Anthropic
anthropic.com
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
- No clear commitment that your data will not train their models
- Data retention window not stated
See Before you sign, with what to ask for ↓
Scanned Sep 3, 2026 · Public evidence · Point-in-time
Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.
Before you sign
Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.
What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.
“Anthropic may not train models on Customer Content from Services.”
“We may use your Inputs and Outputs to train and improve Anthropic AI models, unless you opt out through your account settings.”
Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.
What to ask for: Get retention windows, in days, in writing.
“removed immediately from your conversation history and automatically deleted from our back-end within 30 days.”
“delete all copies of Customer Data (including Customer Personal Data) processed by Anthropic or any Subprocessors,”
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
!Will they train on your data?Ask the vendor
Under the Commercial Terms of Service, Anthropic is contractually barred from training models on Customer Content (inputs and outputs) from the commercial Services.
Requires written confirmation — see Before you sign ↓
“Anthropic may not train models on Customer Content from Services.”
“We may use your Inputs and Outputs to train and improve Anthropic AI models, unless you opt out through your account settings.”
!How long do they keep your data?Ask the vendor
Deleted consumer conversations are removed from history immediately and purged from back-end systems within 30 days.
Requires written confirmation — see Before you sign ↓
“removed immediately from your conversation history and automatically deleted from our back-end within 30 days.”
“delete all copies of Customer Data (including Customer Personal Data) processed by Anthropic or any Subprocessors,”
!Who else can access your data?Ask the vendor
The DPA operates a subprocessor regime with a published list (anthropic.com/subprocessors), advance notice of additions, and a 15-day customer objection window; Anthropic remains liable for subprocessor acts.
Confirm in writing: Ask the vendor to state this in writing before signing.
“Anthropic will provide Customer reasonable notice of the new Subprocessor prior to giving the Subprocessor access to Customer Personal Data;”
“retain, use, or disclose Customer Personal Data outside of the direct business relationship”
!Where is your data processed?Ask the vendor
Personal data is processed on servers in the US and other countries outside the EEA and UK, with transfers relying on adequacy decisions and Standard Contractual Clauses; the DPA adds UK and Swiss addenda.
Confirm in writing: Ask the vendor to state this in writing before signing.
“your personal data is transferred to our servers in the US, or to other countries outside the European Economic Area”
!What happens in a security incident?Ask the vendor
The DPA commits to written breach notification without undue delay and in any event within 48 hours of becoming aware of a Security Breach.
Confirm in writing: Ask the vendor to state this in writing before signing.
“Anthropic will notify Customer in writing without undue delay, but in any event within 48 hours, after becoming aware of any Security Breach,”
Key findingsclick a row for the evidence
✓AI governance disclosure at a depth few vendors matchStrong
A versioned Responsible Scaling Policy with published redlines and risk reports, per-model system cards stating training data and safety-level decisions, and named external red-team partners with adverse results disclosed alongside favourable ones.
The transparency artefacts a buyer usually has to request under NDA are public here, and the willingness to publish unfavourable evaluation results is itself evidence the favourable ones are honest.
“In September 2023, we released the first version of our Responsible Scaling Policy (RSP). We believe that risk governance in this rapidly evolving domain should be proportional, iterative, and exportable.”
“The IPI benchmark was built in partnership with Gray Swan, the UK AI Security Institute, the US Center for AI Standards and Innovation, and other model developers.”
“10a Labs spent about 20 hours red-teaming the classifiers on a task involving the creation of ransomware”
“Claude Opus 5 was trained on a proprietary mix of publicly available information from online sources, public and private datasets, user data, and synthetic data generated by other models.”
✓Contractual data protections are public and specificStrong
The public Commercial Terms bar training on Customer Content; the DPA adds 48-hour breach notice, 30-day post-termination deletion extending to subprocessors, a no-sell/no-share commitment, a published subprocessor list with objection rights, and customer-side IP indemnification covering training data.
These commitments sit in signable contract documents rather than rewritable marketing pages, which is the strongest form a public commitment can take short of independent verification.
“Anthropic may not train models on Customer Content from Services.”
“delete all copies of Customer Data (including Customer Personal Data) processed by Anthropic or any Subprocessors,”
“Anthropic will provide Customer reasonable notice of the new Subprocessor prior to giving the Subprocessor access to Customer Personal Data;”
“Anthropic will notify Customer in writing without undue delay, but in any event within 48 hours, after becoming aware of any Security Breach,”
“Anthropic will defend Customer and its personnel, successors, and assigns from and against any Customer Claim”
“retain, use, or disclose Customer Personal Data outside of the direct business relationship”
!Certifications sit behind an access-gated trust portalGap
The only certification evidence on the collected public surface is the DPA's statement of annual external audits with SOC 2 named as an example; the certificates themselves, and any ISO-family certifications, are distributed via the gated trust.anthropic.com portal.
Scope, issuer and validity of the audit programme cannot be assessed from public pages, so independent assurance rests on a vendor assertion until portal documents are obtained and reviewed.
Question for vendor: Provide the current SOC 2 Type II report and any ISO/IEC 27001 or 42001 certificates, including scope statements and validity dates.
“Anthropic is audited annually against known, established industry standards performed by external auditors.”
!Consumer and commercial data-training postures divergeGap
Commercial Customer Content is contractually excluded from training, while consumer Claude.ai trains on inputs and outputs unless the user opts out, and safety-flagged or user-reported conversations are used even after an opt-out.
An organisation's exposure depends on which agreement its usage actually falls under: employees using personal consumer accounts for work content are outside the commercial no-training commitment.
Question for vendor: Confirm in writing which agreement governs each access path in scope, and that all organisational use falls under the Commercial Terms' no-training commitment.
“Anthropic may not train models on Customer Content from Services.”
“We may use your Inputs and Outputs to train and improve Anthropic AI models, unless you opt out through your account settings.”
✓Vulnerability handling is mature in both directionsStrong
Inbound, an RFC 9116 security.txt routes to a HackerOne programme under a published policy; outbound, a coordinated-disclosure policy governs vulnerabilities Anthropic's own AI tooling finds in third-party software, with 90-day defaults and 7-day targets for actively exploited criticals.
A published policy for AI-discovered vulnerabilities is rare and signals the security function has thought past its own perimeter.
“Policy: https://www.anthropic.com/responsible-disclosure-policy”
“Anthropic aims to follow the industry standard 90-day disclosure deadline, provide human-reviewed reports with suggested fixes where we can, and pace our submissions to what maintainers can actually absorb.”
!Declared Google, technically observed AnthropicGap
The vendor's own materials name Google as the model provider, but DNS, certificate, or HTTP evidence points to Anthropic in that role instead.
A supply-chain claim that doesn't match what is technically observable is a disclosure question worth raising directly, not assuming either side is wrong.
Question for vendor: Can you confirm whether Google or Anthropic is the actual model provider?
“Cloud computing resources from Amazon Web Services, Google Cloud Platform and Microsoft Azure, supported by development frameworks including PyTorch, JAX, and Triton.”
!Declared Microsoft Azure, technically observed AWSGap
The vendor's own materials name Microsoft Azure as the platform provider, but DNS, certificate, or HTTP evidence points to AWS in that role instead.
A supply-chain claim that doesn't match what is technically observable is a disclosure question worth raising directly, not assuming either side is wrong.
Question for vendor: Can you confirm whether Microsoft Azure or AWS is the actual platform provider?
“Cloud computing resources from Amazon Web Services, Google Cloud Platform and Microsoft Azure, supported by development frameworks including PyTorch, JAX, and Triton.”
?Technical dependency observed: IntercomObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Intercom as a application builder. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Intercom appears to be involved as a application builder: confirm whether this dependency exists, and whether it processes customer data.
“Anthropic will provide Customer reasonable notice of the new Subprocessor prior to giving the Subprocessor access to Customer Personal Data;”
“Claude Opus 5 was trained on a proprietary mix of publicly available information from online sources, public and private datasets, user data, and synthetic data generated by other models.”
“Cloud computing resources from Amazon Web Services, Google Cloud Platform and Microsoft Azure, supported by development frameworks including PyTorch, JAX, and Triton.”
?Technical dependency observed: StripeObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Anthropic will provide Customer reasonable notice of the new Subprocessor prior to giving the Subprocessor access to Customer Personal Data;”
“Claude Opus 5 was trained on a proprietary mix of publicly available information from online sources, public and private datasets, user data, and synthetic data generated by other models.”
“Cloud computing resources from Amazon Web Services, Google Cloud Platform and Microsoft Azure, supported by development frameworks including PyTorch, JAX, and Triton.”
?Technical dependency observed: MicrosoftObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Anthropic will provide Customer reasonable notice of the new Subprocessor prior to giving the Subprocessor access to Customer Personal Data;”
“Claude Opus 5 was trained on a proprietary mix of publicly available information from online sources, public and private datasets, user data, and synthetic data generated by other models.”
“Cloud computing resources from Amazon Web Services, Google Cloud Platform and Microsoft Azure, supported by development frameworks including PyTorch, JAX, and Triton.”
?Technical dependency observed: AtlassianObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Anthropic will provide Customer reasonable notice of the new Subprocessor prior to giving the Subprocessor access to Customer Personal Data;”
“Claude Opus 5 was trained on a proprietary mix of publicly available information from online sources, public and private datasets, user data, and synthetic data generated by other models.”
“Cloud computing resources from Amazon Web Services, Google Cloud Platform and Microsoft Azure, supported by development frameworks including PyTorch, JAX, and Triton.”
Assurance dimensionsweighted components of one score — not eight separate ratings
Organisation & AI governance15% of the score80
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
“In September 2023, we released the first version of our Responsible Scaling Policy (RSP). We believe that risk governance in this rapidly evolving domain should be proportional, iterative, and exportable.”
“It expands reporting channels, introduces a pathway for employees to make informal inquiries about potential RSP violations, and aligns with RSP Version 3.0.”
Governance & accountability: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
AI system15% of the score60
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
“Claude is an artificial intelligence, trained by Anthropic using Constitutional AI to be safe, accurate, and secure”
“Claude Opus 5 was trained on a proprietary mix of publicly available information from online sources, public and private datasets, user data, and synthetic data generated by other models.”
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
“The IPI benchmark was built in partnership with Gray Swan, the UK AI Security Institute, the US Center for AI Standards and Innovation, and other model developers.”
“10a Labs spent about 20 hours red-teaming the classifiers on a task involving the creation of ransomware”
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
“The Claude Platform release notes list changes to the Claude API, the client SDKs, and the Claude Console, newest first.”
“In September 2023, we released the first version of our Responsible Scaling Policy (RSP). We believe that risk governance in this rapidly evolving domain should be proportional, iterative, and exportable.”
AI system description: vendor-evidenced, not yet independently corroborated.
Testing & evaluation: vendor-evidenced, not yet independently corroborated.
Change management: vendor-evidenced, not yet independently corroborated.
Model10% of the score60
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
“Claude Opus 5 was trained on a proprietary mix of publicly available information from online sources, public and private datasets, user data, and synthetic data generated by other models.”
“The Claude Platform release notes list changes to the Claude API, the client SDKs, and the Claude Console, newest first.”
Model provider transparency: vendor-evidenced, not yet independently corroborated.
Customer data15% of the score60
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
“Anthropic may not train models on Customer Content from Services.”
“We may use your Inputs and Outputs to train and improve Anthropic AI models, unless you opt out through your account settings.”
“removed immediately from your conversation history and automatically deleted from our back-end within 30 days.”
“delete all copies of Customer Data (including Customer Personal Data) processed by Anthropic or any Subprocessors,”
“your personal data is transferred to our servers in the US, or to other countries outside the European Economic Area”
“retain, use, or disclose Customer Personal Data outside of the direct business relationship”
Customer data treatment: vendor-evidenced, not yet independently corroborated.
AI supply chain10% of the score75
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
“Anthropic will provide Customer reasonable notice of the new Subprocessor prior to giving the Subprocessor access to Customer Personal Data;”
“Cloud computing resources from Amazon Web Services, Google Cloud Platform and Microsoft Azure, supported by development frameworks including PyTorch, JAX, and Triton.”
Security foundation15% of the score85
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
“Anthropic will notify Customer in writing without undue delay, but in any event within 48 hours, after becoming aware of any Security Breach,”
“Policy: https://www.anthropic.com/responsible-disclosure-policy”
“Anthropic aims to follow the industry standard 90-day disclosure deadline, provide human-reviewed reports with suggested fixes where we can, and pace our submissions to what maintainers can actually absorb.”
Vulnerability & incident handling: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
Independent assurance evidence10% of the score100
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
“Anthropic is audited annually against known, established industry standards performed by external auditors.”
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Legal & contractual10% of the score60
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
“Anthropic will defend Customer and its personnel, successors, and assigns from and against any Customer Claim”
“Anthropic may not train models on Customer Content from Services.”
“delete all copies of Customer Data (including Customer Personal Data) processed by Anthropic or any Subprocessors,”
Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.
Not graded: Agent — not applicable to this scan.
What would strengthen assuranceeach figure is from today's score — resolving one changes the others
Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 72 → up to 84 with every identified gap resolved.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
View as list
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.
Map your inherited responsibilitiesAssurance evidence: certifications 4 — registry checks and verification ladders, click to view
SOC 3 Type 2 (the general-use report of the SOC 2 Type 2 examination): Anthropic's AI Services system, trust services criteria security, availability, confidentiality and privacy; period 1 Oct 2024 - 30 Sep 2025; unqualified opinion signed 12 Nov 2025. Cloud-hosting subservice organisations carved out. Vault: Gated/Anthropic/2025-11_anthropic-ai-services-soc3-type2.pdf.
Checked against SOC 3 Type 2 report held in the TrustyCyber vault (Anthropic trust portal), Sep 3, 2026: Verified on the registry
Checked against IAF CertSearch, Sep 3, 2026: Verified on the registry
Checked against CSA STAR Registry, Sep 3, 2026: Verified on the registry
RSP describes an ISO 27001-ALIGNED programme; the certification itself is registry-verifiable.
Checked against IAF CertSearch, Sep 3, 2026: Verified on the registry
Sources 16 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
Want to go further?
This scan assesses Anthropic at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.
Scan a specific product →This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
