Claude & privacy MVP1 / v1.0

Analysis with Anthropic Claude

The planned contextual analysis backend: direct Anthropic BYOK, minimized context, and advisory verdicts.

Development previewLive hooks, enforcement, and Anthropic BYOK are pending. This guide distinguishes current behavior from the MVP1 design.

Why Claude is in the pipeline

TraceRook’s contextual analysis backend is designed around Anthropic Claude. Deterministic local rules handle concrete dangerous signatures; Claude assesses ambiguous action intent, task relevance, prompt injection indicators, and cumulative agent drift.

This is distinct from Claude Code as an integrated coding agent. A Codex session can also receive contextual analysis from Claude. TraceRook owns its policy and review flow; the analysis model supplies a bounded risk report.

Live Anthropic integration is Phase 4 work. The current native preview and this static website make no Claude analysis requests.

Bring your own key, connect directly

The intended provider uses URLSession over TLS to send requests directly to Anthropic’s Messages API at https://api.anthropic.com/v1/messages. The key is retrieved just in time from macOS Keychain. There is no TraceRook analysis proxy, shared vendor account, browser OAuth, or website key form.

Choose a supported, configurable Claude model identifier and API version based on actual provider compatibility. TraceRook must not invent a future model name or claim universal structured-output support. If structured output is unavailable for the selected model, strict JSON decoding and conservative failure handling are required.

External reference: Anthropic API overview.

What context is selected

  • A concise, locally redacted task anchor derived from user prompts.
  • A sanitized description of the proposed action and local policy matches.
  • Relevant recent sanitized event summaries from a bounded rolling context, approximately 20 events.
  • Recent denials, unusual target/path changes, and untrusted instruction indicators when observed.
  • Redaction counts, evidence, and confidence limitations.

No full transcript or repository tree is automatically sent. Additional code excerpts default off and require explicit opt-in to bounded selected lines. A separate minimal remote payload is checked again immediately before transmission.

Claude does not grant permissions

The system prompt defines a read-only security analyst. Inspected content is encoded as untrusted data. The model returns a versioned, constrained JSON verdict with enumerated categories and actions, bounded strings and arrays, a valid confidence range, evidence, and limitations.

The app must reject unexpected execution requests or policy text. Model-only critical findings are capped at high-risk review; Claude cannot silently hard-block solely by attaching a critical label. Concrete deterministic critical evidence cannot be downgraded.

Deadlines, budgets, and availability

Contextual review has an 8-second soft and 12-second hard deadline. These are engineering limits, not guaranteed network latency. Retries for rate limits or server errors use bounded jitter only while the hard deadline permits.

Defaults are 30 synchronous model calls and 12 drift checks per session, plus a configurable daily budget. When paused or exhausted, local rules continue and the UI says AI analysis paused — local rules active. Estimated costs must be labeled as estimates based on returned tokens and configured price data.

Based on the MVP1 architecture specification, version 1.0 · October 8, 2026.