Anthropic

anthropic.com

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
70 / 100B
Procurement decision
Approve with conditions
3 conditions outstanding
  • No formal subprocessor register disclosed
  • Data retention window not stated
  • Processing location not disclosed

See Before you sign, with what to ask for ↓

Evidence Medium HighFreshness CurrentVerification Partial

Scanned Aug 28, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

No formal subprocessor register disclosedCondition

Why it matters: The vendor names AI-related providers or partially addresses its supply chain, but the public sources scanned do not include a formal, dated subprocessor register.

What to ask for: Request a dated subprocessor register with change-notification terms for the DPA/order form.

Data retention window not statedCondition

Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.

What to ask for: Get retention windows, in days, in writing.

Evidence
Vendor publishedData Processing Addendum \ Anthropicretrieved Aug 28, 2026
retention of the Customer Data by Anthropic is necessary to resolve a dispute between the parties, or (iii) retention of the Customer Data is necessary to combat harmful use of the Services.
Vendor publishedPrivacy Policy \ Anthropicretrieved Aug 28, 2026
delete individual conversations , which will be removed immediately from your conversation history and automatically deleted from our back-end within 30 days.
Vendor publishedClaude Platform release notes - Claude Platform Docsretrieved Aug 28, 2026
Claude Fable 5 requires 30-day data retention and is not available under zero data retention.
Processing location not disclosedCondition

Why it matters: The public sources scanned do not state where customer data is processed or offer a residency option.

What to ask for: Pin processing regions per data classification in the contract.

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

Will they train on your data?Clear

The commercial terms state Anthropic may not train models on Customer Content from the Services.

Evidence
Vendor publishedCommercial Terms of Service \ Anthropicretrieved Aug 28, 2026
Anthropic may not train models on Customer Content from Services.
!How long do they keep your data?Ask the vendor

The DPA commits to deletion of Customer Data with exceptions limited to legal requirements, dispute resolution, and combating harmful use.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedData Processing Addendum \ Anthropicretrieved Aug 28, 2026
retention of the Customer Data by Anthropic is necessary to resolve a dispute between the parties, or (iii) retention of the Customer Data is necessary to combat harmful use of the Services.
Vendor publishedPrivacy Policy \ Anthropicretrieved Aug 28, 2026
delete individual conversations , which will be removed immediately from your conversation history and automatically deleted from our back-end within 30 days.
Vendor publishedClaude Platform release notes - Claude Platform Docsretrieved Aug 28, 2026
Claude Fable 5 requires 30-day data retention and is not available under zero data retention.
Who else can access your data?Clear

The DPA prohibits selling or sharing Customer Personal Data and any retention, use or disclosure outside the direct business relationship.

Evidence
Vendor publishedData Processing Addendum \ Anthropicretrieved Aug 28, 2026
retain, use, or disclose Customer Personal Data outside of the direct business relationship and for any purpose other than for the business purposes specified in Part B of Schedule 1
!Where is your data processed?Ask the vendor

Not found in the public sources scanned — ask the vendor directly.

Requires written confirmation — see Before you sign ↓

What happens in a security incident?Clear

Deployment safeguards draw on an incident response protocol, a bug bounty programme, and internal and external red-teaming.

Evidence
Vendor publishedAnthropic’s Responsible Scaling Policy \ Anthropicretrieved Aug 28, 2026
incident response protocol, bug bounty program, and internal and external red-teaming efforts.

Key findingsclick a row for the evidence

The model transparency surface is best-in-classStrong

Versioned RSP, per-model system cards, and a Transparency Hub with detailed model reports including external red-team results.

This is the disclosure depth the rest of the market is measured against.

Evidence
Vendor publishedAnthropic’s Responsible Scaling Policy \ Anthropicretrieved Aug 28, 2026
Anthropic’s Responsible Scaling Policy Anticipating and securing against emerging threats that accompany increasingly powerful models
Vendor publishedAnthropic’s Transparency Hub \ Anthropicretrieved Aug 28, 2026
Anthropic’s Transparency Hub A look at Anthropic's key processes, programs, and practices for responsible AI development.
Vendor publishedModel system cards \ Anthropicretrieved Aug 28, 2026
System cards document the capabilities, safety evaluations, and responsible deployment decisions for Claude models.
Externally corroboratedAnthropic’s Transparency Hub \ Anthropicretrieved Aug 28, 2026
The IPI benchmark was built in partnership with Gray Swan, the UK AI Security Institute, the US Center for AI Standards and Innovation, and other model developers.
Contractual data commitments are explicitStrong

No training on Customer Content, customer ownership of inputs/outputs, deletion with narrow named exceptions, and no sale/sharing.

The two questions buyers open with are answered in the terms, not marketing.

Evidence
Vendor publishedCommercial Terms of Service \ Anthropicretrieved Aug 28, 2026
Anthropic may not train models on Customer Content from Services.
Vendor publishedCommercial Terms of Service \ Anthropicretrieved Aug 28, 2026
retains all rights to its Inputs, and (b) owns its Outputs.
Vendor publishedData Processing Addendum \ Anthropicretrieved Aug 28, 2026
retention of the Customer Data by Anthropic is necessary to resolve a dispute between the parties, or (iii) retention of the Customer Data is necessary to combat harmful use of the Services.
Vendor publishedData Processing Addendum \ Anthropicretrieved Aug 28, 2026
retain, use, or disclose Customer Personal Data outside of the direct business relationship and for any purpose other than for the business purposes specified in Part B of Schedule 1
!Public subprocessor register not found in collected sourcesGap

The DPA defines subprocessor obligations but the register itself (names, locations) was not among the public pages collected.

Buyers need the named list to assess onward transfers; it may sit behind the trust portal.

Question for vendor: Provide the current subprocessor list and change-notification mechanism.

Evidence
Vendor publishedData Processing Addendum \ Anthropicretrieved Aug 28, 2026
means an entity engaged by Anthropic to process Customer Personal Data.
!Security programme is ISO-aligned, with certifications verifiable via registryGap

The RSP describes an ISO 27001-aligned programme; certification evidence itself lives in registries and the trust portal rather than the collected pages.

Alignment language and certification are different strengths; the registry-verified entries on this report carry the latter.

Evidence
Vendor publishedAnthropic’s Responsible Scaling Policy \ Anthropicretrieved Aug 28, 2026
Risk Council sponsored by executive leadership to oversee security programs. Follow a risk-based approach aligned with ISO 27001 standard.
!Declared Google, technically observed AnthropicGap

The vendor's own materials name Google as the model provider, but DNS, certificate, or HTTP evidence points to Anthropic in that role instead.

A supply-chain claim that doesn't match what is technically observable is a disclosure question worth raising directly, not assuming either side is wrong.

Question for vendor: Can you confirm whether Google or Anthropic is the actual model provider?

Evidence
Externally corroboratedAnthropic’s Transparency Hub \ Anthropicretrieved Aug 28, 2026
The IPI benchmark was built in partnership with Gray Swan, the UK AI Security Institute, the US Center for AI Standards and Innovation, and other model developers.
!Declared Microsoft Azure, technically observed AWSGap

The vendor's own materials name Microsoft Azure as the platform provider, but DNS, certificate, or HTTP evidence points to AWS in that role instead.

A supply-chain claim that doesn't match what is technically observable is a disclosure question worth raising directly, not assuming either side is wrong.

Question for vendor: Can you confirm whether Microsoft Azure or AWS is the actual platform provider?

Evidence
Externally corroboratedAnthropic’s Transparency Hub \ Anthropicretrieved Aug 28, 2026
The IPI benchmark was built in partnership with Gray Swan, the UK AI Security Institute, the US Center for AI Standards and Innovation, and other model developers.
?Technical dependency observed: StripeObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedData Processing Addendum \ Anthropicretrieved Aug 28, 2026
means an entity engaged by Anthropic to process Customer Personal Data.
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedData Processing Addendum \ Anthropicretrieved Aug 28, 2026
means an entity engaged by Anthropic to process Customer Personal Data.
?Technical dependency observed: AtlassianObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedData Processing Addendum \ Anthropicretrieved Aug 28, 2026
means an entity engaged by Anthropic to process Customer Personal Data.

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score80
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
Vendor publishedAnthropic’s Responsible Scaling Policy \ Anthropicretrieved Aug 28, 2026
Anthropic’s Responsible Scaling Policy Anticipating and securing against emerging threats that accompany increasingly powerful models
Vendor publishedAnthropic’s Responsible Scaling Policy \ Anthropicretrieved Aug 28, 2026
Risk Council sponsored by executive leadership to oversee security programs. Follow a risk-based approach aligned with ISO 27001 standard.
Vendor publishedAnthropic’s Transparency Hub \ Anthropicretrieved Aug 28, 2026
Anthropic’s Transparency Hub A look at Anthropic's key processes, programs, and practices for responsible AI development.

Governance & accountability: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

AI system15% of the score65
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
Vendor publishedClauderetrieved Aug 28, 2026
Claude is an artificial intelligence, trained by Anthropic using Constitutional AI to be safe, accurate, and secure — the trusted assistant for you to do your best work.
Vendor publishedAnthropic’s Transparency Hub \ Anthropicretrieved Aug 28, 2026
Anthropic’s Transparency Hub A look at Anthropic's key processes, programs, and practices for responsible AI development.
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Covered
Evidence — Testing & evaluation
Vendor publishedAnthropic’s Responsible Scaling Policy \ Anthropicretrieved Aug 28, 2026
Partner with a diverse range of external red team and penetration testing experts. Simulate sophisticated attacks, including insider threat and software supply chain compromise scenarios, to identify vulnerabilities.
Vendor publishedModel system cards \ Anthropicretrieved Aug 28, 2026
System cards document the capabilities, safety evaluations, and responsible deployment decisions for Claude models.
Externally corroboratedAnthropic’s Transparency Hub \ Anthropicretrieved Aug 28, 2026
The IPI benchmark was built in partnership with Gray Swan, the UK AI Security Institute, the US Center for AI Standards and Innovation, and other model developers.
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Partial
Evidence — Change management
Vendor publishedClaude Platform release notes - Claude Platform Docsretrieved Aug 28, 2026
The Claude Platform release notes list changes to the Claude API, the client SDKs, and the Claude Console, newest first.
Vendor publishedClaude Platform release notes - Claude Platform Docsretrieved Aug 28, 2026
Claude Fable 5 requires 30-day data retention and is not available under zero data retention.

AI system description: vendor-evidenced, not yet independently corroborated.

Change management: vendor-evidenced, not yet independently corroborated.

Model10% of the score60
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Partial
Evidence — Model & provider transparency
Vendor publishedModel system cards \ Anthropicretrieved Aug 28, 2026
System cards document the capabilities, safety evaluations, and responsible deployment decisions for Claude models.
Vendor publishedClaude Platform release notes - Claude Platform Docsretrieved Aug 28, 2026
Claude Fable 5 requires 30-day data retention and is not available under zero data retention.

Model provider transparency: vendor-evidenced, not yet independently corroborated.

Customer data15% of the score60
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Vendor publishedCommercial Terms of Service \ Anthropicretrieved Aug 28, 2026
Anthropic may not train models on Customer Content from Services.
Vendor publishedCommercial Terms of Service \ Anthropicretrieved Aug 28, 2026
retains all rights to its Inputs, and (b) owns its Outputs.
Vendor publishedData Processing Addendum \ Anthropicretrieved Aug 28, 2026
retention of the Customer Data by Anthropic is necessary to resolve a dispute between the parties, or (iii) retention of the Customer Data is necessary to combat harmful use of the Services.
Vendor publishedData Processing Addendum \ Anthropicretrieved Aug 28, 2026
retain, use, or disclose Customer Personal Data outside of the direct business relationship and for any purpose other than for the business purposes specified in Part B of Schedule 1
Vendor publishedPrivacy Policy \ Anthropicretrieved Aug 28, 2026
delete individual conversations , which will be removed immediately from your conversation history and automatically deleted from our back-end within 30 days.
Vendor publishedClaude Platform release notes - Claude Platform Docsretrieved Aug 28, 2026
Claude Fable 5 requires 30-day data retention and is not available under zero data retention.

Customer data treatment: vendor-evidenced, not yet independently corroborated.

AI supply chain10% of the score40
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Partial
Evidence — Subprocessors & supply chain
Vendor publishedData Processing Addendum \ Anthropicretrieved Aug 28, 2026
means an entity engaged by Anthropic to process Customer Personal Data.
Security foundation15% of the score85
Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Evidence — Vulnerability & incident handling
Vendor publishedAnthropic’s Responsible Scaling Policy \ Anthropicretrieved Aug 28, 2026
Conduct consistent scanning of all third-party dependencies and maintain a comprehensive vulnerability data repository.
Vendor publishedAnthropic’s Responsible Scaling Policy \ Anthropicretrieved Aug 28, 2026
incident response protocol, bug bounty program, and internal and external red-teaming efforts.
Vendor publishedanthropic.comretrieved Aug 28, 2026
Contact: https://hackerone.com/4f1f16ba-10d3-4d09-9ecc-c721aad90f24/embedded_submissions/new Expires: 2026-12-31T23:59:00.000Z Preferred-Languages: en Canonical: https://anthropic.com/.well-known/security.txt Policy: https://www.anthropic.com/responsible-disclosure-policy
Coordinated vulnerability disclosure for Claude-discovered vulnerabilities Last updated Mar 6, 2026 Purpose Statement: Anthropic is building AI tools that find software vulnerabilities faster and cheaper and we are working towards a clear framework for handling identified vulnerabilities,

Vulnerability & incident handling: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

Independent assurance evidence10% of the score100
Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Partial
Evidence — Independent assurance
Vendor publishedAnthropic’s Responsible Scaling Policy \ Anthropicretrieved Aug 28, 2026
Risk Council sponsored by executive leadership to oversee security programs. Follow a risk-based approach aligned with ISO 27001 standard.
Registry verifiedCSA STAR Registry record — CSA STAR Level 2retrieved Aug 24, 2026

Read from the registry record above — cited, not reproduced.

Registry verifiedIAF CertSearch record — ISO/IEC 42001retrieved Aug 24, 2026

Read from the registry record above — cited, not reproduced.

Registry verifiedIAF CertSearch record — ISO/IEC 27001retrieved Aug 24, 2026

Read from the registry record above — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Legal & contractual10% of the score60
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Vendor publishedData Processing Addendum \ Anthropicretrieved Aug 28, 2026
The parties agree that, to the extent required by Applicable Data Protection Laws, the terms of the SCCs Module Two (controller to processor)
Vendor publishedCommercial Terms of Service \ Anthropicretrieved Aug 28, 2026
our policy on the countries and regions Anthropic currently supports (“ Supported Regions Policy ”) and (c) our Service Specific Terms
Vendor publishedCommercial Terms of Service \ Anthropicretrieved Aug 28, 2026
Anthropic may not train models on Customer Content from Services.

Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+2Have Customer data treatment disclosures independently corroboratedData 6075
+2Have Governance & accountability disclosures independently corroboratedOrganisation 8095
+2Have Vulnerability & incident handling disclosures independently corroboratedSecurity Foundation 85100
+2Complete the Subprocessors & supply chain disclosureSupply Chain 4060
+1Have Legal & contractual transparency disclosures independently corroboratedLegal Contractual 6075

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 70 → up to 83 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESINFRASTRUCTUREAnthropicAnthropicClaudeClaudeGoogle Cloud PlatformGoogle Cloud PlatformMicrosoft AzureMicrosoft Azure
View as list
Claude Uses Infrastructure Google Cloud Platform
Claude Uses Infrastructure Microsoft Azure

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 4 — registry checks and verification ladders, click to view
ISO/IEC 27001Claimed & corroborated

RSP describes an ISO 27001-ALIGNED programme; the certification itself is registry-verifiable.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Currentuntil Jan 6, 2028

Checked against ISO/IEC 27001:2022 certificate held by TrustyCyber (supplied by Anthropic), Aug 24, 2026: Verified on the registry

ISO/IEC 42001Claimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Currentuntil Jan 5, 2028

Checked against ISO/IEC 42001:2023 certificate held by TrustyCyber (supplied by Anthropic), Aug 24, 2026: Verified on the registry

SOC 2Claimed & corroborated

SOC 3 Type 2 (the general-use report of the SOC 2 Type 2 examination): Anthropic's AI Services system, trust services criteria security, availability, confidentiality and privacy; period 1 Oct 2024 - 30 Sep 2025; unqualified opinion signed 12 Nov 2025. Cloud-hosting subservice organisations carved out. Vault: Gated/Anthropic/2025-11_anthropic-ai-services-soc3-type2.pdf.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against SOC 2 Type 2 report held by TrustyCyber (supplied by Anthropic), Aug 24, 2026: Verified on the registry

CSA STAR Level 2Claimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against CSA STAR Registry, Aug 28, 2026: Verified on the registry

Sources 16 — click to view
Anthropic’s Responsible Scaling Policy \ Anthropic
AI Documentation · Vendor · retrieved Aug 28, 2026
https://www.anthropic.com/.well-known/security.txt
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
Data Processing Addendum \ Anthropic
DPA · Vendor · retrieved Aug 28, 2026
Anthropic Trust Center
Subprocessor List · Vendor · retrieved Aug 28, 2026
Privacy Policy \ Anthropic
Privacy Notice · Vendor · retrieved Aug 28, 2026
Anthropic’s Transparency Hub \ Anthropic
Certification Or Compliance Page · Vendor · retrieved Aug 28, 2026
Claude
Product Documentation · Vendor · retrieved Aug 28, 2026
Commercial Terms of Service \ Anthropic
Terms · Vendor · retrieved Aug 28, 2026
Claude Platform release notes - Claude Platform Docs
Changelog Or Release Notes · Vendor · retrieved Aug 28, 2026
How to get support | Anthropic Help Center
Technical Article · Vendor · retrieved Aug 28, 2026
Model system cards \ Anthropic
AI Documentation · Vendor · retrieved Aug 28, 2026
Coordinated vulnerability disclosure for Claude-discovered vulnerabilities \ Anthropic
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
CSA STAR Registry record — CSA STAR Level 2
External Registry Or Certification Evidence · Registry · retrieved Aug 24, 2026
IAF CertSearch record — ISO/IEC 42001
External Registry Or Certification Evidence · Registry · retrieved Aug 24, 2026
IAF CertSearch record — ISO/IEC 27001
External Registry Or Certification Evidence · Registry · retrieved Aug 24, 2026
SOC 3 Type 2 report held in the TrustyCyber vault (Anthropic trust portal) record — SOC 2
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 24, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).

Want to go further?

This scan assesses Anthropic at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.

Scan a specific product →

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.