Is Claude Code safe for business? Permissions and data
Claude Code asks before it edits files or runs commands. How Australian businesses keep it safe: permission modes, blocking secrets, backups and privacy.
Want this done for you? Book a free 30-minute AI audit
Claude Code is safe for business use when it’s set up properly. By default it asks before it edits a file or runs a command, you can block it from reading passwords and keys, and /rewind undoes its edits. Check the model-improvement privacy setting on Pro and Max plans, and connect business software read-only first. On Autopilot, a Melbourne AI consultancy, sets all of this up as part of a $1,500 Claude Code Setup Day.
Everything below is based on Anthropic’s documentation for permissions, checkpointing and data usage, checked on 03/10/2026, and on how we run Claude Code across our own businesses.
What can Claude Code do on my computer?
Claude Code works inside the folder you start it in. It can read files there without asking, but by default it asks before it edits a file, runs a command, fetches a web page or searches the web. You see exactly what it wants to do and choose yes or no.
| Action | Asks you first by default? |
|---|---|
| Read files in the working folder | No |
| Edit or create a file | Yes (approval lasts until the session ends) |
| Run a command | Yes, except a short built-in list of read-only commands such as listing files |
| Fetch a web page | Yes, except some documentation sites |
| Search the web | Yes |
| Read files outside the working folder | Yes |
That is why the folder you start in matters. Start Claude Code in a dedicated working folder, not your whole Documents folder.
Which permission mode should a business owner use?
Use Manual mode, the default, for at least your first few weeks: it asks before every edit and command. Use Plan mode when you want Claude to look and propose without changing anything. Press Shift + Tab in a session to move between modes.
| Mode | What it does | When to use it |
|---|---|---|
| Manual (default) | Asks before each edit and command | Your first weeks, and any folder with real business data |
| Plan | Reads and proposes, doesn’t edit your files | Before a bigger job, to see the plan first |
| Accept edits | Edits files in the working folder without asking; still asks before other commands | A folder of copies, once you trust the job |
| Auto | Runs without routine prompts while a background check reviews risky actions | Later, for experienced users on well-understood jobs |
| Bypass permissions | Skips prompts altogether | Not on a business computer. Anthropic says to use it only in isolated environments such as containers or virtual machines |
How do I stop Claude Code reading passwords and API keys?
Add deny rules. A deny rule blocks Claude’s file tools from reading a file, even if you later approve something by mistake. Keep keys in a password manager or a .env file, never in a document, and never paste a key into the chat.
Save this as .claude/settings.json inside your working folder (or in the .claude folder in your user profile to apply it everywhere):
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(./.env.*)",
"Read(./secrets/**)"
]
}
}
Type /permissions in a session to see and edit your rules. If an older guide tells you to use a .claudeignore file, ignore it: Anthropic’s documentation says it has no effect.
How do I undo a mistake Claude Code makes?
Type /rewind, or press Esc twice with an empty prompt, and choose the point to go back to. Claude Code snapshots files before each of your requests, so you can restore its edits. It can’t undo files deleted, moved or copied by a command, or changes made outside the session.
So keep three layers of protection:
- Work on copies. Make a working folder for each job.
- Keep backups with version history. OneDrive, Google Drive and Dropbox keep earlier versions; so do Windows File History and Mac Time Machine.
- Use Git for anything technical. If Claude Code is building a tool or website for you, it can save each step in Git so any change can be reversed.
Does Anthropic train its AI on my business data?
It depends on your account. On the Free, Pro and Max plans, you choose whether your chats and Claude Code sessions can be used to improve future models; if you allow it, data is kept for up to five years, and if you don’t, for 30 days. On Team, Enterprise and API accounts, Anthropic does not train models on your Claude Code prompts or code unless you opt in, and keeps data for 30 days as standard.
Our advice: if you use a Pro or Max plan for business, check the setting under data privacy in your claude.ai settings. For client or customer data, prefer a Team plan or an API account, which run under Anthropic’s commercial terms.
Is it OK to use Claude Code with customer data under Australian privacy law?
It can be, but the Privacy Act still applies to what you give it. Businesses with annual turnover over $3 million, and some smaller ones such as health service providers, must follow the Australian Privacy Principles. Two matter most here: keeping personal information secure (APP 11), and taking reasonable steps when you disclose it to an overseas provider (APP 8).
In practice:
- Give it the minimum. Strip names, phone numbers and addresses from exports when the job doesn’t need them.
- Know where it’s processed. The Claude API processes requests globally by default. If a contract requires Australian processing, Claude is also available through Amazon Bedrock and Google Cloud, which offer regional endpoints; check whether an Australian region is offered for the model you need.
- Say so in your privacy policy. If customer information goes to AI providers, your privacy policy should cover it.
- Get advice for sensitive information. Health, financial and legal records need more care. This guide isn’t legal advice.
The OAIC explains which small businesses the Privacy Act covers.
How do I connect business software safely?
Connect each tool read-only first, with its own key, and only add write access to one workflow at a time after you’ve watched it behave. Only connect tools from vendors or developers you trust: Anthropic warns that connectors which fetch outside content can expose you to prompt injection, where hidden text tries to give Claude instructions. Our guide to connecting Claude Code to Xero, Shopify and Gmail walks through each one.
What safety checklist do we use on a Setup Day?
On a Claude Code Setup Day we work through this list before building anything:
- Manual permission mode as the default.
- Deny rules for files that hold passwords and keys.
- A working folder of copies, and a backup with version history confirmed.
- The privacy setting checked, or a commercial account for client data.
- Business tools connected read-only.
- A monthly spend limit on any API key, and a separate key for each scheduled agent.
- A short section in CLAUDE.md saying what Claude may and may not do in your business.
How On Autopilot can help
The Claude Code Setup Day is $1,500 fixed (ex GST): one remote day in which we install Claude Code, set up every item on the checklist above, connect your tools and build one real automation from your own work. If you’d rather we built and ran the agents for you, Managed AI starts at $1,500 a month, month to month, and you own the code, prompts and settings. See the pricing page, or book a free 30-minute AI audit to talk through your data and risks first.
New to Claude Code? Read Claude Code for non-developers and the install guide.
Common questions
Can Claude Code delete my files?
Only through an action you approve, or if you switch on a mode that skips permission prompts. In the default Manual mode it asks before running any command that changes files. Add deny rules for delete commands if you want a hard block, and always work on copies.
Can Claude Code see my whole computer?
It reads files in the folder you start it in, plus any folders you add. Reaching outside those folders needs your approval. Start it in a dedicated working folder, not your whole Documents folder or desktop.
Does Claude Code send my files to Anthropic?
Yes, the parts it reads. Claude Code runs on your computer, but your prompts and the file content it works with are sent to Anthropic's servers, encrypted in transit, so the model can process them. How long they are kept depends on your account type and privacy setting.
Is Claude Code safe for client data in an accounting or health practice?
It can be, with care. Use a commercial account (Team, Enterprise or the API), give it the minimum personal information the job needs, and check your obligations under the Australian Privacy Principles. Health information is sensitive information, so get privacy advice before using it with patient records.
What is the safest way to try Claude Code?
Copy the files for one job into a new folder, start Claude Code there in Manual mode, and use Plan mode first so it explains what it would do without changing anything. Move to real folders only after you've watched it work for a week or two.
Want this built for your business?
Book a free 30-minute AI audit call with Jenn Yang. We map where your time goes, name the first systems worth building and give you fixed AUD prices. No obligation.
Book a free AI auditOr have us run it for you, end to end: On Autopilot is Australia's outsourced AI department.