# Protect customer data and account credentials

Submit only the customer information needed for the current task, never share passwords or secrets in chats and screenshots, and check content before sending it externally or sharing it publicly.

## Who this is for

This guide is for everyone who uploads inquiries, works with customer records, uses generated content, shares research sessions, or manages connection credentials in TradeGo AI.

## Before uploading customer information

1. Confirm that the current team is responsible for the customer.
2. Check that the file, email, or conversation belongs to the intended customer.
3. Remove identity documents, private phone numbers, and other personal information not needed for the task.
4. Use a focused sample instead of a complete customer dataset when that is enough.
5. Open each attachment and confirm that it contains no other customer or internal confidential content.

## Protect passwords and secrets

Passwords, API keys, MCP client secrets, and authorization headers do not belong in:

- Chats or email
- Support messages
- Screenshots or presentation files
- Browser-side code
- Public repositories or shared links

If a secret may have been exposed, revoke it or reconnect the application immediately, then update any application that used it.

## Before sending or publishing AI output

Check customer names, products, quantities, prices, delivery terms, dates, contact details, sources, and commercial commitments. Generated content can omit information or state an inference too strongly. The person responsible for the work should confirm it before external use.

## Share sessions and screenshots carefully

Anyone with a TradeClaw public link may be able to open the shared session. Avoid customer-sensitive content, send the link only to the intended people, and stop sharing when collaboration ends.

When taking a screenshot, hide customer email addresses, phone numbers, order details, credentials, and sensitive parameters that may appear in the browser address bar.

## FAQ

### Can I send an API key or MCP client secret to support?

No. Do not include complete passwords, API keys, client secrets, or authorization headers in support messages; hide the sensitive portion when explaining a problem.

### What should I check before uploading customer information?

Confirm the current team and customer, remove personal information unrelated to the task, and verify that attachments contain no other customer or restricted content.

### What should I do before sharing a TradeClaw session?

Check the session for customer or confidential information, send the link only to people who need it, and stop sharing when public access is no longer required.

---

Canonical HTML: https://app.tradegoai.app/docs/security
Last updated: 2026-07-26

Related documentation:
- [Create and manage a TradeGo AI API key](https://app.tradegoai.app/docs/developer-api)
- [Connect email and CRM applications in TradePilot](https://app.tradegoai.app/docs/mcp)
- [Resolve team and product access issues](https://app.tradegoai.app/docs/team-permissions)
