ModelCharter

Is Claude SOC 2 compliant?

Yes

Anthropic · AI assistants

Yes. Anthropic holds a SOC 2 report covering Claude, which gives independent assurance over its security controls.

What we checked

This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.

SOC 2 report
Confirmed
Anthropic reports a SOC 2 attestation. Request the current report and relevant bridge letter during procurement.
ISO 27001
Confirmed
Anthropic also reports ISO/IEC 27001 certification.
Default data training
Opt-out required
Since the Aug 2025 consumer terms update, Free/Pro/Max chats and coding sessions are used to train models unless the user opts out, with up to 5-year retention if left on.
Business-tier training
No by default
Claude for Work (Team/Enterprise), Claude for Education, Claude Gov, and the API run under Commercial Terms and are not used for model training.
Practical risk: Even when a consumer opts out of training, conversations flagged for safety review can still be retained up to two years and used to improve models without notifying the user.

How to make a decision

Check the precise account tier, written contract and intended data before approving Claude. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.

More on Claude

See the full Claude risk profile, with every data-handling fact and its source, or browse all rated AI tools.