Claude Code is Anthropic's agentic CLI - also shipped as a VS Code/JetBrains extension, a web/cloud version, and the Claude Agent SDK - and it reads, writes, and runs shell commands on its own, gated by a permission and allowlist system rather than a hosted stack. That system controls what Claude Code can do on your machine; it doesn't guarantee the code it writes is secure. We audit Claude Code-built apps for the access-control and secrets gaps that slip through, plus the permission-model and MCP risks specific to how it operates.
Run a free 30-second scan Book an auditClaude Code is Anthropic's agentic command-line coding tool - also shipped as a VS Code/JetBrains extension, a web/cloud version, and the Claude Agent SDK. It runs in the terminal, reads and writes files in the working directory, and executes shell commands to complete coding tasks with minimal supervision. Security is built on a permission/allowlist model across project, user, and enterprise "managed settings" tiers: read-only by default, with explicit approval required for writes and commands, plus MCP servers, subagents, and hooks that run shell commands on events. Usage is broadening fast - from professional developers to non-technical teams building internal tools, scripts, and even docs - which means the guardrails matter for more people who don't have a security background to fall back on.
These are the specific, recurring patterns we see when we audit apps built with Claude Code - not generic AI-code warnings.
Roughly double the leak rate of human-only commits - part of a bigger picture where 28.6 million new secrets hit public GitHub in 2025 (up 34% year over year) and AI-service credential leaks alone rose 81%.
We fix it by moving every secret into environment variables or a secrets manager, then scanning history for anything already exposed.
That's higher than the roughly 30% rate Veracode measured for comparable OpenAI models. Models tend to optimize for "it works" over "it's secure," and Claude Code will confidently ship code that runs but isn't safe unless someone checks it.
We fix it by testing for the specific vulnerability classes models miss, not assuming a capable model means secure output.
Claude Code's permission system is opt-in security - an allowlist that's too permissive, or a repo run with --dangerously-skip-permissions, removes the barriers meant to catch a mistake or a malicious instruction before it executes.
We fix it by auditing the actual permission settings and allowlist your team is running, not just the defaults from the setup guide.
Several of Claude Code's disclosed CVEs trace back to this pattern: content the agent treats as data - a README, a dependency, an MCP tool's response - actually contains instructions it follows, sometimes before you've even approved the folder as trusted.
We fix it by auditing MCP server trust boundaries and treating repo content as untrusted input by default.
This is about Claude Code the product, not the code it writes for you. Anthropic holds SOC 2 Type I & II, ISO/IEC 27001:2022, ISO/IEC 42001:2023, CSA STAR, and NIST 800-171, and describes itself as HIPAA-ready - strong certifications, but they cover Anthropic's own systems, not the correctness of what Claude Code generates. Commercial plans (Team, Enterprise, API) aren't used for training; consumer plans (Free, Pro, Max) are, by default, since a September 2025 policy change, with retention up to five years when training is allowed. --dangerously-skip-permissions disables every guardrail at once and should be treated as a deliberate, logged exception, not a convenience setting.
| Item | Status |
|---|---|
| SOC 2 / ISO 27001 / ISO 42001 | Anthropic holds all three; certifies Anthropic's systems, not your generated code |
| HIPAA / BAA | "HIPAA-ready," but BAA coverage is narrow - only ZDR-enabled CLI via API/Enterprise OAuth or Desktop local mode |
| Training on your code | Off for Team / Enterprise / API; consumer Free / Pro / Max trains by default since Sept 2025 |
| Default permission model | Read-only by default; writes and commands require explicit approval unless allowlisted |
| --dangerously-skip-permissions | Disables all guardrails - treat as a logged, deliberate exception only |
| Audit logging | OpenTelemetry monitoring and admin controls - Enterprise tier |
These affect the Claude Code tool, not necessarily your app - but if you're running an unpatched version, they're worth knowing about.
| CVE / Issue | Severity | What it means |
|---|---|---|
| CVE-2025-52882 | High (CVSS v4 8.8) | IDE extensions ran an unauthenticated local WebSocket server; a malicious website could connect to it and achieve remote code execution. Vulnerable versions were pulled. |
| CVE-2025-55284 | High (CVSS 7.1) | A permissive default command allowlist let data be read and exfiltrated over DNS - encoding secrets as subdomains via ping/nslookup - with no prompt or log. Fixed in v1.0.4. |
| CVE-2025-59536 | High (CVSS ~8.7) | A repo's .claude/settings.json could enable MCP servers or run hooks before the "trust this folder?" prompt ever appeared - consent bypass plus RCE. Fixed ~v1.0.111+. |
| CVE-2026-21852 | Moderate (CVSS 5.3) | A malicious repo could override ANTHROPIC_BASE_URL in settings to redirect traffic and steal a plaintext API key before the trust dialog. Fixed ~v2.0.65+. |
| CVE-2025-66032 | High (CVSS 8.7) | The Claude Code GitHub Action could be tricked by a crafted issue into leaking OIDC credentials, gaining write access for supply-chain code injection. Patched within 4 days of disclosure. |
Not automatically. Veracode found Claude Opus 4.7 included a vulnerability in 52% of coding attempts - higher than comparable OpenAI models - because models tend to optimize for working code over secure code. Treat Claude Code output like any AI-generated code: reviewed before it ships.
It depends on the plan. Team, Enterprise, and API usage (including Claude Code via API) is not used for training. Consumer plans - Free, Pro, and Max - are used for training by default since a September 2025 policy change, with retention up to five years when that setting is on, unless you opted out.
All of it - the read-only default, the approval prompts for writes and commands, everything. It exists for specific automation cases, but running it routinely on real code removes every checkpoint that would otherwise catch a mistake or an injected instruction.
The initial scan is free and takes about 30 seconds. A full audit starts at and any fixes we recommend are quoted separately based on what we actually find in your app.
Free 30-second scan, then a clear list of what needs fixing before real users touch it.
Run a free 30-second scan