A transparent look at how we manage AI tooling risks to keep your data, credentials, and systems protected at every step.
Modern AI development tools like Claude Code can dramatically accelerate work — but they also introduce real security considerations that every client deserves to understand. We believe in radical transparency about how these tools operate, what risks exist, and exactly how we mitigate them.
This briefing walks through every significant risk vector and the specific controls we have in place — before we ever touch your project.
Fully documented and controlled
Every action requires explicit sign-off
Scoped access, not broad permissions
Our security posture is built around understanding each capability of the AI toolchain and applying the right control. Here's the full picture at a glance.

AI tools can read, write, and delete files in any directory they're pointed at — which means scope control is critical from day one.
Without proper scoping, an AI tool operating from a home directory could inadvertently access documents, stored credentials, browser profiles, and personal files — far beyond the intended project scope. A technique called prompt injection — where malicious content hidden inside a file tricks the AI — could cause data exfiltration or corruption if access is too broad.
We always run AI tools inside specific, dedicated project folders — never from a home directory or root path. This creates a hard boundary: the AI simply cannot see what lives outside the project scope. Your files stay yours.
The ability to run arbitrary shell commands is the highest-risk capability in any AI development tool. We treat it accordingly.
Malicious instructions hidden in code comments, documentation, or web content that the AI reads could potentially cause it to execute destructive commands — wiping files, exfiltrating data, or modifying system configurations — all without the developer noticing in the moment.
By default, our AI tools always ask before running any shell command. We never configure shell commands for auto-approval, and we never use the --dangerously-skip-permissions flag. Every command is reviewed by a human before execution — full stop.
No command runs silently in the background on your project. You retain visibility and control over every system-level action taken during development, with a clear audit trail of what was run and why.
Connected services like Slack, Notion, Google Calendar, and Airtable each represent an external attack surface that requires careful permission management.
When an AI tool is connected to external services, content from those services becomes part of the AI's context. That means a carefully crafted Slack message, a Notion page, or a calendar invite could contain hidden instructions designed to manipulate the AI's behavior — a technique known as prompt injection via connected services.
AI tools allow certain actions to be pre-approved so they run without prompting. This is a double-edged sword — useful when scoped tightly, catastrophic when over-broad.
Read-only, well-scoped tools such as Read, Glob, and Grep. These can only retrieve information — they cannot modify, delete, or transmit anything.
Shell commands (Bash/PowerShell), write operations, file deletion, and any tool that touches external services. These always require explicit human approval before execution.
Our settings.json contains no blanket tool approvals. Every new permission is evaluated against the principle of least privilege before being added.
Credentials passed through an AI tool's context window — even inadvertently — represent a real data exposure risk. We have explicit controls to prevent this from happening.
When an AI tool reads a file that contains credentials — an .env file, AWS keys, database passwords, or API tokens — those values pass through the API request. While Anthropic's data handling policies provide a layer of protection, the principle of never exposing credentials in the first place is the only truly safe approach.
.claudeignore SolutionWe configure a .claudeignore file in every project that explicitly blocks the AI from reading sensitive files and directories. Think of it as a .gitignore — but for your AI assistant.
.env files are ignored
The --dangerously-skip-permissions flag does exactly what it sounds like — it disables all permission prompts, allowing the AI to act with complete autonomy. No confirmations. No safeguards. No human in the loop.
The only legitimate use of this flag is inside a fully isolated, disposable environment such as a sandboxed VM or Docker container with no access to real data or services. We document when and why such environments are used.
Our baseline configuration is the safest possible starting point — and we only deviate from it with explicit justification.
Our settings.json has zero allowedTools overrides. Every tool action — read or write — requires explicit approval. This is the safest default configuration and our starting point for every engagement.
Connected services with write access (Slack, Notion, Calendar, Airtable) are treated as elevated-risk surfaces. We actively monitor for prompt injection patterns in content these services surface to the AI.
Sensitive directories and credential files are excluded from AI access on every project, preventing inadvertent credential exposure through the API.
Prompt injection is the practice of embedding hidden instructions inside content the AI reads — a comment in a file, a message in Slack, a note in a Notion page — designed to redirect the AI's behavior without the developer's knowledge. It's the single most insidious risk in AI-assisted development, and defending against it requires both technical controls and human vigilance.
No single control eliminates prompt injection risk entirely — defense requires layering multiple safeguards so that even if one layer is bypassed, the others catch malicious instructions before damage is done.
We will never use --dangerously-skip-permissions outside of an isolated, sandboxed environment that has no access to your data or systems.
Bash and PowerShell commands will never be added to the auto-approval list. Every shell command is reviewed by a human before it runs.
We will never ask the AI to read .env files, AWS credentials, API keys, or any file containing secrets. These are blocked at the .claudeignore level.
AI tools are always scoped to a specific project folder. Your personal files, documents, and system directories are never within reach.

Security isn't just about technical controls — it's about trust. We maintain full transparency with every client about how AI tools are being used on their project:
Request only the permissions needed for the task at hand. Never accumulate standing access.
Every consequential action — shell commands, writes, external service interactions — requires a human review before execution.
Any content the AI reads from external services is treated as potentially malicious until proven otherwise.
Clients always know what tools are in use, what permissions are configured, and what actions are being taken on their behalf.
Security isn't a checkbox — it's a practice. We bring the same rigor to protecting your data and systems as we bring to building great software. If you have questions about any aspect of our security configuration, we welcome the conversation.
Ask to see our current configuration settings and .claudeignore setup at any time.
No security question is too detailed. We believe informed clients are the best partners.
Every engagement begins from the safest default configuration — with your approval required every step of the way.
Security-First AI Development