AI governance for Claude Code
Claude Code security: redaction and visibility
PromptWall redacts secrets, credentials and personal data in every Claude Code session before it reaches Anthropic. The AI Control Panel manages company subscriptions and can turn Claude Code off for chosen people.
Real usage
What people paste into Claude Code
The patterns we see most often once a team adopts Claude Code for real work.
Credentials pasted while debugging
A failing deploy or a broken connection gets a real AWS key, token or database password pasted straight into the Claude Code prompt.
Repo files read as context
Claude Code reads files in the working directory and sends them as context, including .env files, credentials in test fixtures and customer data in seed scripts.
Personal data in logs and fixtures
Stack traces, log excerpts and sample data pulled into a session often carry names, emails and phone numbers of real customers.
Long sessions that re-send history
Each turn ships the earlier conversation back to the model, so a secret pasted early in a session travels again with every later request.
What your employee typed
Why does this deploy script fail? AWS_SECRET_ACCESS_KEY=wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY and the DB password is Rk93!mTq2xZ.
What Claude Code received
Why does this deploy script fail? AWS_SECRET_ACCESS_KEY=[API_KEY_1] and the DB password is [PASSWORD_1].
Coverage
How NexusNest covers Claude Code
PromptWall
- API keys, tokens, passwords, SSH keys and connection strings in prompts and code context
- Names, emails, phone numbers and other personal data in logs, fixtures and seed data
- Internal admin emails and other confidential identifiers inside repo files
NetLens
NetLens shows how many people use Claude Code, what they use it for by topic, and how often PromptWall redacted something, built from redacted text only, never from anyone's raw prompts.
Learn moreAI Control Panel
The AI Control Panel manages company Claude Code subscriptions. The agent signs the employee in with a managed credential, so nobody shares a password, and an org-wide CLI policy can turn Claude Code off for chosen people.
Learn moreFAQ
Claude Code, common questions
Does it cover Claude Code in the terminal?
Yes. The NexusNest agent routes Claude Code traffic to Anthropic through redaction, including the messages endpoint and the session calls Claude Code makes, on macOS and Windows.
What does Claude Code see instead of my secret?
A labelled placeholder such as [API_KEY_1], [PASSWORD_1] or [PERSON_1]. The model answers from the surrounding code and context, so the reply is still useful.
Can the company manage Claude Code subscriptions?
Yes. The AI Control Panel assigns company Claude Code subscriptions and the agent signs the employee in with a managed credential, with no shared passwords. Offboarding is one revoke.
Can we turn Claude Code off for some people?
Yes. An org-wide CLI policy can switch Claude Code off for chosen people while everyone else keeps working.
Does redaction ever block a developer?
No. If redaction cannot run, the request is not blocked. The event is tagged with its reason, audited and shown to admins as an alert.
Start with one team. Prove control before you scale AI.
Start with one team. See exactly how your company uses AI.