Registry / Anthropic API
Anthropic API
Anthropic's first-party Claude API (api.anthropic.com). Anthropic is both model developer and serving platform, so vendor-trust, data-handling, and EU AI Act dimensions all describe Anthropic directly. Commercial terms prohibit training on customer content; ZDR and HIPAA-ready configurations are available but sales-gated.
Watch-outs 5
The cells where this offering is not a clean public yes. This is what to check before you sign.
- SOC 2 Type II: Yes, sales-gated access requires request‑access form
- HIPAA BAA: Yes, sales-gated BAA requires primary owner sign‑off and sales‑team activation
- Retention / ZDR: Yes, sales-gated Zero‑data‑retention (ZDR) must be requested via the Anthropic sales team, not self‑serve.
- Residency: Partial Only US region is supported; EU data residency not available.
- Art. 53 summary: Yes, sales-gated access requires request‑access form (sales‑gated)
The SOC 2 Type II report is listed in Anthropic's Trust Center but is only obtainable after submitting a request‑access form, confirming it is not publicly downloadable.
To access sensitive documents, please click the "request access" button at the top of the page and complete the request form. [Anthropic] 2025 Type 2 SOC 2 and CSA STAR L2 Report.pdf
The Anthropic support article publicly confirms that ISO 27001:2022 applies to the Anthropic API.
This article is about our commercial products such as Claude for Work and the Anthropic API. ISO 27001:2022 (Information Security Management)
Anthropic's own news page publicly confirms ISO/IEC 42001 certification for its AI management system, which includes the API offering.
We are excited to announce that Anthropic has achieved accredited certification under the new ISO/IEC 42001:2023 standard for our AI management system.
The Anthropic Trust Center loads publicly and provides compliance artifacts, confirming a maintained public compliance portal.
Here you can find our compliance artifacts, request documentation, and view high-level details on controls we adhere to.
Anthropic’s own trust‑portal page confirms a BAA is offered for the API but must be signed by the organization’s Primary Owner and enabled via a sales contact, matching yes_sales_gated.
Important: To use the 1P API with PHI, your organization’s Primary Owner will need to sign a BAA and then reach out to your Anthropic contact or our Sales team to get this turned on.
Anthropic publishes a DPA that defines SCCs and references Schedule 4, and its subprocessor list is publicly available at https://www.anthropic.com/subprocessors, meeting the public DPA with SCCs and published subprocessor list requirement.
"Standard Contractual Clauses" or "SCCs" means Module Two (controller to processor) or Module Three (processor to processor) of the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 ...
Anthropic’s own privacy page publicly states that API inputs/outputs are not used for model training by default.
By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models.
The provider’s own documentation publicly describes its API data‑retention policy and states that ZDR is available only through a sales‑gated request.
To request ZDR for your organization, contact the Anthropic sales team.
Official Anthropic docs show workspace geo limited to US and inference_geo only 'us' or 'global', so data cannot be pinned to the EU, making the answer partial.
Workspace geo is set when you create a workspace and can't be changed afterward. Currently, "us" is the only available workspace geo.
The EU Commission's official GPAI Code of Practice signatory list on its website includes Anthropic, confirming the model developer is a signatory.
Anthropic
Anthropic's own Trust Center lists the Claude Sonnet 5 training‑data summary but indicates it is behind a request‑access form, matching the definition of a sales‑gated publication.
To access sensitive documents, please click the "request access" button at the top of the page and complete the request form.
Spotted an error? Submit a correction with evidence, corrections with a primary source are folded in and credited in the changelog.