Is Claude AI safe for enterprise data? SOC 2, HIPAA and what the BAA actually covers
Anthropic’s Privacy Center lists ISO 27001:2022, ISO/IEC 42001:2023, and SOC 2 Type I and Type II, and says these apply to its commercial products, including Claude for Work and the Anthropic API. It also offers a HIPAA-ready configuration with a BAA.


Helps business teams design, deploy, and govern monday.com systems and the AI that runs on top of them — from native AI agents and Sidekick to Claude agents connected through MCP.
By default, Anthropic does not use commercial customer inputs or outputs to train its models. Coverage is not uniform, though. Anthropic says Cowork is not an Eligible Service under the BAA in any configuration, and Claude Code is covered only with zero data retention enabled, on qualified accounts.
If someone has asked you to put in writing whether company data can go through Claude, you are in a good position to answer well. Anthropic publishes the detail itself, across its Privacy Center, its Help Center and its platform documentation.
Coverage varies by product, by access method and by retention setting, so a sentence that is true of one combination can be false of another.
What certifications does Anthropic actually hold?
Anthropic’s Privacy Center lists ISO 27001:2022 for information security management, ISO/IEC 42001:2023 for AI management systems, and SOC 2 Type I and Type II, says these apply to, in its words, “our commercial products such as Claude for Work and the Anthropic API.”

ISO 42001 certifies a management system, not a model. Anthropic announced accredited certification under ISO/IEC 42001:2023 on 13 January 2025, issued by Schellman Compliance, LLC and accredited by the ANSI National Accreditation Board. What was audited is Anthropic’s policies, processes, testing and monitoring, not any Claude output.
Does Anthropic train its models on your data?
By default, no. Anthropic’s wording is that it “will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models.” Its platform documentation adds that retained data “is never used for model training without your express permission.”
There are two documented carve-outs, both needing you to act. Feedback and bug reports you explicitly submit can be used for training. So can Claude Code sessions, if your organisation opts into the Development Partner Program, an admin-level opt-in that accounts on a zero data retention agreement cannot use. Data provided under it is stored for up to 2 years.

Flagged content is a separate matter. It is a retention rule rather than a training rule, and it is covered in the next section.
How long is your data kept, and who can read it ?
For Claude API users, Anthropic says it automatically deletes inputs and outputs on its backend within 30 days. Deleted chats leave your chat history immediately and are deleted from backend storage within 30 days.
Then the exception. Where content is flagged by Anthropic’s automated trust and safety systems, it may retain inputs and outputs for up to 2 years, and classification scores for up to 7 years.

On the Enterprise plan a Primary Owner or Owner sets the retention period, in Organization settings under Data and Privacy. The minimum is 30 days, and Anthropic says data past its retention period is permanently deleted and cannot be recovered. If your own policy requires deletion inside a week, this setting will not reach it.
On encryption, Anthropic’s Claude Code documentation says prompts and outputs are encrypted in transit via TLS 1.2 and above, and that at rest the Anthropic API uses infrastructure-level disk encryption with AES-256. That page separates commercial policies from consumer ones, which is why it is the one to quote here.
Be careful, though, with anything you copy across about who inside Anthropic can read a conversation. Those published commitments sit in a Privacy Center article scoped to the Free, Pro and Max plans, and the commercial collection has no equivalent. Anthropic’s Privacy Policy also says it does not apply to content processed on behalf of customers of its business offerings. For the API, Team or Enterprise, ask for that commitment in writing.
Which Claude products are covered by a HIPAA Business Associate Agreement ?
There are two separate arrangements. On the Claude for Work plans, HIPAA readiness can be enabled on Enterprise only, self-serve and sales-assisted, and Anthropic says Team, Free, Pro and Max cannot enable it. The Claude API has its own HIPAA readiness arrangement, enabled in the Claude Console with Anthropic’s standard BAA or negotiated through your account team. Once on, the configuration is permanent and cannot be disabled by an administrator.
Anthropic publishes which combinations count as Eligible Services under its BAA. An Eligible Service requires both signing the BAA and accessing Claude through a HIPAA-ready or zero data retention configuration.

Cowork is out. Anthropic’s wording is that “Cowork isn’t an Eligible Service under the BAA in any configuration”, and its Claude Code documentation adds that Cowork sessions are not covered by zero data retention. Cowork is a general-purpose surface that anyone in the organisation can open, so this belongs in your internal guidance.
Claude Code has two conditions, and they pull against each other. On a HIPAA-ready Enterprise plan, Anthropic says Claude Code is covered under your BAA only where zero data retention is enabled, and only on qualified accounts. Zero data retention, in turn, blocks Covered Models, Anthropic’s designation for models it says represent a substantial step up from prior generations and creates elevated risk if misused, currently Claude Mythos 5 and Claude Fable 5, which it says require 30-day retention. So a team using Claude Code under a BAA works without those models.
Chat needs the configuration switched on. With a HIPAA-ready Claude Enterprise plan, chat is an Eligible Service under the BAA. On the Claude API, Anthropic enforces HIPAA readiness at the organisation level and says to use separate organisations if you also need general-purpose API access. On that same API, a HIPAA-enabled organisation that sends a non-eligible feature gets a 400 error back. Anthropic notes a gap in that guardrail: some client-side tools are accepted rather than blocked, and stay outside HIPAA readiness, so the machine check does not catch everything.
The authoritative per-feature list is the Implementation Guide for HIPAA Entities on the Anthropic Trust Center, and access is by request. Anthropic’s own framing is the line to write down: “Your signed BAA is the official source of truth for which features are covered.”
What does zero data retention actually switch off?
Zero data retention is a Claude API arrangement, enabled per organisation through your account team. Under it, Anthropic does not store customer prompts or responses at rest after the API response is returned.
It does not cover the Claude Console, Claude Managed Agents (beta), the consumer plans, Claude for Excel, third-party integrations, or the Claude Team and Claude Enterprise product interfaces. The one interface exception is Claude Code used through Claude Enterprise with zero data retention enabled.

For Claude Code it is not part of the standard Enterprise plan, cannot be enabled from admin settings, and requires separate enablement by Anthropic. Switching it on disables Claude Code on the Web, cloud sessions from the desktop app, Artifacts, feedback submission and Remote Control.
Even with zero data retention or HIPAA arrangements in place, Anthropic says it may retain data where required by law or where content has been flagged by its automated trust and safety systems, for up to 2 years.
What is still your responsibility ?
Claude Code clients store session transcripts locally in plaintext under ~/.claude/projects/ for 30 days by default, adjustable with the cleanupPeriodDays setting. No vendor certificate reaches a plaintext file on a laptop, so device encryption and your own deletion policy do that job.
Zero data retention applies to requests that authenticate into a zero data retention organisation, so a developer signing in with a personal account is not covered. Anthropic publishes the forceLoginMethod and forceLoginOrgUUID managed settings to close that gap.
Connectors take two steps on Team and Enterprise plans. An Owner or Primary Owner enables one for the organisation, and each person still authenticates individually, unless the organisation uses Anthropic’s Enterprise-managed auth, which is in beta and authorises once for everyone. Anthropic says it reviews connectors against its listing criteria, but does not security-audit or manage any MCP server.

Anthropic’s own Claude Code security documentation puts the residual risk plainly: while these protections significantly reduce risk, no system is completely immune to all attacks.
What about connecting Claude to monday.com ?
monday.com publishes a connector for Claude, listed in Anthropic’s connector directory, and says it is built on monday MCP, uses OAuth, and respects existing monday.com permissions, so Claude reaches only the data you already have permission to see. Permission inheritance is not compliance inheritance, though. Data exchanged through the API MCP connector (beta) is not zero data retention eligible and is retained under Anthropic’s standard policy.

Frequently asked questions
HIPAA compliance is a property of your organisation, not of a product. Anthropic offers a HIPAA-ready configuration with a Business Associate Agreement, and on the Claude for Work plans it can be enabled on Enterprise only.
Anthropic’s Privacy Center lists SOC 2 Type I and Type II, alongside ISO 27001:2022 and ISO/IEC 42001:2023, and says these apply to its commercial products including Claude for Work and the Anthropic API.
Anthropic points customers to its Trust Center, where its Claude Code security documentation says the SOC 2 Type 2 report and the ISO 27001 certificate can be accessed. Its Privacy Center calls the same destination the Trust Portal and says to go there to request copies.
No. Anthropic says analytics metadata, account emails and seat assignments are still retained, and that flagged content may be retained for up to 2 years even with zero data retention or HIPAA arrangements in place.
For commercial products, Anthropic’s platform documentation says retained data is never used for model training without your express permission. Flagged content is a retention rule for commercial customers, up to 2 years, not a training rule.
Anthropic publishes two inference geo values, global and US, and one workspace geo value, US. Inference geo controls where the model runs and workspace geo controls where data is stored at rest. No other specific geography is published today.
Anthropic says that on Amazon Bedrock and Google Cloud’s Agent Platform the cloud provider is the data processor, so those platforms’ own retention and compliance documentation applies. On the Claude API, Anthropic says it is the processor.
Where to go from here
If you are writing this up for a reviewer, three habits beat any summary. Read the Data Processing Addendum, which Anthropic says is automatically incorporated into its Commercial Terms of Service, and check what it commits to on security-breach notification. Anthropic’s Commercial Terms of Service carry no breach-notification clause of their own, so the commitment is in the Addendum. Do not accept a timeframe from a summary. Read the subprocessor list Anthropic publishes on its Trust Center. And treat your signed BAA as the source of truth.
If you run one Enterprise organisation, chat only, with retention configured and no PHI in scope, you can finish this from the pages listed below, and we would rather say that than sell you a project. It gets harder when Claude has to reach into the systems your business runs on. That is the work we do. Workiflow is a monday.com implementation partner and a member of Anthropic’s Claude Partner Network.