Skip to main content
TrustEdge AI
Model developer

Anthropic

Frontier model developer. Claude via first-party API, Enterprise plans, and Claude Code.

7 of 7 criteria carry a sourced value ·  Verified August 8, 2026

What this means for a regulated buyer

Our analysis, not Anthropic’s. Every statement here traces to a sourced claim further down the page.

The strongest published assurance posture of any developer tracked here, paired with the narrowest and most explicit BAA scope — which is a sign of candour, not weakness.

Where it is strong

  • Holds ISO/IEC 42001:2023, the AI management system standard, which most frontier developers still do not.
  • Enumerates BAA exclusions at feature level rather than claiming blanket coverage — the exclusions are published, so they can be designed around.
  • Sub-processor list is scoped per product rather than blanket, and Claude for Government is carved out of every user-support, analytics and fraud-detection sub-processor.
  • Highest overall grade in the FLI Summer 2026 Index, leading five of six domains.

What to check or negotiate

  • The BAA "only covers the single organization that accepted it" and excludes Workbench, Console, Cowork and beta features. Batch API, Files API, Computer Use and Web Fetch are stated as not covered. Check feature-level coverage, not vendor-level.
  • Claude Code is covered only with Zero Data Retention enabled — that is a configuration you must verify, not a default.
  • No advance-notice period is published for sub-processor changes; the Trust Center offers subscription rather than a committed window.
  • The published five-year retention figure covers feedback data specifically. General API retention terms are documented separately.

Verdict

Defensible for PHI if you scope the deployment to the covered surface and prove the ZDR configuration. The work is in feature-level scoping, not in getting the agreement.

The full record

Every criterion, with Anthropic’s own wording where it is hedged or carries exclusions, the primary source, and the date we last read it.

FLI safety grade

Safety-research posture, per the Future of Life Institute

C+ · 2.66 (Summer 2026)

Highest overall grade in the Index, leading five of six domains. Its Existential Safety domain grade was D+, the highest any company received in that domain.

Primary source · verified 2026-08-04

BAA available

Will they sign a business associate agreement for PHI

Yes

Anthropic: "Anthropic provides a BAA covering our HIPAA-ready services, such as use of our first-party API or Enterprise plans." Coverage is narrower than that sentence suggests. The BAA "only covers the single organization that accepted it, and excludes features such as Workbench, Claude Console, Claude Cowork, or features currently in beta." Batch API, Files API, Computer Use, and Web Fetch are stated as not covered and not accessible to HIPAA-ready API users. Claude Code is covered only with Zero Data Retention enabled. Check feature-level coverage, not vendor-level.

Primary source · verified 2026-08-04

Certifications

Independently audited attestations

SOC 2 Type I & Type II · ISO 27001:2022 · ISO/IEC 42001:2023 · HIPAA-ready configuration

ISO/IEC 42001:2023 is the AI management system standard, still uncommon among frontier developers. Reports are available through the Anthropic Trust Portal.

Primary source · verified 2026-08-04

Trains on your data

Whether your inputs and outputs feed model training

Not by default — Opt-in. Submitting thumbs up/down feedback or explicitly consenting permits training use.

Anthropic: "By default, we will not use your inputs or outputs from our commercial products to train our models." Applies to commercial products; consumer tiers are governed separately.

Primary source · verified 2026-08-04

Retention

How long your data is kept, and where

Feedback data retained up to 5 years before de-linking from user identifiers.

This figure covers feedback data specifically. General API retention and Zero Data Retention terms are documented separately and are not yet verified here.

Primary source · verified 2026-08-04

Subprocessors

Who else processes your data

Twenty named sub-processors with purpose, processing location and — unusually — the specific Claude products each one touches. Updates available by subscription.

The per-product scoping is the distinguishing feature: entries read "All Products except Claude for Government", "Claude Free/Pro/Max" or "Claude for Work" rather than applying blanket. Claude for Government is carved out of every user-support, analytics and fraud-detection sub-processor and runs on Palantir Federal Cloud Service instead. Infrastructure runs on all three major clouds — Google Cloud Platform, Amazon Web Services and Microsoft Azure, each Worldwide. No advance-notice period is published; the Trust Center offers a subscribe-to-updates control rather than a committed notice window, which puts Anthropic alongside OpenAI and Mistral and behind Microsoft and AWS.

Primary source · verified 2026-08-08

EU AI Act

Obligations, and which transfer to you as deployer

Signatory to the EU General-Purpose AI Code of Practice, the voluntary route to demonstrating compliance with the AI Act.

Read from the European Commission's own signatory list rather than from any vendor announcement. The Commission cautions that "Some signatories may not appear immediately, but we are making sure to continuously update the list as signatures are confirmed", so absence from the list is weaker evidence than presence on it.

Primary source · verified 2026-08-07

This is a model developer, so the FLI grade above describes its safety-research posture. It says nothing about whether a deployment is compliant — that comes from the contractual terms, either this vendor’s own or those of a platform you run the model through.

This developer’s models are also available through Amazon Bedrock, under those platforms’ terms rather than these. Where the direct API cannot meet a requirement, the platform route often can.

Safety grades come from the FLI AI Safety Index, Summer 2026 — what it measures, and what it explicitly does not.

Deploying Anthropic in a regulated environment

We help regulated organisations build AI vendor diligence that holds up in an audit.