of privileged client material into a consumer Max session just because model improvement is turned off. For that kind of work, use commercial terms, limit the files Claude can reach, and follow the same internal review you would apply to any other cloud service handling the information.

For lawyers, accountants, and other regulated professionals, the answer is not a blanket yes or no. Your professional obligations, client agreements, and company policy still apply. Claude Code does not make those obligations disappear, and its use should be approved the same way your firm approves other cloud software.

What about HIPAA?

Do not put protected health information into Free, Pro, Max, or Team accounts.

Anthropic offers HIPAA-ready Enterprise and API configurations with a Business Associate Agreement, but Claude Code is covered only in specific qualified configurations. Anthropic currently says Claude Code requires zero data retention to fall under its BAA, and some newer covered models cannot be used with zero data retention. Confirm the exact organization and model setup before using Claude Code with protected health information. Anthropic maintains the current requirements on its HIPAA-ready Enterprise page.

Bottom line

Claude Code is not uniquely dangerous. It has the same basic issue as every useful cloud tool: the service has to receive the information you ask it to process.

For ordinary work, turn off model improvement on a consumer account, avoid sending feedback from sensitive sessions, keep the default permissions until you understand them, and be deliberate about which files Claude can read.

For company work, use commercial terms and set a short internal policy. For regulated or unusually sensitive work, confirm the exact configuration before you begin.

That is enough for most people. You do not need a security committee to use Claude Code, but you should know which version of the deal you signed.

The Runpoint Letter

Get the next issue

One idea, one number, one thing you can do Monday. Three minutes.

Sign up for Field Notes →