Chancelry

Security

The operator acts on your behalf, so this page sets out what it’s stopped from doing, what waits for you, and where that protection ends.

It checks before it acts

Every shell command and every file edit passes through a safety gate before it runs.

Some commands are refused outright. A force push to your main branch is one of them, and no approval overrides it.

Others wait for you. A recursive delete or a dropped database table stops until you approve that exact command. An approval covers one use and lapses after 30 days.

Everything else runs, and each action is recorded in an audit log.

Its rules sit in a plain-text file you can read and change. So does its memory. Only the Telegram accounts you approve can reach it.

What the gate is not

The gate is a check inside Claude Code rather than operating-system enforcement. It hasn’t had an independent security audit.

Plate III.The gate, in sectionRefused.Held for your approvalRuns.
An illustration of the gate’s rules. It isn’t connected to a live system.

Put a command to the gate

Plate II.Three verdicts

An illustration of the gate’s rules. It isn’t connected to a live system.

The commands, and the names in them, are examples.

git push --force origin main

Refused. No approval overrides it.

When something goes wrong

There are three places to look.

  • The gate. A command it stops comes back with the reason, and says whether your approval can release it. Nothing on the refused list can be approved.
  • The audit log. Every action is written to it, one file a day, kept on your machine and out of your GitHub backup. Each entry records the tool used, what it was given, and when.
  • The outside check. If the operator goes quiet, a check that doesn’t depend on your machine can message you, within hours rather than minutes. It can’t restart a machine that’s switched off.

Where your information goes

The operator can only be reached from Telegram accounts you approve. Beyond that, your information sits in five places.

  • On your machine: conversation history, the audit log, the memory and the operator’s rules.
  • Kept out of your GitHub backup: the audit log, secrets files and the Telegram bot token.
  • With Anthropic: the work Claude does, under your own plan and Anthropic’s terms.
  • Through Telegram’s servers: the messages between you and the operator.
  • In a private GitHub repository: memory and project files, when they’re pushed there.

Questions

Could it do something I didn’t intend?

It acts on what you tell it, and it can make mistakes. That’s why the gate exists. Commands that can’t be undone are either refused or held for your approval, and every action is logged. The gate has limits. A process started outside Claude Code isn’t checked, and someone who has already gained the ability to run code on your machine has known ways round it.

Has the safety gate been independently audited?

No. It hasn’t been through a third-party security audit. If your sector requires one, this isn’t the right fit yet.

Start with a conversation

Tell us how your business runs and what you’d hand over first. If Chancelry suits it, we’ll say so. If it doesn’t, we’ll say that too.

Request a consultation