Anthropic

anthropic.com

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
72 / 100B
Procurement decision
Approve with conditions
2 conditions outstanding
  • No clear commitment that your data will not train their models
  • Data retention window not stated

See Before you sign, with what to ask for ↓

Evidence Medium HighFreshness CurrentVerification Partial

Scanned Sep 3, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

No clear commitment that your data will not train their modelsCondition

Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.

What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.

Evidence
Vendor publishedCommercial Terms of Service \ Anthropicretrieved Sep 3, 2026
Anthropic may not train models on Customer Content from Services.
Vendor publishedPrivacy Policy \ Anthropicretrieved Sep 3, 2026
We may use your Inputs and Outputs to train and improve Anthropic AI models, unless you opt out through your account settings.
Data retention window not statedCondition

Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.

What to ask for: Get retention windows, in days, in writing.

Evidence
Vendor publishedPrivacy Policy \ Anthropicretrieved Sep 3, 2026
removed immediately from your conversation history and automatically deleted from our back-end within 30 days.
Vendor publishedData Processing Addendum \ Anthropicretrieved Sep 3, 2026
delete all copies of Customer Data (including Customer Personal Data) processed by Anthropic or any Subprocessors,

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

!Will they train on your data?Ask the vendor

Under the Commercial Terms of Service, Anthropic is contractually barred from training models on Customer Content (inputs and outputs) from the commercial Services.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedCommercial Terms of Service \ Anthropicretrieved Sep 3, 2026
Anthropic may not train models on Customer Content from Services.
Vendor publishedPrivacy Policy \ Anthropicretrieved Sep 3, 2026
We may use your Inputs and Outputs to train and improve Anthropic AI models, unless you opt out through your account settings.
!How long do they keep your data?Ask the vendor

Deleted consumer conversations are removed from history immediately and purged from back-end systems within 30 days.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedPrivacy Policy \ Anthropicretrieved Sep 3, 2026
removed immediately from your conversation history and automatically deleted from our back-end within 30 days.
Vendor publishedData Processing Addendum \ Anthropicretrieved Sep 3, 2026
delete all copies of Customer Data (including Customer Personal Data) processed by Anthropic or any Subprocessors,
!Who else can access your data?Ask the vendor

The DPA operates a subprocessor regime with a published list (anthropic.com/subprocessors), advance notice of additions, and a 15-day customer objection window; Anthropic remains liable for subprocessor acts.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedData Processing Addendum \ Anthropicretrieved Sep 3, 2026
Anthropic will provide Customer reasonable notice of the new Subprocessor prior to giving the Subprocessor access to Customer Personal Data;
Vendor publishedData Processing Addendum \ Anthropicretrieved Sep 3, 2026
retain, use, or disclose Customer Personal Data outside of the direct business relationship
!Where is your data processed?Ask the vendor

Personal data is processed on servers in the US and other countries outside the EEA and UK, with transfers relying on adequacy decisions and Standard Contractual Clauses; the DPA adds UK and Swiss addenda.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedPrivacy Policy \ Anthropicretrieved Sep 3, 2026
your personal data is transferred to our servers in the US, or to other countries outside the European Economic Area
!What happens in a security incident?Ask the vendor

The DPA commits to written breach notification without undue delay and in any event within 48 hours of becoming aware of a Security Breach.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedData Processing Addendum \ Anthropicretrieved Sep 3, 2026
Anthropic will notify Customer in writing without undue delay, but in any event within 48 hours, after becoming aware of any Security Breach,

Key findingsclick a row for the evidence

AI governance disclosure at a depth few vendors matchStrong

A versioned Responsible Scaling Policy with published redlines and risk reports, per-model system cards stating training data and safety-level decisions, and named external red-team partners with adverse results disclosed alongside favourable ones.

The transparency artefacts a buyer usually has to request under NDA are public here, and the willingness to publish unfavourable evaluation results is itself evidence the favourable ones are honest.

Evidence
In September 2023, we released the first version of our Responsible Scaling Policy (RSP). We believe that risk governance in this rapidly evolving domain should be proportional, iterative, and exportable.
Vendor publishedAnthropic’s Transparency Hub \ Anthropicretrieved Sep 3, 2026
The IPI benchmark was built in partnership with Gray Swan, the UK AI Security Institute, the US Center for AI Standards and Innovation, and other model developers.
Vendor publishedAnthropic’s Transparency Hub \ Anthropicretrieved Sep 3, 2026
10a Labs spent about 20 hours red-teaming the classifiers on a task involving the creation of ransomware
Vendor publishedAnthropic’s Transparency Hub \ Anthropicretrieved Sep 3, 2026
Claude Opus 5 was trained on a proprietary mix of publicly available information from online sources, public and private datasets, user data, and synthetic data generated by other models.
Contractual data protections are public and specificStrong

The public Commercial Terms bar training on Customer Content; the DPA adds 48-hour breach notice, 30-day post-termination deletion extending to subprocessors, a no-sell/no-share commitment, a published subprocessor list with objection rights, and customer-side IP indemnification covering training data.

These commitments sit in signable contract documents rather than rewritable marketing pages, which is the strongest form a public commitment can take short of independent verification.

Evidence
Vendor publishedCommercial Terms of Service \ Anthropicretrieved Sep 3, 2026
Anthropic may not train models on Customer Content from Services.
Vendor publishedData Processing Addendum \ Anthropicretrieved Sep 3, 2026
delete all copies of Customer Data (including Customer Personal Data) processed by Anthropic or any Subprocessors,
Vendor publishedData Processing Addendum \ Anthropicretrieved Sep 3, 2026
Anthropic will provide Customer reasonable notice of the new Subprocessor prior to giving the Subprocessor access to Customer Personal Data;
Vendor publishedData Processing Addendum \ Anthropicretrieved Sep 3, 2026
Anthropic will notify Customer in writing without undue delay, but in any event within 48 hours, after becoming aware of any Security Breach,
Vendor publishedCommercial Terms of Service \ Anthropicretrieved Sep 3, 2026
Anthropic will defend Customer and its personnel, successors, and assigns from and against any Customer Claim
Vendor publishedData Processing Addendum \ Anthropicretrieved Sep 3, 2026
retain, use, or disclose Customer Personal Data outside of the direct business relationship
!Certifications sit behind an access-gated trust portalGap

The only certification evidence on the collected public surface is the DPA's statement of annual external audits with SOC 2 named as an example; the certificates themselves, and any ISO-family certifications, are distributed via the gated trust.anthropic.com portal.

Scope, issuer and validity of the audit programme cannot be assessed from public pages, so independent assurance rests on a vendor assertion until portal documents are obtained and reviewed.

Question for vendor: Provide the current SOC 2 Type II report and any ISO/IEC 27001 or 42001 certificates, including scope statements and validity dates.

Evidence
Vendor publishedData Processing Addendum \ Anthropicretrieved Sep 3, 2026
Anthropic is audited annually against known, established industry standards performed by external auditors.
!Consumer and commercial data-training postures divergeGap

Commercial Customer Content is contractually excluded from training, while consumer Claude.ai trains on inputs and outputs unless the user opts out, and safety-flagged or user-reported conversations are used even after an opt-out.

An organisation's exposure depends on which agreement its usage actually falls under: employees using personal consumer accounts for work content are outside the commercial no-training commitment.

Question for vendor: Confirm in writing which agreement governs each access path in scope, and that all organisational use falls under the Commercial Terms' no-training commitment.

Evidence
Vendor publishedCommercial Terms of Service \ Anthropicretrieved Sep 3, 2026
Anthropic may not train models on Customer Content from Services.
Vendor publishedPrivacy Policy \ Anthropicretrieved Sep 3, 2026
We may use your Inputs and Outputs to train and improve Anthropic AI models, unless you opt out through your account settings.
Vulnerability handling is mature in both directionsStrong

Inbound, an RFC 9116 security.txt routes to a HackerOne programme under a published policy; outbound, a coordinated-disclosure policy governs vulnerabilities Anthropic's own AI tooling finds in third-party software, with 90-day defaults and 7-day targets for actively exploited criticals.

A published policy for AI-discovered vulnerabilities is rare and signals the security function has thought past its own perimeter.

Evidence
Vendor publishedanthropic.comretrieved Sep 3, 2026
Policy: https://www.anthropic.com/responsible-disclosure-policy
Anthropic aims to follow the industry standard 90-day disclosure deadline, provide human-reviewed reports with suggested fixes where we can, and pace our submissions to what maintainers can actually absorb.
!Declared Google, technically observed AnthropicGap

The vendor's own materials name Google as the model provider, but DNS, certificate, or HTTP evidence points to Anthropic in that role instead.

A supply-chain claim that doesn't match what is technically observable is a disclosure question worth raising directly, not assuming either side is wrong.

Question for vendor: Can you confirm whether Google or Anthropic is the actual model provider?

Evidence
Externally corroboratedAnthropic’s Transparency Hub \ Anthropicretrieved Sep 3, 2026
Cloud computing resources from Amazon Web Services, Google Cloud Platform and Microsoft Azure, supported by development frameworks including PyTorch, JAX, and Triton.
!Declared Microsoft Azure, technically observed AWSGap

The vendor's own materials name Microsoft Azure as the platform provider, but DNS, certificate, or HTTP evidence points to AWS in that role instead.

A supply-chain claim that doesn't match what is technically observable is a disclosure question worth raising directly, not assuming either side is wrong.

Question for vendor: Can you confirm whether Microsoft Azure or AWS is the actual platform provider?

Evidence
Externally corroboratedAnthropic’s Transparency Hub \ Anthropicretrieved Sep 3, 2026
Cloud computing resources from Amazon Web Services, Google Cloud Platform and Microsoft Azure, supported by development frameworks including PyTorch, JAX, and Triton.
?Technical dependency observed: IntercomObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Intercom as a application builder. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Intercom appears to be involved as a application builder: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedData Processing Addendum \ Anthropicretrieved Sep 3, 2026
Anthropic will provide Customer reasonable notice of the new Subprocessor prior to giving the Subprocessor access to Customer Personal Data;
Vendor publishedAnthropic’s Transparency Hub \ Anthropicretrieved Sep 3, 2026
Claude Opus 5 was trained on a proprietary mix of publicly available information from online sources, public and private datasets, user data, and synthetic data generated by other models.
Externally corroboratedAnthropic’s Transparency Hub \ Anthropicretrieved Sep 3, 2026
Cloud computing resources from Amazon Web Services, Google Cloud Platform and Microsoft Azure, supported by development frameworks including PyTorch, JAX, and Triton.
?Technical dependency observed: StripeObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedData Processing Addendum \ Anthropicretrieved Sep 3, 2026
Anthropic will provide Customer reasonable notice of the new Subprocessor prior to giving the Subprocessor access to Customer Personal Data;
Vendor publishedAnthropic’s Transparency Hub \ Anthropicretrieved Sep 3, 2026
Claude Opus 5 was trained on a proprietary mix of publicly available information from online sources, public and private datasets, user data, and synthetic data generated by other models.
Externally corroboratedAnthropic’s Transparency Hub \ Anthropicretrieved Sep 3, 2026
Cloud computing resources from Amazon Web Services, Google Cloud Platform and Microsoft Azure, supported by development frameworks including PyTorch, JAX, and Triton.
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedData Processing Addendum \ Anthropicretrieved Sep 3, 2026
Anthropic will provide Customer reasonable notice of the new Subprocessor prior to giving the Subprocessor access to Customer Personal Data;
Vendor publishedAnthropic’s Transparency Hub \ Anthropicretrieved Sep 3, 2026
Claude Opus 5 was trained on a proprietary mix of publicly available information from online sources, public and private datasets, user data, and synthetic data generated by other models.
Externally corroboratedAnthropic’s Transparency Hub \ Anthropicretrieved Sep 3, 2026
Cloud computing resources from Amazon Web Services, Google Cloud Platform and Microsoft Azure, supported by development frameworks including PyTorch, JAX, and Triton.
?Technical dependency observed: AtlassianObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedData Processing Addendum \ Anthropicretrieved Sep 3, 2026
Anthropic will provide Customer reasonable notice of the new Subprocessor prior to giving the Subprocessor access to Customer Personal Data;
Vendor publishedAnthropic’s Transparency Hub \ Anthropicretrieved Sep 3, 2026
Claude Opus 5 was trained on a proprietary mix of publicly available information from online sources, public and private datasets, user data, and synthetic data generated by other models.
Externally corroboratedAnthropic’s Transparency Hub \ Anthropicretrieved Sep 3, 2026
Cloud computing resources from Amazon Web Services, Google Cloud Platform and Microsoft Azure, supported by development frameworks including PyTorch, JAX, and Triton.

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score80
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
In September 2023, we released the first version of our Responsible Scaling Policy (RSP). We believe that risk governance in this rapidly evolving domain should be proportional, iterative, and exportable.
It expands reporting channels, introduces a pathway for employees to make informal inquiries about potential RSP violations, and aligns with RSP Version 3.0.

Governance & accountability: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

AI system15% of the score60
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
Vendor publishedClauderetrieved Sep 3, 2026
Claude is an artificial intelligence, trained by Anthropic using Constitutional AI to be safe, accurate, and secure
Vendor publishedAnthropic’s Transparency Hub \ Anthropicretrieved Sep 3, 2026
Claude Opus 5 was trained on a proprietary mix of publicly available information from online sources, public and private datasets, user data, and synthetic data generated by other models.
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Partial
Evidence — Testing & evaluation
Vendor publishedAnthropic’s Transparency Hub \ Anthropicretrieved Sep 3, 2026
The IPI benchmark was built in partnership with Gray Swan, the UK AI Security Institute, the US Center for AI Standards and Innovation, and other model developers.
Vendor publishedAnthropic’s Transparency Hub \ Anthropicretrieved Sep 3, 2026
10a Labs spent about 20 hours red-teaming the classifiers on a task involving the creation of ransomware
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Partial
Evidence — Change management
The Claude Platform release notes list changes to the Claude API, the client SDKs, and the Claude Console, newest first.
In September 2023, we released the first version of our Responsible Scaling Policy (RSP). We believe that risk governance in this rapidly evolving domain should be proportional, iterative, and exportable.

AI system description: vendor-evidenced, not yet independently corroborated.

Testing & evaluation: vendor-evidenced, not yet independently corroborated.

Change management: vendor-evidenced, not yet independently corroborated.

Model10% of the score60
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Partial
Evidence — Model & provider transparency
Vendor publishedAnthropic’s Transparency Hub \ Anthropicretrieved Sep 3, 2026
Claude Opus 5 was trained on a proprietary mix of publicly available information from online sources, public and private datasets, user data, and synthetic data generated by other models.
The Claude Platform release notes list changes to the Claude API, the client SDKs, and the Claude Console, newest first.

Model provider transparency: vendor-evidenced, not yet independently corroborated.

Customer data15% of the score60
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Vendor publishedCommercial Terms of Service \ Anthropicretrieved Sep 3, 2026
Anthropic may not train models on Customer Content from Services.
Vendor publishedPrivacy Policy \ Anthropicretrieved Sep 3, 2026
We may use your Inputs and Outputs to train and improve Anthropic AI models, unless you opt out through your account settings.
Vendor publishedPrivacy Policy \ Anthropicretrieved Sep 3, 2026
removed immediately from your conversation history and automatically deleted from our back-end within 30 days.
Vendor publishedData Processing Addendum \ Anthropicretrieved Sep 3, 2026
delete all copies of Customer Data (including Customer Personal Data) processed by Anthropic or any Subprocessors,
Vendor publishedPrivacy Policy \ Anthropicretrieved Sep 3, 2026
your personal data is transferred to our servers in the US, or to other countries outside the European Economic Area
Vendor publishedData Processing Addendum \ Anthropicretrieved Sep 3, 2026
retain, use, or disclose Customer Personal Data outside of the direct business relationship

Customer data treatment: vendor-evidenced, not yet independently corroborated.

AI supply chain10% of the score75
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Covered
Evidence — Subprocessors & supply chain
Vendor publishedData Processing Addendum \ Anthropicretrieved Sep 3, 2026
Anthropic will provide Customer reasonable notice of the new Subprocessor prior to giving the Subprocessor access to Customer Personal Data;
Externally corroboratedAnthropic’s Transparency Hub \ Anthropicretrieved Sep 3, 2026
Cloud computing resources from Amazon Web Services, Google Cloud Platform and Microsoft Azure, supported by development frameworks including PyTorch, JAX, and Triton.
Security foundation15% of the score85
Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Evidence — Vulnerability & incident handling
Vendor publishedData Processing Addendum \ Anthropicretrieved Sep 3, 2026
Anthropic will notify Customer in writing without undue delay, but in any event within 48 hours, after becoming aware of any Security Breach,
Vendor publishedanthropic.comretrieved Sep 3, 2026
Policy: https://www.anthropic.com/responsible-disclosure-policy
Anthropic aims to follow the industry standard 90-day disclosure deadline, provide human-reviewed reports with suggested fixes where we can, and pace our submissions to what maintainers can actually absorb.

Vulnerability & incident handling: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

Independent assurance evidence10% of the score100
Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Covered
Evidence — Independent assurance
Vendor publishedData Processing Addendum \ Anthropicretrieved Sep 3, 2026
Anthropic is audited annually against known, established industry standards performed by external auditors.
Registry verifiedCSA STAR Registry record — CSA STAR Level 2retrieved Sep 3, 2026

Read from the registry record above — cited, not reproduced.

Registry verifiedIAF CertSearch record — ISO/IEC 42001retrieved Sep 3, 2026

Read from the registry record above — cited, not reproduced.

Registry verifiedIAF CertSearch record — ISO/IEC 27001retrieved Sep 3, 2026

Read from the registry record above — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Legal & contractual10% of the score60
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Vendor publishedCommercial Terms of Service \ Anthropicretrieved Sep 3, 2026
Anthropic will defend Customer and its personnel, successors, and assigns from and against any Customer Claim
Vendor publishedCommercial Terms of Service \ Anthropicretrieved Sep 3, 2026
Anthropic may not train models on Customer Content from Services.
Vendor publishedData Processing Addendum \ Anthropicretrieved Sep 3, 2026
delete all copies of Customer Data (including Customer Personal Data) processed by Anthropic or any Subprocessors,

Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+3Have Customer data treatment disclosures independently corroboratedData 6075
+3Have Governance & accountability disclosures independently corroboratedOrganisation 8095
+3Have Vulnerability & incident handling disclosures independently corroboratedSecurity Foundation 85100
+2Have Legal & contractual transparency disclosures independently corroboratedLegal Contractual 6075
+2Have Model provider transparency disclosures independently corroboratedModel 6075

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 72 → up to 84 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESINFRASTRUCTUREAnthropicAnthropicClaudeClaudeAmazon Web ServicesAmazon Web ServicesGoogle Cloud PlatformGoogle Cloud PlatformMicrosoft AzureMicrosoft AzureAmazon BedrockAmazon BedrockGoogle Vertex AIGoogle Vertex AIMicrosoft Azure AI FoundryMicrosoft Azure AI Foundry
View as list
Anthropic Uses Infrastructure Amazon Web Services
Anthropic Uses Infrastructure Google Cloud Platform
Anthropic Uses Infrastructure Microsoft Azure
Claude Uses Infrastructure Amazon Bedrock
Claude Uses Infrastructure Google Vertex AI
Claude Uses Infrastructure Microsoft Azure AI Foundry

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 4 — registry checks and verification ladders, click to view
SOC 2Claimed & corroborated

SOC 3 Type 2 (the general-use report of the SOC 2 Type 2 examination): Anthropic's AI Services system, trust services criteria security, availability, confidentiality and privacy; period 1 Oct 2024 - 30 Sep 2025; unqualified opinion signed 12 Nov 2025. Cloud-hosting subservice organisations carved out. Vault: Gated/Anthropic/2025-11_anthropic-ai-services-soc3-type2.pdf.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against SOC 3 Type 2 report held in the TrustyCyber vault (Anthropic trust portal), Sep 3, 2026: Verified on the registry

ISO/IEC 42001Claimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Currentuntil Jan 5, 2028

Checked against IAF CertSearch, Sep 3, 2026: Verified on the registry

CSA STAR Level 2Claimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against CSA STAR Registry, Sep 3, 2026: Verified on the registry

ISO/IEC 27001Claimed & corroborated

RSP describes an ISO 27001-ALIGNED programme; the certification itself is registry-verifiable.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Currentuntil Jan 6, 2028

Checked against IAF CertSearch, Sep 3, 2026: Verified on the registry

Sources 16 — click to view
Anthropic’s Responsible Scaling Policy \ Anthropic
AI Documentation · Vendor · retrieved Sep 3, 2026
https://www.anthropic.com/.well-known/security.txt
Trust Or Security Page · Vendor · retrieved Sep 3, 2026
Data Processing Addendum \ Anthropic
DPA · Vendor · retrieved Sep 3, 2026
Anthropic Trust Center
Subprocessor List · Vendor · retrieved Sep 3, 2026
Privacy Policy \ Anthropic
Privacy Notice · Vendor · retrieved Sep 3, 2026
Anthropic’s Transparency Hub \ Anthropic
Certification Or Compliance Page · Vendor · retrieved Sep 3, 2026
Claude
Product Documentation · Vendor · retrieved Sep 3, 2026
Commercial Terms of Service \ Anthropic
Terms · Vendor · retrieved Sep 3, 2026
Claude Platform release notes - Claude Platform Docs
Changelog Or Release Notes · Vendor · retrieved Sep 3, 2026
How to get support | Anthropic Help Center
Technical Article · Vendor · retrieved Sep 3, 2026
Model system cards \ Anthropic
AI Documentation · Vendor · retrieved Sep 3, 2026
CSA STAR Registry record — CSA STAR Level 2
External Registry Or Certification Evidence · Registry · retrieved Sep 3, 2026
IAF CertSearch record — ISO/IEC 42001
External Registry Or Certification Evidence · Registry · retrieved Sep 3, 2026
IAF CertSearch record — ISO/IEC 27001
External Registry Or Certification Evidence · Registry · retrieved Sep 3, 2026
SOC 3 Type 2 report held in the TrustyCyber vault (Anthropic trust portal) record — SOC 2
External Registry Or Certification Evidence · External Corroborating · retrieved Sep 3, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).

Want to go further?

This scan assesses Anthropic at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.

Scan a specific product →

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.