SaaSDossier

No. 004 · Licensed Edition

Anthropic — Security Evidence Dossier

Question
What security evidence does Anthropic publish?
Answer
Anthropic publishes a Trust Center for Claude covering SOC 2 Type II, ISO/IEC 27001, ISO/IEC 42001, and selected security/privacy controls. The Licensed Edition records 47 of 55 fields as Documented and surfaces 8 buyer follow-up questions.
47 Documented8 Questions surfacedof 55
Cover of the Anthropic Security Evidence Dossier — Licensed Edition, Dossier No. 004
Edition
Licensed Edition
Reference
Dossier No. 004
Framework
55 fields · 10 domains
Documented
47 of 55
Questions surfaced
8
Evidence date
24 June 2026
Release date
2026-07-02
Vendor pages reviewed
14
Price
US$1,500 — Licensed Edition

Evidence date 2026-06-24. A vendor-published privacy policy update post-dates this snapshot; re-verification is in preparation.

10 domains reviewed

  • Identity & legal entity
  • Standards & attestations
  • Privacy & compliance
  • Encryption & key management
  • Infrastructure & hosting
  • Access control
  • Vulnerability & incident response
  • Subprocessors & supply chain
  • AI governance
  • Secure development & organization

A sample of the evidence ledger

A preview of the discipline — one Documented, one Question surfaced. The full 55-field ledger is in the dossier.

Documented
ISO/IEC 42001:2023
Question surfaced
PCI DSS compliance

What's inside

Evidence ledger

All 55 fields across 10 domains, each recorded in one of two states, with the vendor's own words quoted and cited where Documented.

Source register

Every vendor-published page reviewed, listed with its URL, so each line traces back to where it was found.

Integrity record

Each dossier includes a SHA-256 identifier tied to the reviewed evidence record used for that release.

Buyer-ready vendor follow-up questions

Field-level follow-ups generated from Question surfaced entries, used to help buyers decide what to confirm with the vendor in writing.

Question surfaced means: Reviewed vendor-published sources did not establish the field for the evidence date. This does not establish absence of the control.

Does Anthropic store files or code Claude Code reads, and does opting out of model improvement change that?

Storage, retention and model-improvement use are separate questions. The Anthropic dossier records each separately: what Anthropic documents about retained content, whether customer data is used for model improvement, and how data is handled. Where vendor-published material does not resolve a point, it is shown as a Question surfaced rather than assumed.

How do teams monitor Claude Code at work and meet security and internal oversight requirements?

Endpoint monitoring is an internal control, not something a vendor evidence record can provide. The Anthropic dossier instead organises what Anthropic publishes about API visibility, logging, access controls and enterprise administration. Each point is shown as Documented or Question surfaced, without judging whether an organisation's own monitoring is sufficient.

What this adds beyond a trust center

A vendor trust center can show what the vendor chooses to publish. SaaSDossier reads vendor-published sources against the same 55-field framework and separates fields marked Documented from fields marked Question surfaced. The value is not replacing the vendor's SOC 2, DPA, or trust portal. The value is a dated, source-linked review record your team can use before the vendor call.

Licensed Edition use

  • For use within one purchasing organization.
  • Unlimited internal users inside that organization.
  • Excerpts may be shared with external auditors, vCISOs, counsel, procurement reviewers, or GRC advisors under confidentiality.
  • Redistribution, resale, public posting, or use as a competing dataset is not permitted.

Using this record for a vendor security questionnaire or DDQ? See how SaaSDossier supports the review without completing or deciding it for you.