- Read-only by default: additional actions require explicit permission
- Write scope: Claude can only write inside the directory where it was started
- Checkpoints: every file edit is snapshotted and reversible
- SOC 2 Type 2, ISO 27001 certified — artifacts at trust.anthropic.com
| Mode | Behavior |
|---|---|
| Default | Approve each file edit and shell command |
| Auto-accept edits | Files edit without prompting; commands still prompt |
| Plan mode | Read-only; produces plan for approval before execution |
Use /permissions to allowlist safe commands. Use /sandbox for OS-level isolation.
- Sensitive operations always require explicit approval
- Web fetch uses an isolated context window (malicious content can't bleed into conversation)
curlandwgetare blocklisted by default- Command injection detection flags suspicious bash even if previously allowlisted
- First-time codebase runs and new MCP servers require trust verification (disabled with
-pflag) - Fail-closed: unmatched commands default to requiring manual approval
Enable with /sandbox for OS-level filesystem and network isolation:
- Filesystem: write restricted to project directory
- Network: only allowlisted domains accessible
See sandboxing cheatsheet for full details.
- Review all suggested changes before approval
- Use project-specific permission settings for sensitive repos
- Use devcontainers for additional isolation
- Audit permissions regularly with
/permissions
- Use managed settings to enforce org-wide standards (distributable via MDM)
- Share approved permission configs through version control
- Monitor activity via OpenTelemetry metrics
- Audit or block settings changes with
ConfigChangehooks
- Each cloud session runs in an isolated Anthropic-managed VM
- Network access limited by default; configurable per session
- GitHub credentials handled via secure proxy — never enter the sandbox
- Git push restricted to current working branch
- All operations are audit-logged
- Environments auto-terminate after session
- All execution stays on your local machine
- Data flows through Anthropic API over TLS (same as local usage)
- Uses multiple short-lived, narrowly scoped credentials
- No cloud VMs or sandboxing involved
- You are responsible for vetting MCP servers — Anthropic does not audit them
- Use MCP servers only from providers you trust or that you wrote yourself
- MCP permissions are configurable in Claude Code settings
Avoid enabling WebDAV or allowing Claude Code to access \\* paths — WebDAV is deprecated by Microsoft and can allow Claude Code to trigger unauthorized network requests, bypassing the permission system.
- Review suggested commands before approval
- Don't pipe untrusted content directly to Claude
- Verify proposed changes to critical files
- Use VMs when interacting with external web services
- Report suspicious behavior with
/bug
Do not disclose publicly. Report via HackerOne with detailed reproduction steps.
Source: security.md