Loading the catalogue…
Loading the catalogue…
Compliance posture
Sovereignty ladder · how the level was reached
Stav's assessment · serving-side
Anthropic is a US-incorporated operator (Anthropic PBC) whose first-party Claude API and claude.ai run exclusively on US infrastructure, with confirmed CLOUD Act exposure and no Anthropic-operated EU processing region — EU residency is only achievable by routing through AWS Bedrock or Google Vertex AI EU regions, where the hyperscaler assumes the processor role instead of Anthropic. This drives the composite down despite a genuinely strong security and contractual baseline: security posture is the standout dimension, backed by current ISO 27001, ISO 42001, and SOC 2 Type II certifications, and contractual posture benefits from a DPA with 2021 SCCs, audit rights, and subprocessor liability commitments. Serving residency and legal exposure are the weakest dimensions and are weighted most heavily by design, reflecting that every direct request to Claude's first-party endpoints constitutes an EEA-to-US transfer regardless of contract tier. Serving retention sits in the middle — commercial/API traffic isn't trained on by default and offers a Zero Data Retention option, but consumer-tier defaults and flagged-content retention introduce some drift. On balance this is an elevated-risk posture for EU-regulated workloads: Stav's verdict is routed-only, with sovereign EEA serving achievable only via a hyperscaler-operated EU-region deployment (Bedrock/Vertex) rather than Anthropic's own infrastructure, and a contractual derogation or ZDR arrangement is advisable for any regulated use of the direct API.
Anthropic's first-party Claude API and claude.ai have no native EU processing region (inference_geo only supports 'us' or 'global'); EU-region processing exists only via AWS Bedrock or Google Vertex AI EU deployments, where the hyperscaler—not Anthropic—is the processor.
Certifications & legal documents
Endpoints served · 11
Anthropic PBC is US-incorporated with confirmed CLOUD Act exposure, and its published subprocessor list includes US hyperscalers (AWS, Google Cloud, Azure) in the serving path, with DPF adequacy status contested rather than confirmed.
Commercial/API traffic is not used for training by default and is deleted within 30 days, with a contractible Zero Data Retention option, though consumer-tier Claude trains by default since August 2025 and flagged content is retained up to 2 years.
Anthropic holds multiple current, sourced certifications (ISO/IEC 27001:2022, ISO/IEC 42001:2023, SOC 2 Type II) with a 48-hour breach notification commitment and no unresolved breach history noted.
The DPA incorporates 2021 SCCs plus a UK Addendum, grants audit rights and a 15-day subprocessor-objection window, and Anthropic accepts liability for subprocessors, though the exact contracting entity is only disclosed on request rather than named in the DPA.
Risk assessment
Anthropic's first-party Claude API and claude.ai offer no EU-only processing region; the inference_geo parameter only supports 'us' or 'global', and Workspace data storage is US-only. EU data residency is only obtainable by routing through AWS Bedrock EU regions or Google Vertex AI EU regions, which are operated by the hyperscaler, not Anthropic. source ↗
DATA_RESIDENCYClaude Platform on AWS (the AWS-billed, Anthropic-operated product) processes customer requests outside the AWS security boundary, in a location of Anthropic's choosing — distinct from, and easily confused with, genuine Bedrock EU-region deployments where AWS remains the processor. source ↗
DATA_RESIDENCYA German-market legal analysis states that, as a US-headquartered provider, Anthropic does not currently hold a certification under the EU-U.S. Data Privacy Framework according to its own published certification information — meaning SCCs (not DPF adequacy) are the operative EU transfer mechanism for direct Claude use. This conflicts with some third-party summaries claiming DPF participation, so the point should be independently verified before relying on DPF as a transfer basis. source ↗
LEGAL_EXPOSUREConsumer Claude (Free/Pro/Max) conversations are, since an August 2025 policy change, eligible for model training by default unless the user actively opts out, with training-eligible data retained for up to 5 years; this consumer-tier default is materially weaker than the commercial/API no-training baseline and creates risk if staff use consumer accounts for work data. source ↗
SERVING_RETENTIONAnthropic's status page and third-party monitors recorded a cluster of incidents in August–September 2026, including a major outage on Aug 16, 2026 affecting Claude.ai, Claude Code and Claude Cowork, and a reported string of roughly 21 incidents between Aug 12 and Sep 2, 2026, several tied to capacity-related 529 errors. source ↗
RESILIENCEAnthropic's DPA identifies the data importer only as 'the Anthropic entity that executed the Agreement,' with contact details 'disclosed to Customer upon request' rather than a named EU/UK contracting entity published in the DPA itself, leaving the exact liable legal entity for EU customers to be confirmed per-contract. source ↗
GOVERNANCESafeguards
Commercial/API traffic (api.anthropic.com, Claude Platform on AWS, Claude in Microsoft Foundry) is not used to train models by default, and inputs/outputs are automatically deleted within 30 days of receipt or generation unless a longer retention feature, ZDR, or legal requirement applies. source ↗
Qualifying enterprise customers can contract for a Zero Data Retention (ZDR) arrangement under which prompts and responses are not stored at rest after the API response is returned, except as needed to comply with law or combat misuse. source ↗
Anthropic publishes a full subprocessor list (AWS, Google Cloud, Microsoft Azure, Cloudflare, Stripe, WorkOS, Intercom, etc.) on its own Trust Center domain, with per-vendor product scope and jurisdiction noted. source ↗
The DPA grants customers a 15-day objection window before any new subprocessor is engaged, and Anthropic commits to remain liable for subprocessors' acts to the same extent as its own. source ↗
The DPA incorporates the EU's 2021 Standard Contractual Clauses (Module 2/3) plus the UK Addendum, and commits Anthropic to notify customers of a Security Breach without undue delay and within 48 hours of becoming aware of it. source ↗
The DPA grants customers audit rights over Anthropic's controls (self or third-party auditor, subject to confidentiality and a 12-month cadence), and requires Anthropic to delete or return Customer Data within 30 days of contract termination. source ↗
For customers requiring EU/EEA-region processing, Anthropic supports regional deployment via AWS Bedrock EU profiles (Frankfurt, Ireland, Paris, Stockholm) and Google Vertex AI EU regions, with Microsoft Foundry EU-native inference targeted for 2026. source ↗
Privacy-policy issues
No first-party EU processing region source ↗
Direct use of claude.ai or api.anthropic.com results in an EEA-to-US data transfer on every request regardless of plan tier; EU-only processing requires a separate deployment path through a hyperscaler.
Consumer-tier training-by-default source ↗
Since the August 2025 consumer terms update, Claude Free/Pro/Max conversations are used for model training by default unless the user opts out, with a 5-year retention window when training is on.
Retention window conflicting across sources source ↗
Some third-party trackers claim Anthropic cut default API log retention from 30 to 7 days in September 2025, while Anthropic's own current platform documentation states a 30-day default deletion window, so the exact current default should be confirmed directly with Anthropic before contracting.
Flagged-content retention extends to 2 years source ↗
Conversations flagged for a Usage Policy violation are retained for up to 2 years, and associated trust-and-safety classifier scores for up to 7 years, extending beyond the standard retention window.