Company data in a published artifact: what to do first

Unpublish it first, from the artifact itself. That kills the link in seconds and is the only step that reduces further exposure. Everything after that is assessment and cleanup: who could have seen it, what copies exist, and whether it has to be reported.

First, take the link down

Open the artifact and switch it back to private. The public URL stops resolving immediately. Do this before investigating, before telling anyone, and before deciding how serious it is, because every minute it stays up is more exposure and none of the other steps get faster for waiting.

If more than one person may have published something, a Team or Enterprise admin can switch off public artifacts for the whole organisation under Organization settings, then Capabilities. That turns existing public artifacts private in one action rather than asking each person to check.

Then work out what was actually reachable

The artifact address is a UUID and cannot be guessed, so exposure came from the link being shared rather than from anyone finding it. Ask where it went: a client email, a Slack channel, a ticket, a public post.

The categories on this site that most often carry company material are dashboards and business documents: quarterly numbers, architecture diagrams, client proposals. If an artifact of that kind was public, treat the data in it as having been readable by anyone who had the address.

What unpublishing cannot reach

Screenshots, pasted text, a page someone wrote quoting it, a crawler that read it last week, a browser cache. Those left your control when the link went public and no setting in Claude touches them.

If the link was posted somewhere public, the post is a separate takedown request to a separate site, and search engines keep their own caches on their own schedule.

Whether this is a reportable incident

That is a question for whoever handles data protection where you work, not for this page. What they will need is the timeline: when it was published, when it was taken down, what it contained, and where the link was posted. Collect that while it is fresh.

Personal data about identifiable people raises the bar considerably in most jurisdictions. Commercial data that is merely embarrassing usually does not, but that call is not yours to make alone.

Getting the record out of this index

If a record for it appears here, the removal form deletes it and puts the artifact ID on a blocklist so the daily crawl will not add it back. There is no review and no argument.

Do it after unpublishing at the source, not before. Removing the record here while the artifact is still live changes nothing about who can read it.

Verified against claude.ai on 2026-07-29. Claude changes, so a menu may have moved.