No. 004 · Licensed Edition
Anthropic — Security Evidence Dossier

Evidence date 2026-06-24. A vendor-published privacy policy update post-dates this snapshot; re-verification is in preparation.
10 domains reviewed
- Identity & legal entity
- Standards & attestations
- Privacy & compliance
- Encryption & key management
- Infrastructure & hosting
- Access control
- Vulnerability & incident response
- Subprocessors & supply chain
- AI governance
- Secure development & organization
A sample of the evidence ledger
A preview of the discipline — one Documented, one Question surfaced. The full 55-field ledger is in the dossier.
What's inside
Evidence ledger
All 55 fields across 10 domains, each recorded in one of two states, with the vendor's own words quoted and cited where Documented.
Source register
Every vendor-published page reviewed, listed with its URL, so each line traces back to where it was found.
Integrity record
Each dossier includes a SHA-256 identifier tied to the reviewed evidence record used for that release.
Buyer-ready vendor follow-up questions
Field-level follow-ups generated from Question surfaced entries, used to help buyers decide what to confirm with the vendor in writing.
Does Anthropic store files or code Claude Code reads, and does opting out of model improvement change that?
Storage, retention and model-improvement use are separate questions. The Anthropic dossier records each separately: what Anthropic documents about retained content, whether customer data is used for model improvement, and how data is handled. Where vendor-published material does not resolve a point, it is shown as a Question surfaced rather than assumed.
How do teams monitor Claude Code at work and meet security and internal oversight requirements?
Endpoint monitoring is an internal control, not something a vendor evidence record can provide. The Anthropic dossier instead organises what Anthropic publishes about API visibility, logging, access controls and enterprise administration. Each point is shown as Documented or Question surfaced, without judging whether an organisation's own monitoring is sufficient.
What this adds beyond a trust center
A vendor trust center can show what the vendor chooses to publish. SaaSDossier reads vendor-published sources against the same 55-field framework and separates fields marked Documented from fields marked Question surfaced. The value is not replacing the vendor's SOC 2, DPA, or trust portal. The value is a dated, source-linked review record your team can use before the vendor call.
Licensed Edition use
- For use within one purchasing organization.
- Unlimited internal users inside that organization.
- Excerpts may be shared with external auditors, vCISOs, counsel, procurement reviewers, or GRC advisors under confidentiality.
- Redistribution, resale, public posting, or use as a competing dataset is not permitted.
Using this record for a vendor security questionnaire or DDQ? See how SaaSDossier supports the review without completing or deciding it for you.
