Executing at Scale · 11 of 17

Keeping Deal Data Safe

How Claude Code handles your files, where confidential material belongs, and the one rule to follow when you are unsure.

Claude Code runs closer to your files than the browser does, so it is worth being clear about what that means for confidential deal material. The reassuring part is that the model is simple, and the safe habit is a single sentence. This page explains how your data is handled, then points you to the full decision tree when a specific document leaves you unsure.

What Claude Code can and cannot see

Claude Code only ever looks at the folder you open. It cannot reach across your machine, browse other drives, or send a file anywhere on its own. When you make a request, your prompt and the specific context that task needs are sent to Claude; the rest of your files stay where they are.

Where your files live

What stays on your machineWhat is sent to Claude
Every file in the folder you openedYour prompt, plus the parts of files a task needs
Folders you have not openedNothing from outside the open folder
Your Git history and saved commitsNothing, unless a task asks about them

A strong default, but never a substitute for your firm's policy.

The plan you are on

Your firm provides Claude through an Enterprise or Team plan. On these plans your prompts and uploaded files are not used to train the model, which is what makes them appropriate for professional work. That protection is real, but it sits underneath your obligations, not above them: the NDA on a deal, the client’s terms, and your firm’s own policy still decide what may be opened where.

Habits that keep deal data safe

  • Practice on samples first. Learn the loop on a throwaway or dummy folder before you ever point Claude Code at live deal material.
  • Open one deal at a time. Keep each engagement in its own folder so material from separate deals never mixes.
  • Do not move restricted files to reach them. If a document is not somewhere Claude Code can already work, that is a permissions question for IT, not a reason to copy it into an approved folder.
  • Use a .gitignore before your first commit. It keeps confidential files from ever being saved into history or pushed anywhere. See Saving Your Work.
  • Never paste passwords, secrets, or API keys into a prompt. Claude Code does not need them to do its work, and anything you type becomes part of the conversation.
  • Involve IT or security when unsure. A short question about permissions or data handling now prevents a real problem later.

Where to go next

The full, step-by-step logic for deciding what may go where lives in Your Account & Confidential Data, which applies across both Claude Code and the browser. For the wider set of everyday habits, see Habits That Keep You Safe.