ModelCharter

Is Claude ISO 27001 certified?

Yes

Anthropic · AI assistants

Yes. Anthropic is ISO/IEC 27001 certified for Claude, the international information-security management standard.

What we checked

This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.

ISO/IEC 27001
Confirmed
Anthropic reports ISO/IEC 27001 certification. Ask for scope and current certificate dates before treating it as supplier assurance.
SOC 2
Confirmed
Anthropic also reports a SOC 2 attestation, which can complement but does not replace ISO scope evidence.
Default data training
Opt-out required
Since the Aug 2025 consumer terms update, Free/Pro/Max chats and coding sessions are used to train models unless the user opts out, with up to 5-year retention if left on.
Business-tier training
No by default
Claude for Work (Team/Enterprise), Claude for Education, Claude Gov, and the API run under Commercial Terms and are not used for model training.
Practical risk: Even when a consumer opts out of training, conversations flagged for safety review can still be retained up to two years and used to improve models without notifying the user.

How to make a decision

Check the precise account tier, written contract and intended data before approving Claude. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.

More on Claude

See the full Claude risk profile, with every data-handling fact and its source, or browse all rated AI tools.