AI Chatbots & Assistants

Claude

Medium risk

Anthropic's AI assistant for analysis, writing, and coding, available as a consumer app, Team/Enterprise plans, and an API.

Verified 2026-08-31Anthropicclaude.ai

Is Claude safe for confidential data?

Claude's consumer app asks users to choose whether their chats may be used for model training; where a user accepts, retention is extended. Team and Enterprise plans do not train on customer data by default and add admin controls and a DPA. As with any external chatbot, the residual risk is unmanaged consumer accounts and unredacted confidential detail in prompts — not the enterprise contract.

Risk by plan

The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.

Free / Pro / Max (consumer)
Conditional

User-level training choice presented at signup/settings; retention varies with that choice. No admin controls.

Team
No training

No training on customer data by default; central billing and admin tools.

Enterprise
No training

SSO, domain capture, audit logs, DPA, SOC 2 Type II scope.

Data handling

Training on inputs

Consumer users are prompted to choose whether chats may be used for training; commercial tiers (Team, Enterprise, API) do not train on customer data by default.

Retention

Consumer retention depends on the user's training choice — up to five years where training is accepted, shorter where declined. Deleted chats are removed from the back end within about 30 days and excluded from future training. Enterprise retention is configurable by contract.

Residency

Processed in Anthropic's cloud infrastructure, primarily in the United States. API access through AWS Bedrock or Google Vertex can pin regional processing.

Compliance

  • SOC 2Yes
  • GDPR / DPAYes
  • HIPAA BAAConditional

Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.

New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.

Enterprise controls

  • SSO / SAML (Enterprise)
  • Domain capture and role management
  • Audit logs (Enterprise)
  • Data Processing Addendum
  • No-training default on commercial tiers

Frequently asked questions

Does Claude train on my data?

Commercial tiers (Team, Enterprise, API) do not train on customer data by default. On consumer plans, Anthropic asks each user to choose whether their chats may be used for training, and retention differs based on that choice — so what an individual employee clicked determines your exposure.

Is Claude safe for confidential client data?

On managed Team/Enterprise accounts with a DPA, exposure is contractually limited. On personal consumer accounts your organization has no visibility, no contract, and no control over the training choice — the same shadow-AI problem as any consumer chatbot. Redact identifiers before they reach any prompt.

How do I get visibility into employee Claude usage?

Consumer accounts leave no enterprise audit trail. Detection has to happen where the prompt is written: Sanitized AI identifies AI destinations in the browser, redacts sensitive fields before submission, and reports usage by tool and team.

Policy changelog

  • Initial entry published from Anthropic's published policies.

Sources

This profile summarizes the vendor's published policies as of the verification date. It is not legal advice.

Claude is probably already in your organization.

Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.

Get a demo

More AI tool profiles