Local data protection for Claude Code.

TigerMole temporarily processes content from supported flows in memory, replaces the sensitive values it detects, and sends the remaining content to the configured provider. It does not keep the prompt or response as an on-disk conversation.

AVAILABLE · Windows 10/11 · Ubuntu 20.04+ / Debian 11+ · Available since TigerMole 1.4.6

CONCEPTUAL FLOW · CLAUDE CODEAVAILABLE
01Work contextDATABASE_URL=postgres://demo:[value]@localhost
02TigerMole · local boundarytemporary in-memory processing
03Replaced value[redacted_credential_01]
04AI providerremaining content
An illustrative view of the boundary. The coverage matrix documents the exact behaviour of each version.
01 · LOCAL BOUNDARY

The control runs before the cloud.

Processing sits within a supported Claude Code flow while the organization retains responsibility for authorizing the tool.

STEP 01

Process in memory

TigerMole temporarily receives content on the device to examine the values present in a supported flow.

STEP 02

Replace detected values

Values that match active rules are locally replaced with opaque references.

STEP 03

Continue to the provider

The remaining content is sent directly to the configured provider to complete the request.

02 · EVIDENCE

Useful evidence, with explicit limits.

The persistent audit provides local technical metadata for review without being presented as a conversation copy or central console.

What the local audit retains

Recorded entries provide metadata about detections and protection actions. The published schema defines the fields available in each version.

  • Local metadata about detections.
  • Protection actions applied by the boundary.
  • The persistent audit does not include the prompt, response, or original secret.

What remains out of scope

Detection depends on rules, context, and version. A value that is not detected is not automatically replaced.

  • TigerMole does not decide whether Claude Code is authorized.
  • It does not replace DLP, CASB, contracts, access controls, or internal policies.
  • Protection is limited to supported flows and detected values.
Review coverage and architecture
03 · GETTING STARTED

Three checks before the first use.

Use fictional data for initial verification and confirm the published coverage before introducing the control into a real workflow.

01

Check the version

Install a TigerMole version equal to or later than the minimum shown for Claude Code.

02

Follow the guide

Complete the documented installation and configuration for your platform and licence.

03

Verify with a preset

Use a fictional example, confirm the protection state, and review the resulting local event.

04 · QUESTIONS

Questions about Claude Code and TigerMole.

These answers describe the published scope. The Security Evidence Pack remains the versioned technical reference.

Does TigerMole receive the processed content?

Flow content is not sent to TigerMole. After local replacement, the remaining content continues directly to the configured AI provider.

What happens to a value that is not detected?

If a value does not match the active rules, TigerMole cannot replace it. Coverage should therefore be reviewed alongside policies, classification, and complementary controls.

Does it replace provider agreements and controls?

No. TigerMole complements—it does not replace—contracts, DPAs, access controls, internal policies, and assurances from the AI provider.

Add the boundary before the next prompt.

Review the flow with your technical team and validate the integration with fictional data.

Your privacy, your choice

We use essential storage to keep the site working and, only with your consent, analytics through PostHog and Google Analytics 4. We do not load advertising providers. Read our Privacy Policy.