Anthropic
ai-api · anthropic.com · last read 2026-10-07
Identity
No identity observation recorded yet.
Data location
| Region | EU data location | Minimum plan | Source | Observed |
|---|---|---|---|---|
| EU | No EU location | — | platform.claude.com | 2026-10-05 |
EU: The document says workspace geo, which controls where data is stored at rest, is currently available only as "us", and inference geo only as "us" or "global". No EU location is offered.
Subprocessor chain
20 third parties · 16 with a country outside the EEA · all read 2026-10-05
| Subprocessor | Country | Purpose |
|---|---|---|
| Amazon Web Services | — | Cloud Infrastructure |
| Arkose Labs | US | Fraud and abuse detection |
| Boldr | CA | User support |
| Brave Search | US | Web Search |
| Cloudflare | — | Traffic Routing (CDN) |
| ElevenLabs | US | Text to speech |
| Functional Software, dba Sentry | US | Error Handling, User Support |
| Google Cloud Platform | — | Cloud infrastructure |
| Intercom | US | User support |
| Iterable | US | Email communications |
| Microsoft Azure | — | Cloud Infrastructure |
| Nutun | ZA | User support |
| Palantir Federal Cloud Service (PFCS) | US | FedRAMP Cloud |
| Persona | US | Fraud and abuse detection, identity verification |
| Sift | US | Fraud and abuse detection |
| Stripe | US | Billing |
| TurboPuffer | US | Web Search |
| Twilio | US | Analytics, email/SMS communications |
| WorkOS | US | Security, Single Sign-On |
| Yoti | GB | Fraud and abuse detection, identity verification |
The count outside the EEA is arithmetic over the country column, not a judgement about lawfulness. A transfer outside the EEA can be perfectly lawful; whether this one is depends on your use, not on the vendor.
Assurance
| Scheme | Status | Scope | Source | Observed |
|---|---|---|---|---|
| HIPAA-ready configuration · HIPAA | Claimed | BAA available; article covers commercial products such as Claude for Work and the Anthropic API | privacy.claude.com | 2026-10-05 |
| ISO 27001:2022 · ISO27001 | Available on request | Information Security Management; article covers commercial products such as Claude for Work and the Anthropic API | privacy.claude.com | 2026-10-05 |
| ISO/IEC 42001:2023 · ISO42001 | Available on request | AI Management Systems; article covers commercial products such as Claude for Work and the Anthropic API | privacy.claude.com | 2026-10-05 |
| SOC 2 Type I & Type II · SOC2T2 | Available on request | article covers commercial products such as Claude for Work and the Anthropic API | privacy.claude.com | 2026-10-05 |
Claimed means the vendor asserts the scheme on its own page and offers nothing further. Available on request means the report or certificate exists but sits behind a request, a login or an NDA. Neither is a certificate we have seen. That is a distinction an auditor makes, so we make it too.
Official registers
- ACN qualified cloud (Italy): checked 2026-10-07, no entry under Anthropic
- Data Privacy Framework List (US): checked 2026-10-07, no entry under Anthropic
- FedRAMP Marketplace (US): checked 2026-10-07, no entry under Anthropic
What the authority publishes, not what the vendor claims. An entry covers the offering it names and nothing else: a FedRAMP authorisation for a government edition says nothing about the commercial service. No entry is not a finding about security - most vendors never apply - and an entry filed under a name not listed above would not have been found.
Support window
Not yet collected. This row will say not declared only once we have read a lifecycle or security page and found no period stated — see support windows.
Documents
| Document | Disclosure | Transcription | HTTP | Observed |
|---|---|---|---|---|
| certifications | Public | full | 200 | 2026-10-05 |
| residency | Public | full | 200 | 2026-10-05 |
| subprocessors | JavaScript only | full | 200 | 2026-10-05 |
History
Nothing has moved since we started watching this vendor on 2026-10-05. Changes appear here only after a human has reviewed them.