# Is Claude Code safe? The security risks and how to lock it down

Claude Code runs commands on your machine with your permissions. What protects you, where those protections stop, and the settings worth changing today.

Published 2026-10-07 by Richard Kaminsky and Mitchell Lipyansky, the co-founders of Poly. Canonical: https://usepoly.co/claude-code-security
Poly is a multiplayer AI coding workspace: a shared room where your team works with one AI agent, together. Free to start: https://usepoly.co/

**Claude Code is as safe as the boundaries you give it. It runs commands and edits files on your machine with your own user's permissions, so its protections are permission prompts and modes, an optional sandbox, and your review. Anthropic's docs are frank about the gaps: a command you approve "can still write anywhere your user account can," the /sandbox command that limits files and network isn't on by default and doesn't exist on native Windows, and prompt injection (instructions hidden in a web page, issue or file) remains the main risk. GitHub lists 33 published security advisories for Claude Code since June 2025, each fixed in an update. For code you don't trust, Anthropic recommends a virtual machine or a cloud session.**

## Key takeaways

- **Your permissions:** whatever Claude runs, it runs as you; a prompt is the boundary, not a wall.
- **Sandbox:** `/sandbox` limits writes to the project and network to an allowlist, on macOS, Linux and WSL 2, not native Windows. Anthropic says it cut permission prompts by 84% internally.
- **Prompt injection:** the main risk. Anthropic: "Avoid piping untrusted content directly to Claude."
- **Your data:** consumer plans can train on your chats if the setting is on; Team, Enterprise and API code isn't used for training.
- **Updates matter:** 33 advisories so far, 26 rated high, all fixed in new versions.

*Ways to contain Claude Code, from Anthropic's docs, October 7, 2026.*

| Option | What it limits | Platforms | Watch out for |
| --- | --- | --- | --- |
| Permission prompts (Manual) | Asks before edits and commands | All | An approved command can do anything you can |
| Auto mode | Classifier blocks risky actions | All | Pauses after repeated blocks; not a sandbox |
| /sandbox | Writes to the project; network to an allowlist | macOS, Linux, WSL 2 | Off by default; not on native Windows; reads most files |
| Dev container | Everything outside the container | Any with Docker | Trusted repositories only |
| Virtual machine or cloud session | Your whole machine | Any | Setup effort |

## How does Claude Code protect you?

From Anthropic's security page ([Anthropic](https://code.claude.com/docs/en/security)):

- **Permission modes:** Manual mode starts read-only and asks before edits and most commands; auto mode, the default since v2.1.283, has a classifier block risky actions instead ([Claude Code plan mode](/claude-code-plan-mode)).
- **Network approval:** tools that reach the network ask by default, and `curl` and `wget` are "not auto-approved by default."
- **Web page summaries:** fetched pages go through a separate model call, so Claude sees a summary rather than raw content.
- **Trust checks:** a trust dialog for new folders and an approval prompt for a repository's MCP servers.
- **Command analysis:** it asks before running a shell command it can't fully analyze.

**The limits:** Claude Code may write only inside your project, but that boundary "is a permission prompt," so a command you approve can write anywhere you can. And `claude -p` and the Agent SDK skip the trust dialog, so a repository's own hooks and MCP servers load without asking ([Claude Code hooks](/claude-code-hooks), [headless mode](/claude-code-headless)).

## What does the Claude Code sandbox do?

`/sandbox` (or `"sandbox": {"enabled": true}` in settings) runs shell commands inside an operating-system sandbox ([Anthropic](https://code.claude.com/docs/en/sandboxing)):

- **Files:** writes only to the project, a temporary folder and folders you add; Claude Code's own settings stay read-only to it.
- **Network:** no direct internet; a local proxy allows only domains you list, and the list starts empty.
- **Platforms:** macOS (Seatbelt), Linux and WSL 2 (bubblewrap). "On native Windows, Claude Code runs commands unsandboxed."

Watch the defaults: the sandbox reads most of your machine, including credential files such as `~/.ssh`, unless you deny them; if it can't start, commands run unsandboxed unless you set `failIfUnavailable`; and file edits, web fetches, hooks and MCP servers run outside it. Anthropic reported that sandboxing "safely reduces permission prompts by 84%" ([Anthropic](https://www.anthropic.com/engineering/claude-code-sandboxing)).

## Dev containers and bypass mode

Anthropic publishes a reference dev container with a firewall that allows only listed hosts ([Anthropic](https://code.claude.com/docs/en/devcontainer)). Because it runs as a non-root user inside the container, you can use `--dangerously-skip-permissions` there for unattended runs, but even then a malicious project can take anything inside the container, Claude Code's own credentials included. Anthropic's advice: "Only use dev containers when developing with trusted repositories," and use a dedicated virtual machine or a cloud session for code you don't trust. Bypass mode "offers no protection against prompt injection."

## What data does Claude Code send to Anthropic?

Your prompts and Claude's responses, encrypted in transit and at rest ([Anthropic](https://code.claude.com/docs/en/data-usage)):

- **Free, Pro and Max:** Anthropic trains on your data "when this setting is on," and keeps it five years if so, 30 days if not.
- **Team, Enterprise and the API:** Anthropic "does not train generative models using code or prompts sent to Claude Code under commercial terms." Standard retention is 30 days, and zero data retention is available on Claude for Enterprise by arrangement.
- **On your machine:** transcripts are kept as plain text in `~/.claude/projects/` for 30 days.

## Has Claude Code had security vulnerabilities?

Yes. GitHub lists 33 published advisories for Claude Code: 13 in 2025 and 20 in 2026 so far, 26 rated high ([GitHub](https://github.com/anthropics/claude-code/security/advisories)). Most are ways around a check: running code before the trust dialog was accepted, commands that slipped past validation, path and symlink escapes, and sandbox escapes. One in January 2026 let a repository's settings send API keys to another server before you trusted the folder. All are fixed in later versions, so keep auto-update on.

## How do you review code for security with Claude?

- **`/security-review`** checks the changes on your branch against the default branch.
- **The security-guidance plugin** (`/plugin install security-guidance@claude-plugins-official`) flags risky patterns as Claude edits and reviews each turn's changes in the background; "none of the layers block writes or commits" ([Anthropic](https://code.claude.com/docs/en/security-guidance)).
- **Claude Security,** formerly Claude Code Security, scans a whole codebase for vulnerabilities; it's a plugin in Claude Code and a public beta for Claude Enterprise.
- **Managed Code Review** reviews pull requests for Team and Enterprise, at $15 to $25 a review ([Claude Code GitHub Actions](/claude-code-github-actions)).

## Is Claude Code compliant with SOC 2 and HIPAA?

Anthropic's Trust Center lists SOC 2 Type 2, ISO 27001 and ISO 42001 for its API and Claude Enterprise, and HIPAA for those with a business associate agreement ([Anthropic](https://trust.anthropic.com)). Claude Code is covered through the plan it runs on; the BAA extends to the CLI and the desktop app's Code tab on Claude for Enterprise with the HIPAA configuration, but not to cloud sessions, Remote Control or mobile ([Anthropic](https://code.claude.com/docs/en/legal-and-compliance)).

## A Claude Code security checklist

From Anthropic's own recommendations:

1. "Review suggested commands before approval," and run untrusted code in a virtual machine or cloud session.
2. Turn on `/sandbox` (WSL 2 on Windows), with `failIfUnavailable` and the network allowlist.
3. Deny secrets: permission rules such as `Read(./.env)`, plus the sandbox's credential settings, since a read rule doesn't stop `cat`.
4. Don't pipe untrusted content to Claude, and only install MCP servers and plugins from sources you trust ([Claude Code MCP](/claude-code-mcp)).
5. For `claude -p` on a repository you didn't write, use `--bare` or disable its hooks.
6. Audit permissions with `/permissions`, keep auto-update on, and in a company, lock settings with managed settings and send events to your monitoring with OpenTelemetry.

## A safer way for a team to run an agent

Poly (usepoly.co) runs Claude Code and Codex for a team in a shared browser room, never on anyone's laptop: each agent works in an isolated container with only the project mounted, it can reach only approved domains, and any member can approve a change before it happens. Free to start. [Poly's security model](/security)

## Common questions

**Is Claude Code safe to use?**

With care. It runs commands with your permissions, protected by permission prompts, an optional sandbox and your review. Anthropic recommends reviewing commands, avoiding untrusted content, and using a virtual machine or cloud session for code you don't trust.

**Does Claude Code have a sandbox?**

Yes, the /sandbox command limits shell commands' file writes to your project and their network access to an allowlist. It works on macOS, Linux and WSL 2, is off by default, and isn't available on native Windows.

**Does Anthropic train on my code from Claude Code?**

On Free, Pro and Max, only if the model-improvement setting is on. Under commercial terms (Team, Enterprise and the API), Anthropic says it does not train on code or prompts sent to Claude Code.

**Has Claude Code had security vulnerabilities?**

Yes. GitHub lists 33 published advisories since June 2025, most of them bypasses of trust or permission checks, all fixed in later versions. Keeping Claude Code updated is the main defense.

**How do I run a security review with Claude Code?**

Type /security-review to check your branch's changes, install the security-guidance plugin for checks as Claude edits, or use Claude Security for a full codebase scan. Team and Enterprise can add managed pull request review.

More guides: https://usepoly.co/guides · Security: https://usepoly.co/security · Pricing: https://usepoly.co/pricing
