Security-First AI Development

We Take AI Security Seriously. Here's the Proof.

A transparent look at how we manage AI tooling risks to keep your data, credentials, and systems protected at every step.

Client Security Briefing

Why This Matters

AI Tools Are Powerful — And That Power Demands Responsibility

Modern AI development tools like Claude Code can dramatically accelerate work — but they also introduce real security considerations that every client deserves to understand. We believe in radical transparency about how these tools operate, what risks exist, and exactly how we mitigate them.

This briefing walks through every significant risk vector and the specific controls we have in place — before we ever touch your project.

6 Risk Areas

Fully documented and controlled

Zero Auto-Approvals

Every action requires explicit sign-off

Minimal Footprint

Scoped access, not broad permissions

Security Overview

Six Risk Areas — All Accounted For

Our security posture is built around understanding each capability of the AI toolchain and applying the right control. Here's the full picture at a glance.

Risk Area 1

File System Access

AI tools can read, write, and delete files in any directory they're pointed at — which means scope control is critical from day one.

How We Control File System Access

The Risk

Without proper scoping, an AI tool operating from a home directory could inadvertently access documents, stored credentials, browser profiles, and personal files — far beyond the intended project scope. A technique called prompt injection — where malicious content hidden inside a file tricks the AI — could cause data exfiltration or corruption if access is too broad.

Our Mitigation

We always run AI tools inside specific, dedicated project folders — never from a home directory or root path. This creates a hard boundary: the AI simply cannot see what lives outside the project scope. Your files stay yours.

Risk Area 2

Shell Command Execution

The ability to run arbitrary shell commands is the highest-risk capability in any AI development tool. We treat it accordingly.

Shell Commands: Always Ask, Never Auto-Run

Why Shell Access Is High-Risk

Malicious instructions hidden in code comments, documentation, or web content that the AI reads could potentially cause it to execute destructive commands — wiping files, exfiltrating data, or modifying system configurations — all without the developer noticing in the moment.

The "Ask" Mode Commitment

By default, our AI tools always ask before running any shell command. We never configure shell commands for auto-approval, and we never use the --dangerously-skip-permissions flag. Every command is reviewed by a human before execution — full stop.

What This Means for You

No command runs silently in the background on your project. You retain visibility and control over every system-level action taken during development, with a clear audit trail of what was run and why.

Risk Area 3

MCP Server Connections

Connected services like Slack, Notion, Google Calendar, and Airtable each represent an external attack surface that requires careful permission management.

Managing External Service Connections

When an AI tool is connected to external services, content from those services becomes part of the AI's context. That means a carefully crafted Slack message, a Notion page, or a calendar invite could contain hidden instructions designed to manipulate the AI's behavior — a technique known as prompt injection via connected services.

Our Approach to MCP Security

  • Treat all external service content as potentially hostile
  • Grant write permissions only when a specific task requires it
  • Revoke write access immediately after task completion
  • Default to read-only connections wherever possible
  • Review AI actions on connected services before confirming

Risk Area 4

Auto-Approved Permissions: Where Convenience Becomes Danger

AI tools allow certain actions to be pre-approved so they run without prompting. This is a double-edged sword — useful when scoped tightly, catastrophic when over-broad.

✅ Safe to Auto-Approve

Read-only, well-scoped tools such as Read, Glob, and Grep. These can only retrieve information — they cannot modify, delete, or transmit anything.

⚠️ Never Auto-Approved

Shell commands (Bash/PowerShell), write operations, file deletion, and any tool that touches external services. These always require explicit human approval before execution.

Our settings.json contains no blanket tool approvals. Every new permission is evaluated against the principle of least privilege before being added.

Risk Area 5

API Keys & Credential Exposure

Credentials passed through an AI tool's context window — even inadvertently — represent a real data exposure risk. We have explicit controls to prevent this from happening.

Keeping Credentials Out of the AI's Sight

The Exposure Mechanism

When an AI tool reads a file that contains credentials — an .env file, AWS keys, database passwords, or API tokens — those values pass through the API request. While Anthropic's data handling policies provide a layer of protection, the principle of never exposing credentials in the first place is the only truly safe approach.

The .claudeignore Solution

We configure a .claudeignore file in every project that explicitly blocks the AI from reading sensitive files and directories. Think of it as a .gitignore — but for your AI assistant.

  • All .env files are ignored
  • Credential directories are blocked
  • Key files and secrets are excluded
  • Personal directories are off-limits

Risk Area 6

The "Dangerously Skip Permissions" Flag

The --dangerously-skip-permissions flag does exactly what it sounds like — it disables all permission prompts, allowing the AI to act with complete autonomy. No confirmations. No safeguards. No human in the loop.

The only legitimate use of this flag is inside a fully isolated, disposable environment such as a sandboxed VM or Docker container with no access to real data or services. We document when and why such environments are used.

Current Security Posture

Our Default State: Maximum Approval Control

Our baseline configuration is the safest possible starting point — and we only deviate from it with explicit justification.

No Pre-Approved Tools

Our settings.json has zero allowedTools overrides. Every tool action — read or write — requires explicit approval. This is the safest default configuration and our starting point for every engagement.

Write-Capable Services Monitored

Connected services with write access (Slack, Notion, Calendar, Airtable) are treated as elevated-risk surfaces. We actively monitor for prompt injection patterns in content these services surface to the AI.

.claudeignore Deployed

Sensitive directories and credential files are excluded from AI access on every project, preventing inadvertent credential exposure through the API.

Prompt Injection: The Threat You Can't Always See

Prompt injection is the practice of embedding hidden instructions inside content the AI reads — a comment in a file, a message in Slack, a note in a Notion page — designed to redirect the AI's behavior without the developer's knowledge. It's the single most insidious risk in AI-assisted development, and defending against it requires both technical controls and human vigilance.

Our Prompt Injection Defense Strategy

No single control eliminates prompt injection risk entirely — defense requires layering multiple safeguards so that even if one layer is bypassed, the others catch malicious instructions before damage is done.

For Your Peace of Mind

What We Will Never Do on Your Project

🚫 Skip Permission Prompts

We will never use --dangerously-skip-permissions outside of an isolated, sandboxed environment that has no access to your data or systems.

🚫 Auto-Approve Shell Commands

Bash and PowerShell commands will never be added to the auto-approval list. Every shell command is reviewed by a human before it runs.

🚫 Read Credential Files

We will never ask the AI to read .env files, AWS credentials, API keys, or any file containing secrets. These are blocked at the .claudeignore level.

🚫 Operate from Your Home Directory

AI tools are always scoped to a specific project folder. Your personal files, documents, and system directories are never within reach.

Transparency in Practice

You Always Know What's Happening

Security isn't just about technical controls — it's about trust. We maintain full transparency with every client about how AI tools are being used on their project:

  • Clear documentation of which AI tools are in use
  • Disclosure of any MCP server connections relevant to your project
  • Shared visibility into permission settings upon request
  • Immediate notification if any security-relevant configuration changes
  • Open-door policy for security questions at any stage

Summary

Security Principles We Live By

Minimal Footprint

Request only the permissions needed for the task at hand. Never accumulate standing access.

Human in the Loop

Every consequential action — shell commands, writes, external service interactions — requires a human review before execution.

Assume Hostile Content

Any content the AI reads from external services is treated as potentially malicious until proven otherwise.

Full Transparency

Clients always know what tools are in use, what permissions are configured, and what actions are being taken on their behalf.

Let's Build Something Secure Together

Security isn't a checkbox — it's a practice. We bring the same rigor to protecting your data and systems as we bring to building great software. If you have questions about any aspect of our security configuration, we welcome the conversation.

Request a Security Review

Ask to see our current configuration settings and .claudeignore setup at any time.

Ask Us Anything

No security question is too detailed. We believe informed clients are the best partners.

Start With Confidence

Every engagement begins from the safest default configuration — with your approval required every step of the way.