Incident record
RAI-0022 · Claude Code deploys a client’s financial dashboard to a public Netlify URL
According to the operator, Claude Code (an Opus model), asked to analyze a client’s cashflow, commissions and related data, built a dashboard and deployed it to a public Netlify URL the way it did for his personal projects; the page showed real names and amounts, needed no login and could be indexed by search engines.
- Stable ID
- RAI-0022
- Event period (not publication date)
- Parties involved
- Claude Code (Opus model), Operator (solo developer), The operator’s client (unnamed), Netlify
Context and evidence boundaries
The source is the operator’s first-person account on his own site, and the operator is identifiable; there is no confirmation from Anthropic or Netlify. The blog says only that he began using these agents in late 2025, so its cases fall between then and the March 2026 post; “November 2025” comes from an entry he wrote for a GitHub collection of agent failures and links from the post. Per that entry he found the page in a routine review and removed it urgently, the exposure lasted an unknown time, and he saw no sign of third-party access. He routinely had the agent deploy personal dashboards to share pages, so what was crossed was his intent and the client’s ownership of the data, not a technical permission; he attributes the failure to the agent not distinguishing his data from the client’s.
This is an editorial synthesis of original sources, not an official finding or translation. Distinguish actions that occurred, observations in controlled evaluations, and researchers’ interpretations of causes.
Original sources and follow-ups
Publication order: oldest first- Travis Bonnet