is Claude AI safe for enterprise dataClaude SOC 2Claude HIPAAAnthropic BAAAnthropic Business Associate AgreementClaude zero data retentiondoes Anthropic train on my dataClaude enterprise securityClaude data retentionISO 42001 AnthropicClaude Code HIPAACowork BAAmonday.com Claude connectormonday MCP security

Is Claude AI safe for enterprise data? SOC 2, HIPAA and what the BAA actually covers

Anthropic’s Privacy Center lists ISO 27001:2022, ISO/IEC 42001:2023, and SOC 2 Type I and Type II, and says these apply to its commercial products, including Claude for Work and the Anthropic API. It also offers a HIPAA-ready configuration with a BAA.

Is Claude AI safe for enterprise data? SOC 2, HIPAA and what the BAA actually covers
Peter Marroquin
Peter Marroquin

Implementation Support Consultant

August 24, 2026 · 11 min read

Helps business teams design, deploy, and govern monday.com systems and the AI that runs on top of them — from native AI agents and Sidekick to Claude agents connected through MCP.

By default, Anthropic does not use commercial customer inputs or outputs to train its models. Coverage is not uniform, though. Anthropic says Cowork is not an Eligible Service under the BAA in any configuration, and Claude Code is covered only with zero data retention enabled, on qualified accounts.

If someone has asked you to put in writing whether company data can go through Claude, you are in a good position to answer well. Anthropic publishes the detail itself, across its Privacy Center, its Help Center and its platform documentation.

Coverage varies by product, by access method and by retention setting, so a sentence that is true of one combination can be false of another.

What certifications does Anthropic actually hold?

Anthropic’s Privacy Center lists ISO 27001:2022 for information security management, ISO/IEC 42001:2023 for AI management systems, and SOC 2 Type I and Type II, says these apply to, in its words, “our commercial products such as Claude for Work and the Anthropic API.”

Anthropic’s certifications: ISO 27001:2022 for information security management, ISO/IEC 42001:2023 for AI management systems, and SOC 2 Type I and II, applying to commercial products such as Claude for Work and the Anthropic API

ISO 42001 certifies a management system, not a model. Anthropic announced accredited certification under ISO/IEC 42001:2023 on 13 January 2025, issued by Schellman Compliance, LLC and accredited by the ANSI National Accreditation Board. What was audited is Anthropic’s policies, processes, testing and monitoring, not any Claude output.

Does Anthropic train its models on your data?

By default, no. Anthropic’s wording is that it “will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models.” Its platform documentation adds that retained data “is never used for model training without your express permission.”

There are two documented carve-outs, both needing you to act. Feedback and bug reports you explicitly submit can be used for training. So can Claude Code sessions, if your organisation opts into the Development Partner Program, an admin-level opt-in that accounts on a zero data retention agreement cannot use. Data provided under it is stored for up to 2 years.

By default Anthropic does not use commercial inputs or outputs to train its models — the two carve-outs are explicitly submitted feedback and the Development Partner Program opt-in

Flagged content is a separate matter. It is a retention rule rather than a training rule, and it is covered in the next section.

How long is your data kept, and who can read it ?

For Claude API users, Anthropic says it automatically deletes inputs and outputs on its backend within 30 days. Deleted chats leave your chat history immediately and are deleted from backend storage within 30 days.

Then the exception. Where content is flagged by Anthropic’s automated trust and safety systems, it may retain inputs and outputs for up to 2 years, and classification scores for up to 7 years.

Claude data retention timeline: API inputs and outputs deleted within 30 days, content flagged by trust and safety systems kept up to 2 years, classification scores up to 7 years

On the Enterprise plan a Primary Owner or Owner sets the retention period, in Organization settings under Data and Privacy. The minimum is 30 days, and Anthropic says data past its retention period is permanently deleted and cannot be recovered. If your own policy requires deletion inside a week, this setting will not reach it.

On encryption, Anthropic’s Claude Code documentation says prompts and outputs are encrypted in transit via TLS 1.2 and above, and that at rest the Anthropic API uses infrastructure-level disk encryption with AES-256. That page separates commercial policies from consumer ones, which is why it is the one to quote here.

Be careful, though, with anything you copy across about who inside Anthropic can read a conversation. Those published commitments sit in a Privacy Center article scoped to the Free, Pro and Max plans, and the commercial collection has no equivalent. Anthropic’s Privacy Policy also says it does not apply to content processed on behalf of customers of its business offerings. For the API, Team or Enterprise, ask for that commitment in writing.

Which Claude products are covered by a HIPAA Business Associate Agreement ?

There are two separate arrangements. On the Claude for Work plans, HIPAA readiness can be enabled on Enterprise only, self-serve and sales-assisted, and Anthropic says Team, Free, Pro and Max cannot enable it. The Claude API has its own HIPAA readiness arrangement, enabled in the Claude Console with Anthropic’s standard BAA or negotiated through your account team. Once on, the configuration is permanent and cannot be disabled by an administrator.

Anthropic publishes which combinations count as Eligible Services under its BAA. An Eligible Service requires both signing the BAA and accessing Claude through a HIPAA-ready or zero data retention configuration.

Which Claude products are covered by a HIPAA BAA: chat on a HIPAA-ready Enterprise plan is covered, Claude Code only with zero data retention on qualified accounts, and Cowork is not an Eligible Service in any configuration

Cowork is out. Anthropic’s wording is that “Cowork isn’t an Eligible Service under the BAA in any configuration”, and its Claude Code documentation adds that Cowork sessions are not covered by zero data retention. Cowork is a general-purpose surface that anyone in the organisation can open, so this belongs in your internal guidance.

Claude Code has two conditions, and they pull against each other. On a HIPAA-ready Enterprise plan, Anthropic says Claude Code is covered under your BAA only where zero data retention is enabled, and only on qualified accounts. Zero data retention, in turn, blocks Covered Models, Anthropic’s designation for models it says represent a substantial step up from prior generations and creates elevated risk if misused, currently Claude Mythos 5 and Claude Fable 5, which it says require 30-day retention. So a team using Claude Code under a BAA works without those models.

Chat needs the configuration switched on. With a HIPAA-ready Claude Enterprise plan, chat is an Eligible Service under the BAA. On the Claude API, Anthropic enforces HIPAA readiness at the organisation level and says to use separate organisations if you also need general-purpose API access. On that same API, a HIPAA-enabled organisation that sends a non-eligible feature gets a 400 error back. Anthropic notes a gap in that guardrail: some client-side tools are accepted rather than blocked, and stay outside HIPAA readiness, so the machine check does not catch everything.

The authoritative per-feature list is the Implementation Guide for HIPAA Entities on the Anthropic Trust Center, and access is by request. Anthropic’s own framing is the line to write down: “Your signed BAA is the official source of truth for which features are covered.”

What does zero data retention actually switch off?

Zero data retention is a Claude API arrangement, enabled per organisation through your account team. Under it, Anthropic does not store customer prompts or responses at rest after the API response is returned.

It does not cover the Claude Console, Claude Managed Agents (beta), the consumer plans, Claude for Excel, third-party integrations, or the Claude Team and Claude Enterprise product interfaces. The one interface exception is Claude Code used through Claude Enterprise with zero data retention enabled.

Zero data retention coverage matrix: Claude API prompts and responses are not stored at rest, while the Claude Console, Managed Agents, consumer plans, Claude for Excel, third-party integrations, and the Team and Enterprise interfaces are not covered

For Claude Code it is not part of the standard Enterprise plan, cannot be enabled from admin settings, and requires separate enablement by Anthropic. Switching it on disables Claude Code on the Web, cloud sessions from the desktop app, Artifacts, feedback submission and Remote Control.

Even with zero data retention or HIPAA arrangements in place, Anthropic says it may retain data where required by law or where content has been flagged by its automated trust and safety systems, for up to 2 years.

What is still your responsibility ?

Claude Code clients store session transcripts locally in plaintext under ~/.claude/projects/ for 30 days by default, adjustable with the cleanupPeriodDays setting. No vendor certificate reaches a plaintext file on a laptop, so device encryption and your own deletion policy do that job.

Zero data retention applies to requests that authenticate into a zero data retention organisation, so a developer signing in with a personal account is not covered. Anthropic publishes the forceLoginMethod and forceLoginOrgUUID managed settings to close that gap.

Connectors take two steps on Team and Enterprise plans. An Owner or Primary Owner enables one for the organisation, and each person still authenticates individually, unless the organisation uses Anthropic’s Enterprise-managed auth, which is in beta and authorises once for everyone. Anthropic says it reviews connectors against its listing criteria, but does not security-audit or manage any MCP server.

Claude enterprise security responsibilities that stay with you: protecting local plaintext transcripts, enforcing organisation login, and governing connectors

Anthropic’s own Claude Code security documentation puts the residual risk plainly: while these protections significantly reduce risk, no system is completely immune to all attacks.

What about connecting Claude to monday.com ?

monday.com publishes a connector for Claude, listed in Anthropic’s connector directory, and says it is built on monday MCP, uses OAuth, and respects existing monday.com permissions, so Claude reaches only the data you already have permission to see. Permission inheritance is not compliance inheritance, though. Data exchanged through the API MCP connector (beta) is not zero data retention eligible and is retained under Anthropic’s standard policy.

Claude monday.com connector: permissions inherit through OAuth but compliance does not — data exchanged through a connector still needs its own compliance review

Frequently asked questions

HIPAA compliance is a property of your organisation, not of a product. Anthropic offers a HIPAA-ready configuration with a Business Associate Agreement, and on the Claude for Work plans it can be enabled on Enterprise only.

Anthropic’s Privacy Center lists SOC 2 Type I and Type II, alongside ISO 27001:2022 and ISO/IEC 42001:2023, and says these apply to its commercial products including Claude for Work and the Anthropic API.

Anthropic points customers to its Trust Center, where its Claude Code security documentation says the SOC 2 Type 2 report and the ISO 27001 certificate can be accessed. Its Privacy Center calls the same destination the Trust Portal and says to go there to request copies.

No. Anthropic says analytics metadata, account emails and seat assignments are still retained, and that flagged content may be retained for up to 2 years even with zero data retention or HIPAA arrangements in place.

For commercial products, Anthropic’s platform documentation says retained data is never used for model training without your express permission. Flagged content is a retention rule for commercial customers, up to 2 years, not a training rule.

Anthropic publishes two inference geo values, global and US, and one workspace geo value, US. Inference geo controls where the model runs and workspace geo controls where data is stored at rest. No other specific geography is published today.

Anthropic says that on Amazon Bedrock and Google Cloud’s Agent Platform the cloud provider is the data processor, so those platforms’ own retention and compliance documentation applies. On the Claude API, Anthropic says it is the processor.

Where to go from here

If you are writing this up for a reviewer, three habits beat any summary. Read the Data Processing Addendum, which Anthropic says is automatically incorporated into its Commercial Terms of Service, and check what it commits to on security-breach notification. Anthropic’s Commercial Terms of Service carry no breach-notification clause of their own, so the commitment is in the Addendum. Do not accept a timeframe from a summary. Read the subprocessor list Anthropic publishes on its Trust Center. And treat your signed BAA as the source of truth.

If you run one Enterprise organisation, chat only, with retention configured and no PHI in scope, you can finish this from the pages listed below, and we would rather say that than sell you a project. It gets harder when Claude has to reach into the systems your business runs on. That is the work we do. Workiflow is a monday.com implementation partner and a member of Anthropic’s Claude Partner Network.

If you would like a second pair of eyes before this goes in front of your reviewer.

Book a call
Sources & verification

Sources: Anthropic Privacy Center, “What Certifications has Anthropic obtained?” (verified August 2026); Anthropic, “Anthropic achieves ISO 42001 certification for responsible AI”, 13 January 2025 (verified August 2026); Anthropic Privacy Center, “Is my data used for model training?” (commercial edition) (verified August 2026); Anthropic Privacy Center, “How do you use personal data in model training?” (commercial) (verified August 2026); Anthropic Privacy Center, Commercial Customers collection index (verified August 2026); Anthropic Privacy Center, “Does Anthropic Act as a Data Processor or Controller?” (verified August 2026); Anthropic Privacy Center, “Who owns and manages the data of my team?” (verified August 2026); Anthropic Privacy Center, “How long do you store my organization’s data?” (verified August 2026); Anthropic Privacy Center, “Configure custom data retention controls for Enterprise plans” (verified August 2026); Anthropic Privacy Center, “How does Anthropic protect the personal data of Claude users?”, scoped to the Free, Pro and Max plans (verified August 2026); Anthropic Privacy Center, “How do I view and sign your Data Processing Addendum (DPA)?” (verified August 2026); Anthropic, “HIPAA-ready Enterprise plans”, Claude Help Center (verified August 2026); Anthropic, “Covered Models under a Business Associate Agreement (BAA)”, Claude Help Center (verified August 2026); Anthropic, “Data retention practices for Covered Models”, Claude Help Center (verified August 2026); Anthropic, “About the Development Partner Program”, Claude Help Center (verified August 2026); Anthropic, “API and data retention”, Claude Platform documentation (verified August 2026); Anthropic, “Data residency”, Claude Platform documentation (verified August 2026); Anthropic, “Zero data retention”, Claude Code documentation (verified August 2026); Anthropic, “Data usage”, Claude Code documentation (verified August 2026); Anthropic, “Security”, Claude Code documentation (verified August 2026); Anthropic, “Use connectors to extend Claude’s capabilities”, Claude Help Center (verified August 2026); Anthropic, Claude Enterprise solutions page (verified August 2026); Anthropic, Privacy Policy, effective 8 July 2026 (verified August 2026); Anthropic, Commercial Terms of Service, effective 17 June 2025 (verified August 2026); Anthropic, Claude connector directory, Monday connector (verified August 2026); monday.com, “monday.com introduces new connector for Anthropic’s Claude” (verified August 2026); monday.com, monday MCP product page (verified August 2026). Anthropic’s Privacy Center is served from privacy.claude.com and its Claude Code documentation from code.claude.com; the certifications article is article 10015870. Note: Anthropic’s Enterprise marketing page prints a shorter certification list that omits ISO 42001 and does not distinguish SOC 2 Type I from Type II, and the Privacy Center is the more precise source used here. Note also that Anthropic’s Privacy Center publishes separate commercial and consumer editions of several articles under the same title, and only commercial-scoped articles are relied on above, except where a statement is expressly labelled as consumer-scoped. Product surfaces, feature eligibility and retention settings move with Anthropic’s monthly releases, so every product-level statement above is verified as of August 2026.