Every criterion, with Anthropic’s own wording where it is hedged or carries exclusions, the primary source, and the date we last read it.
FLI safety grade
Safety-research posture, per the Future of Life Institute
C+ · 2.66 (Summer 2026)
Highest overall grade in the Index, leading five of six domains. Its Existential Safety domain grade was D+, the highest any company received in that domain.
Primary source · verified 2026-08-04
BAA available
Will they sign a business associate agreement for PHI
Yes
Anthropic: "Anthropic provides a BAA covering our HIPAA-ready services, such as use of our first-party API or Enterprise plans." Coverage is narrower than that sentence suggests. The BAA "only covers the single organization that accepted it, and excludes features such as Workbench, Claude Console, Claude Cowork, or features currently in beta." Batch API, Files API, Computer Use, and Web Fetch are stated as not covered and not accessible to HIPAA-ready API users. Claude Code is covered only with Zero Data Retention enabled. Check feature-level coverage, not vendor-level.
Primary source · verified 2026-08-04
Certifications
Independently audited attestations
SOC 2 Type I & Type II · ISO 27001:2022 · ISO/IEC 42001:2023 · HIPAA-ready configuration
ISO/IEC 42001:2023 is the AI management system standard, still uncommon among frontier developers. Reports are available through the Anthropic Trust Portal.
Primary source · verified 2026-08-04
Trains on your data
Whether your inputs and outputs feed model training
Not by default — Opt-in. Submitting thumbs up/down feedback or explicitly consenting permits training use.
Anthropic: "By default, we will not use your inputs or outputs from our commercial products to train our models." Applies to commercial products; consumer tiers are governed separately.
Primary source · verified 2026-08-04
Retention
How long your data is kept, and where
Feedback data retained up to 5 years before de-linking from user identifiers.
This figure covers feedback data specifically. General API retention and Zero Data Retention terms are documented separately and are not yet verified here.
Primary source · verified 2026-08-04
Subprocessors
Who else processes your data
Twenty named sub-processors with purpose, processing location and — unusually — the specific Claude products each one touches. Updates available by subscription.
The per-product scoping is the distinguishing feature: entries read "All Products except Claude for Government", "Claude Free/Pro/Max" or "Claude for Work" rather than applying blanket. Claude for Government is carved out of every user-support, analytics and fraud-detection sub-processor and runs on Palantir Federal Cloud Service instead. Infrastructure runs on all three major clouds — Google Cloud Platform, Amazon Web Services and Microsoft Azure, each Worldwide. No advance-notice period is published; the Trust Center offers a subscribe-to-updates control rather than a committed notice window, which puts Anthropic alongside OpenAI and Mistral and behind Microsoft and AWS.
Primary source · verified 2026-08-08
EU AI Act
Obligations, and which transfer to you as deployer
Signatory to the EU General-Purpose AI Code of Practice, the voluntary route to demonstrating compliance with the AI Act.
Read from the European Commission's own signatory list rather than from any vendor announcement. The Commission cautions that "Some signatories may not appear immediately, but we are making sure to continuously update the list as signatures are confirmed", so absence from the list is weaker evidence than presence on it.
Primary source · verified 2026-08-07