Will Claude pass our IT security review?
Usually yes, but which plan you buy decides most of the answer. Anthropic's trust center shows SOC 2 Type 2, ISO 27001, ISO 42001, CSA STAR, and NIST 800-171 coverage for both Claude Team and Claude Enterprise, with HIPAA coverage on Enterprise and the API but not on Team, and the underlying reports sit behind an access request form. Single sign-on is available on Team and Enterprise, but SCIM directory provisioning, audit logs, the Compliance API, custom roles, and custom data retention controls are Enterprise only, so a reviewer who requires automated deprovisioning and an audit trail is effectively requiring Enterprise. The gap most reviews miss: Anthropic states that data is stored in the United States and its platform docs list US as the only available storage region, so a non-US data residency requirement is a real blocker rather than a setting.
The plan you buy decides most of the review
Most Claude security reviews stall for a boring reason. The COO buys Team seats because the price is predictable, IT then asks for automated deprovisioning and an audit trail, and those two controls are not on Team at any price. Sorting that out before the review starts saves a month.
Here is what Anthropic's own plan comparison shows on the Team versus Enterprise table, verified against the live pricing page. Single sign-on, domain verification, restrict organization creation, central billing, admin controls for connectors, usage analytics, and organization-wide skills deployment are all available on Team. The controls a security reviewer usually treats as mandatory are not.
Two labeling quirks on that page are worth knowing before you quote it to IT. The consumer comparison table lists a single combined row called Single sign-on (SSO) and domain capture, while the business table splits them into separate rows where SSO is available on Team and domain capture is not. And the row labeled Role-based access shows as unavailable on Team, which reads as though Team has no roles at all. It does: Anthropic's provisioning guide documents Owner, Admin, and User roles on Team plans. What Enterprise adds is custom roles with granular capability, connector, model, and admin permissions.
- Available on Team and Enterprise: single sign-on, domain verification, restrict organization creation, just-in-time provisioning, central billing, connector admin controls, usage analytics, organization instructions
- Enterprise only: SCIM directory sync, audit logs, Compliance API, custom roles and role-based permissions, custom data retention controls, domain capture, HIPAA-ready offering, session length controls
- Enterprise only and easy to miss: migrating existing accounts on your domains into the organization, which is how you pull staff out of personal Pro logins
- Neither plan gives you a native multi-factor policy inside Claude. The documented path to MFA and conditional access is to require SSO and enforce those policies in your identity provider
Single sign-on and directory provisioning, and the traps in setup
Anthropic's setup guide states plainly that single sign-on is available for Team plans, Enterprise plans, and Console organizations. You need to be an Owner or Primary Owner in Claude, or an Admin in Console, plus control of DNS for your email domain and admin access to your identity provider. Anthropic uses WorkOS as the subprocessor for domain verification and SSO, and WorkOS is listed on the trust center subprocessor page as a United States provider covering Claude for Work and the Claude Developer Platform. Your reviewer will ask about that, so name it before they find it.
Domain verification is a TXT record at the root of your domain whose value begins with anthropic-domain-verification-. Verifying a domain does not by itself change anyone's access. Access changes only when you set up SSO and turn on Require SSO. One structural limit matters for organizations that grew by acquisition: you can verify multiple domains in one organization, but all of them must be managed through a single identity provider. Anthropic does not support verifying domains from separate providers inside the same organization.
The control that quietly does the most work for a mid-market operator is Restrict organization creation, which appears under Security once a domain is verified. Turning it on prevents people from creating new Claude or Console organizations, including personal accounts, using your verified domains. That is your answer to the shadow-IT question, and it is available on Team.
Provisioning has three modes. Invite only is the default. Just-in-time provisioning creates the account on first login and is available on all plans. SCIM directory sync provisions and deprovisions without the user logging in first, and Anthropic states it is available for Enterprise plans and Console organizations only, not for Team plans. If your reviewer's requirement is that access disappears when HR terminates someone, that requirement is a requirement for Enterprise.
Four documented failure modes are worth putting in your rollout plan rather than discovering live. First, if you save group mappings before every user is assigned to the right group in your identity provider, those users get deprovisioned; where it is available the admin console shows a preview of how many members a sync will remove, and you should read it. Second, only the single Primary Owner is exempt from SCIM reconciliation. Owner and Admin accounts are not exempt and will be removed if they are not in a group mapped to a role. Set your intended Primary Owner before you enable SCIM. Third, Microsoft Entra only pushes SCIM changes about every 40 minutes, so deprovisioning is not instant. Fourth, identity-provider-initiated login is not supported for Console organizations that share SSO settings with a Team or Enterprise organization.
Audit logging and administrative visibility
Anthropic's audit log article opens by saying audit logs are available for Enterprise organizations only. Owners and Primary Owners export them from Organization settings, Data and Privacy, using Export logs. The export aggregates the organization's audit logs for the past 180 days and emails a download link that stays active for 24 hours.
Read the exclusions carefully, because a reviewer who assumes audit logs contain conversation content will be disappointed. Titles and contents of chats and projects are not exported in audit logs; only their unique identifiers are. Chat inputs and outputs come from a separate Primary Owner data export. If your organization uses customer-managed encryption keys on Enterprise, the Export logs button does not work at all, and Anthropic directs you to the Compliance API instead.
The log fields themselves are reasonable for an access review. Each entry carries created_at, actor information, event type, event and entity details, plus ip_address, device_id, user_agent, and client_platform where available. Recorded events include SSO sign-ins, magic link requests and verification attempts, SSO connection activation and deletion, SSO enforcement toggles, JIT toggles, domain verification, invites sent, accepted, rejected and deleted, user deletion, project and conversation create, rename, delete, project visibility changes, file uploads, and organization data export start and completion. Retention setting changes and deletion events are tracked there too.
The Compliance API is the answer for anything continuous. Anthropic describes it as generally available to Claude Enterprise plans, excluding public sector organizations, and to Claude Platform customers in Claude chats, and says it pulls activity feed events, chat data, and file content, and now includes audit log events. Coverage of Cowork and Claude Code is in beta for Enterprise customers and does not include Claude Code on web, Claude Code accessed through the Claude Platform, or sessions run on Amazon Bedrock or Google Vertex AI. Third-party security platforms have built integrations on top of it, which is the practical route into an existing SIEM.
Two more visibility controls belong in the packet. Session length controls let Enterprise Admins and Owners cap sessions at 1, 7, 14, or 28 days, with 1, 3, or 7 days available for Console; when a user belongs to organizations with different settings, the shortest applies because a single session spans their organizations. And on Enterprise, custom roles carry a Can view permission tier across Identity and Access, Billing, Analytics, Privacy, User Management, and Libraries, which is exactly what you give a compliance reviewer or internal auditor who needs to see the configuration without changing it.
- Ask for in writing, because Anthropic does not publish it: how long audit log data is retained behind the 180 day export window, and how far back the Compliance API reaches
- Flag in your own design review: connector permissions are additive across custom roles, so blocking a connector in one role does nothing for a member who holds another role that allows it, and the most permissive grant wins
- Flag as a privilege escalation path: a custom role with Identity and Access set to Manage can edit group and role definitions including its own, so members with it can widen their own access
- Remember the ceiling rule: a capability switched off at the organization level cannot be granted back by any custom role, and members on a Custom role do not inherit organization-enabled capabilities automatically
The compliance reports Anthropic publishes, and how to request them
Anthropic runs a trust center at trust.anthropic.com with a per-product certification matrix, a document library, and a request access button. Completing the access request form is what opens the sensitive documents, and it also enables the trust center's AI feature so you can query the documentation directly. Plan for that request to take a few days and start it before your review meeting, not after.
The scope matrix is the single most useful artifact on the page, because coverage is per product rather than company-wide. As verified on the live trust center, Claude via Anthropic's API, Claude Enterprise, and Claude in Microsoft Foundry hosted on Anthropic each show SOC 2 Type 2, ISO 27001, ISO 42001, CSA STAR, HIPAA, and NIST 800-171. Claude Team shows SOC 2 Type 2, ISO 27001, ISO 42001, CSA STAR, and NIST 800-171, and shows HIPAA as not applicable. Claude in Amazon Bedrock and Claude on Google Cloud Vertex AI show SOC 2 Type 2, ISO 27001, ISO 42001, and CSA STAR with HIPAA marked partner-managed, and the page footnotes that this applies only to the model itself and containers Anthropic supplies to partners, not the partner hosting environment. Claude in Microsoft Foundry hosted on Azure shows in-process for Q4 2026. FedRAMP High and Defense Department impact levels attach to the government offerings, not to Claude Enterprise.
One certification deserves explanation because most reviewers have not seen it. ISO/IEC 42001:2023 is the management system standard for artificial intelligence, the AI equivalent of what ISO 27001 does for information security. If your reviewer has an AI governance checklist, that certificate plus the model documentation forms and training data summaries on the trust center is the strongest thing you can hand them.
The document library carried the following at the time of writing, and the specific report years matter when your reviewer asks whether the attestation is current: a 2025 Type 2 SOC 2 and CSA STAR Level 2 report, a 2025 Type 2 SOC 3 report, ISO 27001 and ISO 42001 certificates dated 2025, an ISO statement of applicability, 2025 Type 1 HIPAA reports, a HIPAA-ready offering implementation guide, a 2026 NIST 800-171r3 attestation letter, 2025 annual penetration testing reports, an infrastructure diagram, a data processing addendum, and completed standard questionnaires including SIG Lite, CAIQ Full, VSA Core, and HECVAT, all dated June 2026. If your procurement team was going to send Anthropic its own 300-line questionnaire, send them the CAIQ or SIG first and see how much of it is already answered.
Two practical notes. The subprocessor list is public and worth reading before your reviewer does, because it includes user-support providers based in South Africa and Canada and lists the three cloud infrastructure providers as worldwide, which is the kind of detail a reviewer would rather hear from you. And the trust center has an updates feed you can subscribe to, which is the mechanism Anthropic uses to announce subprocessor changes; put a named person on that subscription as part of your vendor management process.
Data residency and retention, exactly as published
Be straight with your reviewer here, because this is the area where wishful reading causes the most damage. Anthropic's privacy article on server location says that by default it may route customer traffic to select countries in the US, Europe, Asia, and Australia unless otherwise agreed or at your instruction, and then says data is stored in the US. Anthropic may also process data in countries where it or its affiliates operate for internal processes such as safety review, product support, or incident response.
There are real inference-location controls, and they are narrower than they sound. On usage-based Enterprise plans, a US-only inference toggle under Organization settings, Data and privacy keeps model processing inside the United States across the Claude apps including background work like conversation titles and memory, billed at 1.1x standard rates for Claude Opus 4.6, Sonnet 4.6, and later models. Anthropic states directly that this setting does not control connectors and third-party services, which process data on their own infrastructure, and does not control data storage. The toggle does not appear on Team plans or legacy seat-based Enterprise plans. On the API there are two independent settings: inference_geo per request or as a workspace default, and workspace geo, which governs storage at rest. The platform documentation says workspace geo is set at workspace creation, cannot be changed afterward, and that US is currently the only available value.
So the honest answer to a European data residency requirement is that Anthropic publishes inference controls, not a non-US storage region. If your reviewer's control is data at rest inside the EU, that is a blocker to raise now, and the conversation to have is about consuming Claude through a cloud provider under that provider's own regional paperwork instead.
Retention has three layers, and the default surprises people. For the API, Anthropic automatically deletes inputs and outputs on its backend within 30 days of receipt or generation, with exceptions for services with longer retention under your control, agreed zero data retention, usage policy enforcement, and legal requirements. For the chat products, conversations are retained in the product so users can continue them; a deleted conversation leaves chat history immediately and is deleted from backend storage within 30 days, and incognito chats are deleted within 30 days unless flagged. Chats flagged as usage policy violations are retained up to 2 years, with trust and safety classification scores kept up to 7 years, and feedback you submit is retained for 5 years.
The layer to underline: Anthropic's Enterprise retention article states that by default data is retained indefinitely unless a custom retention period is set. Custom retention controls are Enterprise only, need Owner or Primary Owner, have a 30 day minimum, count a month as 30 days, run from last activity, and delete at midnight UTC. Changing the setting deletes anything already outside the new window immediately and permanently on save. Project retention supersedes chat retention. If your record-retention policy says client work product is destroyed after a defined period, this setting is the control that satisfies it, and nobody sets it by accident.
One more thing that no vendor summary mentions and that a sharp reviewer will eventually find. Anthropic requires 30 day retention and review of prompts and outputs for what it calls covered models, on every platform where those models are offered, effective June 9, 2026. This changes nothing for organizations on standard retention, but organizations running zero data retention in Claude Console, Claude Code with ZDR on Enterprise, or Claude through Bedrock, Google Cloud, or Microsoft Foundry with ZDR must enable retention to use those models. Anthropic describes the safeguards: no personnel can read retained conversations by default, human review happens only through a controlled path for content flagged by automated systems, reviewers are a small approved set, every access is written to a tamper-proof log reviewers cannot suppress, and eligible organizations can add customer-managed encryption keys and access transparency audit logs. Tell your reviewer this before they read it themselves.
The training question has a control attached that almost nobody configures. Anthropic states that by default it will not use inputs or outputs from its commercial products, including Claude for Work and the API, to train its models. The exception is feedback: if someone uses the thumbs up or thumbs down button, Anthropic stores the entire related conversation, including content, custom styles, conversation preferences, and model settings, for up to 5 years, and may use it to train models after de-linking it from user and customer IDs. A Primary Owner or Owner on either Team or Enterprise can turn that off with the Rate chats setting under Organization settings, Data and Privacy. If your policy says client data never enters a training corpus, that toggle is the thing that makes the sentence true.
The packet: what your reviewer will ask and where each answer lives
Assemble this once and the review takes one meeting instead of four. The pattern that works is a single document that answers each question in one or two sentences and links to the Anthropic-owned page it came from, with the requested trust center documents attached. Reviewers reject vendor marketing summaries and accept primary sources.
Where Anthropic does not publish something, say so in the packet and put it on the list of contract questions rather than leaving a blank. In our experience the unpublished items are audit log retention behind the export window, Compliance API historical depth, uptime and support commitments for your specific plan, and whether your particular combination of connectors is in scope for anything you have signed. Those are account team questions, and asking them in writing early is what separates a rollout that clears review from one that gets paused in week three.
- Do you support SAML SSO, and on which plan? Set up single sign-on (SSO), which names Team, Enterprise, and Console, and lists the supported providers
- Can access be revoked automatically on termination? Set up JIT or SCIM provisioning, which states SCIM is Enterprise and Console only
- Who are your subprocessors and where do they operate? The public subprocessor list on the trust center, plus the updates feed for changes
- Give us your SOC 2 report and ISO certificates. Trust center document library, after completing the request access form
- Do you have an AI-specific certification? The ISO 42001 certificate, plus model documentation forms and training data summaries on the trust center
- Do you train on our data? Anthropic's model training article, which says no by default for commercial products, plus the Rate chats setting that closes the feedback exception
- Where is our data stored and processed? The server location privacy article, the US-only inference article for Enterprise, and the platform data residency docs for the API
- How long is our data kept and can we control it? The organization data retention article plus the Enterprise custom retention controls article, noting the indefinite default
- What is logged and can we get it into our SIEM? Access audit logs for the 180 day export and its exclusions, and Access the Compliance API for continuous pull
- Can we restrict who does what? Set up role-based permissions on Enterprise plans, for capability, connector, model, and admin permission scoping
- Can we force re-authentication? Configuring session security settings, for the 1 to 28 day session caps
- Can staff spin up accounts we do not control? Restrict organization creation, documented in the SSO setup guide, available once your domain is verified
- Do you sign a DPA, and a BAA if we handle health data? Anthropic's published Data Processing Addendum, and the BAA article for the HIPAA-ready services on Enterprise and the API
- Have you been penetration tested? The 2025 annual penetration testing reports in the trust center document library
- Will you complete our security questionnaire? Send their completed CAIQ Full, SIG Lite, VSA Core, or HECVAT first and only ask for the delta
Sources
Policies and product details change. Check the source rather than trusting this page indefinitely.
- Anthropic Trust Center: per-product certification scope matrix, document library, and access request form
- Anthropic Trust Center: public subprocessor list
- Claude plans and pricing: the Team versus Enterprise security and administration comparison
- Anthropic: Set up single sign-on (SSO), including plan availability, domain verification, and restrict organization creation
- Anthropic: Set up JIT or SCIM provisioning, stating SCIM is available for Enterprise and Console only
- Anthropic: Access audit logs, the 180 day export window, log fields, and what is excluded
- Anthropic: Access the Compliance API, and its coverage limits
- Anthropic: Set up role-based permissions on Enterprise plans, including view-only admin permissions
- Anthropic: Configuring session security settings, for maximum session length
- Anthropic: Where are your servers located? Do you host your models on EU servers?
- Anthropic: How long do you store my organization's data?
- Anthropic: Is my data used for model training? Covers the commercial default, the feedback exception, and the Rate chats setting
- Anthropic: Configure custom data retention controls for Enterprise plans, including the indefinite default
- Anthropic: Data retention practices for Covered Models, which requires 30 day retention for ZDR organizations
- Anthropic: Enable US-only inference for your organization, and what it does not cover
- Claude Platform docs: data residency, inference geo and workspace geo, with US as the only workspace geo
- Anthropic: Data Processing Addendum
Need to send this to someone else?
I will email you this answer with every source linked, so it stands up when it lands in front of IT, legal, or finance. Plus the questions that usually come next. Unsubscribe any time.
Want to know what Claude can actually do in your business?
Four questions, about a minute, and Claude writes three automations for your specific situation with the exact prompts. No account.
Build my plan