<!-- Generated from the canonical documentation source. Do not edit directly. -->
Canonical: https://pentect.dev/
# Docs\_

Keep sensitive values local while Codex and Claude use the context they need.

Pentect replaces sensitive values with usable handles before requests leave your machine. Known handles are restored only at trusted local boundaries.

## Start with a client

Choose the surface you already use. Pentect only applies to sessions you launch through it.

[Codex CLI](/clients/codex/) — Run Codex through Pentect for the current session.

[Claude Code](/clients/claude/) — Route Anthropic Messages traffic through Pentect.

[Codex App](/clients/codex/) — Start an isolated App session with Pentect enabled.

[Claude Desktop](/clients/claude/) — Protect supported Claude Desktop traffic.

## Explore Pentect

Go directly to the part you need.

[How it works](/start/how-it-works/) — Follow a value from detection to a local tool call.

[Structured data](/protection/structured-data/) — Protect dotenv, Terraform, Kubernetes, and other supported formats.

[Files and images](/protection/files-and-images/) — Understand document, upload, image, and OCR handling.

[Custom upstreams](/clients/upstreams/) — Put compatible gateways and local model servers behind Pentect.

[Plugins](/plugins/overview/) — Extend detection and middleware in a Wasm sandbox.

[CLI and configuration](/reference/capabilities/) — Browse commands, settings, compatibility, and troubleshooting.
