AccuroAI inspects Claude traffic where it originates (browser sessions on claude.ai, API calls from your services, and Claude Code on developer machines) with one policy engine and the same 40+ classifiers, at sub-38ms. PII, customer data, and credentials are redacted before Anthropic ever receives them.
Tool calls are where conversations become actions. Each MCP call Claude makes (what tool, what arguments, what comes back) is logged and evaluated against policy, so a prompt-injected instruction to read ~/.aws/credentials gets stopped as an action, not discovered in a postmortem.
Before Claude Code ships repository context to the cloud, AccuroAI scans it for secrets, keys, and protected source (60+ secret types) and redacts or blocks per policy. Developers keep the productivity; the security team keeps the audit trail of exactly what left each machine.
Anthropic controls what happens after your data arrives: retention, training use. AccuroAI controls what arrives in the first place, and covers the personal accounts and side channels an enterprise agreement can't see.
Calls are evaluated inline against policy; allowed calls pass through untouched. Only calls that trip a rule (a sensitive path, an unsanctioned destination) are blocked or held for approval, with a logged reason.
Inspection stays inside the sub-38ms p99 envelope, imperceptible next to model response time.
Yes. API traffic is inspected with the same policies, so your customer-facing Claude features inherit the same data guarantees as internal use.