Data security · for the team evaluating this

Where does your data go?Nowhere without your say-so.

That is the design, not a policy bolted on afterwards. This page is the whole answer, in two layers: the picture for the person deciding, then the depth an IT, security and compliance review needs — what leaves the machine, where it goes, how long it exists, who is legally responsible for it, and what you can control centrally. Primary sources throughout.

Download the paper · PDF

No form, no email address. Built to forward to your security team.

Talk to us

A security review with your IT is part of that conversation.

Facts verified against Anthropic’s published policies · July 2026

The answer for leadership

This section is for the person deciding. Everything after it is for your security team — the paper is the version built to forward.

Where does your data go? Nowhere without your say-so — that is the design.

Your organisation’s working files stay on your people’s own computers, as plain files you can open and read. Nothing is uploaded in bulk, no index of your data is built anywhere, and nothing runs in the background. Data moves only when a person working chooses to send it: task by task, they direct which files the AI reads and supervise everything that comes back.

That discipline is not an add-on to the training — it is the training. Managing what the AI reads for each piece of work is the core skill we teach, so the same practice that makes your people effective with AI is what keeps your data governed.

Your organisation holds its own layer of control on top of that: policies for what may be shared, deny rules that put named files beyond the AI’s reach, central settings no individual can override — and the commercial agreements governing the AI itself, under which the model provider is contractually prohibited from training on your data. That is the default, not something you opt into.

The rest of this page takes your security team through the full picture, with primary sources throughout. They will be in good company: the sectors with the strictest confidentiality duties — major banks, most of the UK’s top law firms, healthcare, the US federal government — have completed this review and deployed.

One pattern worth carrying into the review: organisations whose biggest barrier to AI is data control tend to discover that this is the version of AI they can actually approve. The design that makes it governable is the same design that makes it work.

The security review

Everything below is written for the people who have to sign this off.

01How much of this applies to you

For most organisations, this is one decision.

Adoption comes down to running Claude on a commercial plan — Team or above. Every protection that matters here comes with that plan by default. Nothing has to be configured, negotiated or deployed to get it.

Arrives by default on a commercial plan

The contractual no-training prohibition · 30-day deletion · processor status under a Data Processing Addendum · encryption in transit and at rest. A five-minute managed-settings baseline (deny rules on credential files, telemetry off) is worth adding and is described below, but it is a hardening step, not a precondition.

Exists if your data classification demands it

Zero data retention · cloud-perimeter deployment · the Compliance API · US-only inference. If yours does, your security team will already know; most are not in that position, and none of it needs deciding before people start.

Individuals exploring before their organisation commits can do so on a personal plan with the training setting turned off — the first module of the training walks through that setting.

02The review in three sentences

The whole review, in three sentences.

On commercial plans, Anthropic is contractually prohibited from training on your data and acts as your data processor. Claude Code sessions are encrypted in transit and at rest and deleted from Anthropic’s servers within 30 days — with zero-retention arrangements available for qualified enterprise accounts. Every control can be enforced centrally through managed settings, including disabling all non-essential transmission.

03A deliberately narrow scope

One tool, one inspectable loop.

Multiply Academy’s training deploys one AI tool: Anthropic’s Claude Code, used interactively in a terminal on the employee’s own computer. There is no web workspace to govern, no tenant integration, and no background service. The entire data story is a single, inspectable loop — which makes this a materially simpler review than most AI tools your team will have assessed.

If your organisation has already approved Microsoft 365 Copilot — the most common prior AI review — the questions here have the same class of answers (commercial no-training terms, encryption, central governance), applied to a much narrower surface: Copilot’s review concerned tenant-wide access to mail, calendars and SharePoint by design; Claude Code starts with access to nothing beyond the files a user’s task touches, and any reach into other systems exists only if deliberately connected — per user, under that user’s own sign-in, governable centrally (see connecting other systems). The one genuinely different consideration is that processing happens on Anthropic’s infrastructure rather than inside your Microsoft tenant — the retention and control sections below address it directly.

04The data flow, in one paragraph

Nothing moves until a person sends it.

An employee’s files stay on their computer. When they set a task, Claude Code sends the instruction plus the specific files it reads for that task — encrypted — to Anthropic’s servers; the model’s response comes back; the loop repeats. The person working directs what is read and reviews what comes back — and because choosing what the AI reads per task is the core skill the training teaches, that human control point is a practised discipline, not an assumption. Nothing is uploaded in bulk, no index of your data is built, and nothing runs when the terminal is closed. Where an organisation chooses to connect other systems (next section), the same loop extends to them under each user’s existing permissions. On the plans used for organisational work, the server-side copy of each session is deleted within 30 days and is never used to train models — and organisations with stricter requirements can go further: a zero-data-retention arrangement, negotiated directly with Anthropic for qualifying Enterprise accounts, means sessions are not stored at all (detail in the retention section below).

05What leaves the machine

What leaves the machine — and what never does.

Transmitted · encrypted, TLS 1.2+, compatible with corporate VPNs and proxies

  • The user’s prompts and the model’s responses
  • The contents of files Claude Code reads for the task in hand
  • Operational telemetry — performance metrics that contain no file content, code or file paths. All non-essential transmission (telemetry, error reports, feedback commands) can be switched off with a single setting, deployed centrally so individual users configure nothing.

Never transmitted

  • ×Files outside the folder the user is working in, unless explicitly granted
  • ×Files your organisation places under deny rules — credentials, key files and other named paths that Claude Code’s tools are forbidden to open
  • ×Anything from other applications, and nothing to any third party beyond Anthropic — unless your organisation deliberately connects a service (next section)

And on Anthropic’s side, your data is never: used to train models (contractual on commercial plans), sold, used for advertising, visible to any other customer, or added to any cross-customer index. There is no mechanism by which one customer’s data reaches another.

06Connecting other systems (MCP integrations)

Connections are default-closed, and yours to govern.

Claude Code can optionally connect to other systems — email, cloud drives, calendars, line-of-business tools — through MCP, the open standard for AI-tool connections. Three facts govern the security review:

  1. Default-closed. Out of the box there are no connections; each one is deliberately added.
  2. Per-user sign-in. A connector authenticates as the individual user (typically OAuth) and can reach only what that user’s account can already reach. The agent inherits existing permissions — it does not create new ones. If a connected tool over-shares, that visibility existed before any AI was attached; the fix belongs in the source system.
  3. Centrally governable. Managed settings can allowlist approved connectors or block them outright, so the reachable surface is an organisational decision, not a user one.

Content a connector retrieves enters the session and follows the same transmission and retention rules as everything else on this page. The connected service itself continues to process its own data under its own terms, as it did before.

07Where does it go, and for how long?

Thirty days on commercial plans — or nothing at all.

Processing and storage happen on Anthropic’s infrastructure; data at rest is stored in the US, encrypted with AES-256. Usage-based Enterprise plans can additionally pin all inference to US-based servers.

Server-side retention of Claude Code session data, by plan:

PlanRetentionTrained on?Legal basis
Personal subscription (Pro/Max)~30 daysprovided the user has turned the training setting off (it defaults to on)Only if the training toggle is onConsumer policy — Anthropic is the data controller
Team30 days, then deletedNever — contractually prohibitedCommercial Terms + DPA — Anthropic is your data processor
Enterprise30 days, then deletedNeverSame
Enterprise with Zero Data RetentionNothing stored at rest — prompts and responses are processed in real time and not retainedNeverSame

Three honest footnotes that belong in any accurate review:

  • Three exceptions apply on every plan — including under a zero-data-retention arrangement, where nothing else is stored: sessions flagged by automated trust-and-safety systems may be retained up to 2 years; feedback a user actively submits to Anthropic is retained 5 years (the feedback commands can be disabled organisation-wide); and legal holds apply as they would to any processor.
  • Zero Data Retention (ZDR) is not a plan feature. It is a per-organisation arrangement available to qualified Enterprise accounts, enabled by Anthropic’s account team after an eligibility review — raise it with Anthropic (or with us) if your data classification requires it. It is also available for API-based deployments. One caveat: the frontier models Anthropic designates as “Covered Models” under its safety framework require a 30-day retention window and sit outside ZDR; other models are unaffected.
  • The personal-subscription row is why organisations should not roll out on personal accounts. Its protections are settings and policy rather than contract — the consumer terms carry no confidentiality obligations, and policy can change (the training default did, in September 2025). Commercial plans make the same protections contractual. If individuals explore on personal accounts first, the training toggle must be off.

09What can you control centrally?

All of it, and users cannot override any of it.

Machine-level policy — managed settings

Pushed via MDM/GPO (or server-managed without device management), taking precedence over all user settings: permission rules and file-access deny lists (for example, blocking credential and key files from ever being read), command restrictions, network domain allowlists, forced login to your organisation’s account, telemetry disabled, and MCP connectors allowlisted or blocked.

Identity and the leaver problem

SSO with domain capture from the Team plan up; SCIM automated provisioning and deprovisioning on Enterprise. Access ends when the account does, and organisational data belongs to the organisation — the common concern about staff on individual accounts taking data access with them does not arise.

Oversight (Enterprise)

Audit logs, usage analytics, spend controls, and a Compliance API giving programmatic access to organisational usage data for monitoring and eDiscovery — the governance layer regulated industries ask for.

Data controls

Custom retention policies for organisation content (Enterprise), the US-only inference option (usage-based Enterprise), and ZDR for qualified accounts. Stated plainly: the standard 30-day operational window is not configurable downwards except via ZDR — there is no setting between 30 days and zero.

On the machine itself. Claude Code is read-only by default, asks approval before acting, is scoped to the folder it is started in, and supports OS-level sandboxing — with credential and key files excludable from its reach entirely via the deny rules above. The final control is the person: every action is proposed and approved, and the training builds that supervision into how people work rather than leaving it to policy.

10Deployment options

Two ways to run it — and one keeps everything inside your own cloud.

Standard SaaS (Team or Enterprise) suits most organisations: the controls above, contractual data protection, fastest path to running.

Cloud marketplace deployment suits organisations whose data must stay inside their existing cloud security perimeter. Claude runs on your cloud provider’s managed infrastructure — Anthropic never sees your inputs or outputs, the cloud provider is the data processor, and your existing compliance frameworks, identity management and (optionally) private networking apply. Billing goes through the cloud agreement you already have.

Cloud platformService
AWSAmazon Bedrock
Google CloudVertex AI
Microsoft AzureAzure Foundry

Claude is available across all three major cloud platforms, so this route is open whichever one your organisation already uses.

11Certifications, and who has already done this review

Independently audited, and already through the strictest reviews.

CertificationScope
SOC 2 Type IISecurity and operational controls, independently audited
ISO 27001:2022Information security management
ISO/IEC 42001:2023AI management systems
HIPAABusiness Associate Agreements available
FedRAMP HighUS government sensitive data (via AWS GovCloud)

Full reports are available through Anthropic’s Trust Centre.

Who has already run this review

These are Anthropic’s customers rather than ours, and that is the point: the review has been run, and passed, by teams with more to lose than most. The most data-sensitive sectors have already completed this evaluation and deployed — major banks and wealth managers (Anthropic runs a dedicated financial-services offering; RBC Wealth Management is a named customer), healthcare and pharma (Banner Health, Stanford Healthcare; Novo Nordisk cut clinical study report writing times by ~90% running Claude inside AWS Bedrock), most of the UK’s top law firms — a sector whose confidentiality duties exceed almost any corporate standard — and the US federal government, where a GSA agreement makes Claude available across all three branches at FedRAMP High.

On our side of it: an AIM-listed plc runs this across its leadership and its teams today — five of them talk about it, by name and on camera, on our homepage.

12The other two tools in the workflow

The other two tools are simpler cases.

The training workflow includes two supporting tools. Both are simpler cases than Claude Code.

Obsidian · local, no account

A local application for viewing and editing the plain-text files Claude Code works with. It has no account, no cloud processing and no telemetry — company data never flows through Obsidian’s servers. Its optional sync service is end-to-end encrypted (AES-256). Independently security-audited (Cure53 penetration test, report public). It holds no SOC 2 — a small team with, structurally, nothing server-side to certify. For cautious organisations, Restricted Mode disables all community plugins.

Wispr Flow · voice, one setting decides it

Voice dictation, processing audio in the cloud. The evaluation hinges on one setting: Privacy Mode, which implements zero data retention — audio is processed and immediately discarded, with nothing stored or used for training. Administrators can enforce it organisation-wide, and for work use it should be treated as mandatory. Wispr Flow holds SOC 2 Type II, offers SSO/SAML and BAAs, and its Context Awareness feature (which reads the active application) should be evaluated separately for sensitive workflows.

13Getting started

The path is short.

Choose Team or Enterprise, forward the paper and the Trust Centre to your security team — the SOC 2 report and DPA answer most questionnaires — and, where you want the hardening baseline, push the managed settings described above. Nothing else on this page is a precondition. The deeper options — cloud-marketplace deployment, ZDR, custom retention — are there when your data classification calls for them, not before.

On policy: little new policy is usually needed. The human-oversight requirement most AI policies already contain is how this methodology works by design — every output is reviewed and approved by the person who directed it.

And where you have a hard constraint, tell us: we would rather scope honestly around it than talk past it.

Download the paper · PDF

Everything on this page, built to forward.

Talk to us

A short form and a reply from Phil. Bring your IT team to the call.

Primary sourceWhat it covers
Anthropic Privacy CentreData handling and retention, plan by plan
Anthropic Trust CentreSOC 2 report access, subprocessors, security documentation
Commercial TermsThe no-training clause, IP assignment, confidentiality
Data Processing AddendumProcessor obligations, SCCs, deletion at end of contract
Claude Code SecuritySandboxing, permissions, what leaves the machine
Claude Code Data UsageRetention detail and telemetry controls