Claude Code

Claude Code history: answering an audit or security questionnaire

A customer asks how AI-generated code is reviewed and retained. What do we show them?

Why this is hard

The question has stopped being hypothetical: customer security questionnaires now ask about prompt logging and retention directly. The answer has to be a system rather than a description of good intentions, and it has to cover a period that already happened.

What Claude Code specifically does to you here

The audit window is shorter than the audit cycle. Retention defaults to 30 days and the setting that controls it is absent from a normal install, so when a questionnaire arrives asking about the last quarter, most of that quarter is already gone from every machine.

See it on your own machine
find ~/.claude/projects -name '*.jsonl' -mtime +30 | wc -l

Where Claude Code keeps this in the first place: ~/.claude/projects/<project>/<session>.jsonl. Transcripts older than 30 days are deleted by default, and nothing tells you it is happening.

What a working answer looks like

A working answer means a retained, timestamped record you can point at — with a retention policy you chose rather than inherited from a tool's default.

Start by measuring what you have. npx promptwake doctor reports what every AI tool on the machine is holding and how much of it sits inside a deletion window — no account, writes nothing, sends nothing anywhere. If the conclusion is that the record should not depend on one laptop, that is what PromptWake captures: prompt, response and the resulting diff, local by default and synced into a shared timeline on the paid tiers.