Claude
anthropic.com
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
- No formal subprocessor register disclosed
- Data retention window not stated
- Processing location not disclosed
See Before you sign, with what to ask for ↓
Scanned Aug 28, 2026 · Public evidence · Point-in-time
Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.
Before you sign
Why it matters: The vendor names AI-related providers or partially addresses its supply chain, but the public sources scanned do not include a formal, dated subprocessor register.
What to ask for: Request a dated subprocessor register with change-notification terms for the DPA/order form.
Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.
What to ask for: Get retention windows, in days, in writing.
“retention of the Customer Data by Anthropic is necessary to resolve a dispute between the parties, or (iii) retention of the Customer Data is necessary to combat harmful use of the Services.”
“delete individual conversations , which will be removed immediately from your conversation history and automatically deleted from our back-end within 30 days.”
“Claude Fable 5 requires 30-day data retention and is not available under zero data retention.”
Why it matters: The public sources scanned do not state where customer data is processed or offer a residency option.
What to ask for: Pin processing regions per data classification in the contract.
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
✓Will they train on your data?Clear
The commercial terms state Anthropic may not train models on Customer Content from the Services.
“Anthropic may not train models on Customer Content from Services.”
!How long do they keep your data?Ask the vendor
The DPA commits to deletion of Customer Data with exceptions limited to legal requirements, dispute resolution, and combating harmful use.
Requires written confirmation — see Before you sign ↓
“retention of the Customer Data by Anthropic is necessary to resolve a dispute between the parties, or (iii) retention of the Customer Data is necessary to combat harmful use of the Services.”
“delete individual conversations , which will be removed immediately from your conversation history and automatically deleted from our back-end within 30 days.”
“Claude Fable 5 requires 30-day data retention and is not available under zero data retention.”
✓Who else can access your data?Clear
The DPA prohibits selling or sharing Customer Personal Data and any retention, use or disclosure outside the direct business relationship.
“retain, use, or disclose Customer Personal Data outside of the direct business relationship and for any purpose other than for the business purposes specified in Part B of Schedule 1”
!Where is your data processed?Ask the vendor
Not found in the public sources scanned — ask the vendor directly.
✓What happens in a security incident?Clear
Deployment safeguards draw on an incident response protocol, a bug bounty programme, and internal and external red-teaming.
“incident response protocol, bug bounty program, and internal and external red-teaming efforts.”
Key findingsclick a row for the evidence
✓Per-model documentation directly covers the assessed productStrong
System cards, model reports with external red-team results, and named per-model retention requirements all speak about Claude itself, not just the company.
Product-scoped evidence is what a system card is graded on; Claude has it natively.
“System cards document the capabilities, safety evaluations, and responsible deployment decisions for Claude models.”
“The IPI benchmark was built in partnership with Gray Swan, the UK AI Security Institute, the US Center for AI Standards and Innovation, and other model developers.”
“Claude Fable 5 requires 30-day data retention and is not available under zero data retention.”
✓Contractual data commitments apply to the productStrong
No training on Customer Content and customer ownership of inputs/outputs are organisation-wide commitments that carry to Claude deployments.
The core buyer questions are answered in the governing terms.
“Anthropic may not train models on Customer Content from Services.”
“retains all rights to its Inputs, and (b) owns its Outputs.”
!Consumer and commercial data terms differ — confirm which appliesGap
Consumer services document 30-day back-end deletion, while commercial terms and the DPA govern enterprise use; Claude Fable 5 additionally requires 30-day retention.
Which policy applies depends on the plan and model in use.
Question for vendor: Confirm in writing the retention mode and policy applying to your specific plan and model selection.
“delete individual conversations , which will be removed immediately from your conversation history and automatically deleted from our back-end within 30 days.”
“retention of the Customer Data by Anthropic is necessary to resolve a dispute between the parties, or (iii) retention of the Customer Data is necessary to combat harmful use of the Services.”
“Claude Fable 5 requires 30-day data retention and is not available under zero data retention.”
!Public subprocessor register not found in collected sourcesGap
The DPA defines subprocessor obligations but the named register was not among the collected public pages.
Buyers need the named list to assess onward transfers.
Question for vendor: Provide the current subprocessor list and change-notification mechanism.
“means an entity engaged by Anthropic to process Customer Personal Data.”
!Declared Google, technically observed AnthropicGap
The vendor's own materials name Google as the model provider, but DNS, certificate, or HTTP evidence points to Anthropic in that role instead.
A supply-chain claim that doesn't match what is technically observable is a disclosure question worth raising directly, not assuming either side is wrong.
Question for vendor: Can you confirm whether Google or Anthropic is the actual model provider?
“The IPI benchmark was built in partnership with Gray Swan, the UK AI Security Institute, the US Center for AI Standards and Innovation, and other model developers.”
!Declared Microsoft Azure, technically observed AWSGap
The vendor's own materials name Microsoft Azure as the platform provider, but DNS, certificate, or HTTP evidence points to AWS in that role instead.
A supply-chain claim that doesn't match what is technically observable is a disclosure question worth raising directly, not assuming either side is wrong.
Question for vendor: Can you confirm whether Microsoft Azure or AWS is the actual platform provider?
“The IPI benchmark was built in partnership with Gray Swan, the UK AI Security Institute, the US Center for AI Standards and Innovation, and other model developers.”
?Technical dependency observed: StripeObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“means an entity engaged by Anthropic to process Customer Personal Data.”
?Technical dependency observed: MicrosoftObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“means an entity engaged by Anthropic to process Customer Personal Data.”
?Technical dependency observed: AtlassianObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“means an entity engaged by Anthropic to process Customer Personal Data.”
Assurance dimensionsweighted components of one score — not eight separate ratings
Organisation & AI governance15% of the scoreorganisation-level evidence60
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
“Anthropic’s Responsible Scaling Policy Anticipating and securing against emerging threats that accompany increasingly powerful models”
“Anthropic’s Transparency Hub A look at Anthropic's key processes, programs, and practices for responsible AI development.”
“Risk Council sponsored by executive leadership to oversee security programs. Follow a risk-based approach aligned with ISO 27001 standard.”
Governance & accountability: vendor-evidenced, not yet independently corroborated.
AI system15% of the score65
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
“Claude is an artificial intelligence, trained by Anthropic using Constitutional AI to be safe, accurate, and secure — the trusted assistant for you to do your best work.”
“System cards document the capabilities, safety evaluations, and responsible deployment decisions for Claude models.”
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
“System cards document the capabilities, safety evaluations, and responsible deployment decisions for Claude models.”
“The IPI benchmark was built in partnership with Gray Swan, the UK AI Security Institute, the US Center for AI Standards and Innovation, and other model developers.”
“Partner with a diverse range of external red team and penetration testing experts. Simulate sophisticated attacks, including insider threat and software supply chain compromise scenarios, to identify vulnerabilities.”
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
“The Claude Platform release notes list changes to the Claude API, the client SDKs, and the Claude Console, newest first.”
“Claude Fable 5 requires 30-day data retention and is not available under zero data retention.”
AI system description: vendor-evidenced, not yet independently corroborated.
Change management: vendor-evidenced, not yet independently corroborated.
Model10% of the score60
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
“System cards document the capabilities, safety evaluations, and responsible deployment decisions for Claude models.”
“Claude Fable 5 requires 30-day data retention and is not available under zero data retention.”
Model provider transparency: vendor-evidenced, not yet independently corroborated.
Customer data15% of the score60
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
“Anthropic may not train models on Customer Content from Services.”
“retains all rights to its Inputs, and (b) owns its Outputs.”
“retention of the Customer Data by Anthropic is necessary to resolve a dispute between the parties, or (iii) retention of the Customer Data is necessary to combat harmful use of the Services.”
“delete individual conversations , which will be removed immediately from your conversation history and automatically deleted from our back-end within 30 days.”
“Claude Fable 5 requires 30-day data retention and is not available under zero data retention.”
“retain, use, or disclose Customer Personal Data outside of the direct business relationship and for any purpose other than for the business purposes specified in Part B of Schedule 1”
Customer data treatment: vendor-evidenced, not yet independently corroborated.
AI supply chain10% of the scoreorganisation-level evidence40
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
“means an entity engaged by Anthropic to process Customer Personal Data.”
Security foundation15% of the scoreorganisation-level evidence85
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
“incident response protocol, bug bounty program, and internal and external red-teaming efforts.”
“Contact: https://hackerone.com/4f1f16ba-10d3-4d09-9ecc-c721aad90f24/embedded_submissions/new Expires: 2026-12-31T23:59:00.000Z Preferred-Languages: en Canonical: https://anthropic.com/.well-known/security.txt Policy: https://www.anthropic.com/responsible-disclosure-policy”
“Coordinated vulnerability disclosure for Claude-discovered vulnerabilities Last updated Mar 6, 2026 Purpose Statement: Anthropic is building AI tools that find software vulnerabilities faster and cheaper and we are working towards a clear framework for handling identified vulnerabilities,”
“Conduct consistent scanning of all third-party dependencies and maintain a comprehensive vulnerability data repository.”
Vulnerability & incident handling: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
Independent assurance evidence10% of the scoreorganisation-level evidence81
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
“Risk Council sponsored by executive leadership to oversee security programs. Follow a risk-based approach aligned with ISO 27001 standard.”
Read from the registry record above — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.
Legal & contractual10% of the scoreorganisation-level evidence60
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
“The parties agree that, to the extent required by Applicable Data Protection Laws, the terms of the SCCs Module Two (controller to processor)”
“our policy on the countries and regions Anthropic currently supports (“ Supported Regions Policy ”) and (c) our Service Specific Terms”
“Anthropic may not train models on Customer Content from Services.”
Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.
Not graded: Agent — not applicable to this scan.
What would strengthen assuranceeach figure is from today's score — resolving one changes the others
Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 65 → up to 81 with every identified gap resolved.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
View as list
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.
Map your inherited responsibilitiesAssurance evidence: certifications 3 — registry checks and verification ladders, click to view
RSP describes an ISO 27001-ALIGNED programme; certification is registry-verifiable.
Checked against IAF CertSearch, Aug 28, 2026: Verified on the registry
Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.
SOC 3 Type 2 (the general-use report of the SOC 2 Type 2 examination): Anthropic's AI Services system, trust services criteria security, availability, confidentiality and privacy; period 1 October 2024 to 30 September 2025; unqualified opinion signed 12 November 2025. Claude sits within the AI Services system, so the assessed product is in scope. Cloud-hosting subservice organisations are carved out. The period is now more than ten months past its end - request the successor report on the next pass. Vault: Gated/Anthropic/2025-11_anthropic-ai-services-soc3-type2.pdf.
Checked against SOC 3 Type 2 report held in the TrustyCyber vault (Anthropic trust portal), Aug 27, 2026: Verified on the registry
Sources 16 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
