VendorScore · AI assistant · Data-access posture
A plain-language answer from Anthropic's Privacy Center, Claude Help Center, platform docs, Commercial Terms and DPA. CMEK gives custody and revocation, not zero access.
Get the full 5-dimension PDF — join the waitlistEvidence dated 2026-10-07, public docs only, not legal advice.
Short answer
Yes, by design (with controls): Anthropic's models process your chats in plaintext and flagged content can get human review; CMEK adds custody and revoke, not zero access.
Scored configuration: Claude Enterprise with customer-managed encryption keys (AWS/GCP/Azure KMS), custom data retention, Compliance API, and feedback ('Rate chats') disabled.
Default setup and Claude Team (no CMEK) score lower: Anthropic-managed keys. CMEK and custom retention are Enterprise-only.
Report confidence: Medium. Anthropic's Trust Center and subprocessor list render only via JavaScript and couldn't be read.
Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.
Commercial inputs and outputs aren't used for training by default; the Commercial Terms say Anthropic may not train models on Customer Content.
Evidence: Is my data used for model training?, Anthropic Commercial TermsCMEK encrypts Enterprise chats, attachments, Claude Code and Cowork with your KMS key; revoking it makes the data permanently inaccessible. US regions only; new data only.
Evidence: Claude CMEK docsAccess Transparency (logs of Anthropic staff access) doesn't cover claude.ai Enterprise seats or Claude for Work.
Evidence: Anthropic Access TransparencyOur report flags these gaps in Claude for Work's public documentation:
Get the full 5-dimension PDF — join the waitlist
PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.
Yes, by design (with controls): Anthropic's models process your chats in plaintext and flagged content can get human review; CMEK adds custody and revoke, not zero access. VendorScore rates Claude for Work 64/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Claude Enterprise with customer-managed encryption keys (AWS/GCP/Azure KMS), custom data retention, Compliance API, and feedback ('Rate chats') disabled.
Yes, for eligible Enterprise organizations. CMEK uses your AWS KMS, Google Cloud KMS or Azure Key Vault key to encrypt chat content, attachments, Claude Code, Cowork and other covered features, and "Every operation Anthropic performs with your key is recorded in your cloud provider's audit logs." Revoking the key makes CMEK data permanently inaccessible. Limits: US regions only, new data only, and account data and audit logs stay on Anthropic-managed keys. Otherwise data is encrypted with at least AES-256 at rest and TLS 1.2+ in transit. Anthropic makes no E2EE claim.
If content is flagged. Anthropic describes human review of content flagged by automated trust-and-safety systems "only by a small set of approved reviewers", with tamper-proof access logging. Flagged chats are kept up to 2 years and classifier scores up to 7 years. Access Transparency logs of Anthropic staff access don't cover claude.ai Enterprise seats or Claude for Work, and public docs don't describe routine employee access outside flagged-content review.
No, not by default. Anthropic says: "By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models." The Commercial Terms add that Anthropic may not train models on Customer Content from Services. If users send thumbs up/down feedback or bug reports, the whole conversation is stored for up to 5 years and may be used for training; Team and Enterprise owners can disable Rate chats.
VendorScore doesn't certify compliance; Anthropic publishes a DPA at https://www.anthropic.com/legal/data-processing-addendum. The DPA promises reasonable notice before a new subprocessor gets access, with a 15-day objection window, and allows customer audits at the customer's expense.
Anthropic says it uses multiple cloud providers to process customer data, as documented in its subprocessor list at https://trust.anthropic.com/subprocessors. That page renders only via JavaScript, so we couldn't read the list content and don't repeat names from third-party copies. Anthropic also says it may process data for safety review, product support or incident response in countries where it or its affiliates operate.
No. Anthropic says "data is stored in the US", and traffic may be routed to the US, Europe, Asia and Australia by default. CMEK is also US-region only.
Every URL cited on this page. Score, key findings and FAQ: VendorScore report (claude.md), evidence dated 2026-10-07.