Security and trust
We tell you exactly what our governance enforces, and what it does not.
CRE Skills Pro runs as a local Claude Code plugin. By default no deal data leaves your machine. Here is the enforcement boundary, stated plainly so your security team can review it.
Enforcement model
| Guarded (self-install, default) | Enforced (managed, Enterprise) |
|---|---|
| The PreToolUse hook blocks the write. The audit log records every action. Self-approval is rejected at the hook. A user with shell access can edit or remove a hook. Strong process enforcement and a tamper-evident audit. Not an IT security control. | Managed settings override the user. The server issues attested approval tokens. Four-eyes cannot be self-satisfied. An external WORM store holds the audit, uneditable locally. An operator-proof control plane. |
Data handling
Local-first. Deal state is gitignored on your machine. The most sensitive class of data (SSN, EIN, wire details, API keys) is never auto-saved. The shared file stores aggregates and hashes, never raw payloads.
Audit and managed settings
The audit log is append-only JSONL with an artifact hash chain, and a file-change monitor flags any external mutation. Enterprise admins pin a fleet with strictKnownMarketplaces and disableBypassPermissionsMode.
The IP boundary, stated plainly
Plugin skills are plaintext Markdown in Claude Code’s local cache. There is no client-side DRM. License enforcement is a soft entitlement check plus your firm’s terms of use. Where IP protection is paramount, the value is in the governed workflow, not in making files unreadable.
Download the security package