Registry / Anthropic API
Anthropic API
Anthropic's first-party Claude API (api.anthropic.com). Anthropic is both model developer and serving platform, so vendor-trust, data-handling, and EU AI Act dimensions all describe Anthropic directly. Commercial terms prohibit training on customer content; ZDR and HIPAA-ready configurations are available but sales-gated.
Watch-outs 5
The cells where this offering is not a clean public yes. This is what to check before you sign.
- SOC 2 Type II: Yes, sales-gated access requires request form
- HIPAA BAA: Yes, sales-gated requires BAA signing and sales contact to enable
- Retention / ZDR: Yes, sales-gated Zero‑data‑retention must be enabled via a sales contact per organization.
- Residency: Partial EU region pinning not offered; only US workspace geo and US/global inference geo are available
- Art. 53 summary: Yes, sales-gated Access to the training‑data summary requires a gated request‑access form.
Anthropic lists the SOC 2 Type II report in its Trust Center but requires a request to obtain it, confirming it is not publicly downloadable.
To access sensitive documents, please click the "request access" button at the top of the page and complete the request form.
Anthropic's own support page publicly lists ISO 27001:2022 as a certification it maintains, with no login or sales gate to see that claim — making it yes_public, not yes_sales_gated (the portal gate is only for downloading the artifact, not for verifying existence).
Anthropic is committed to the safety and security of our users' information and maintains the following compliance credentials: ... ISO 27001:2022 (Information Security Management)
Anthropic's own news page publicly confirms ISO/IEC 42001 certification for its AI management system, which encompasses the Anthropic API.
We are excited to announce that Anthropic has achieved accredited certification under the new ISO/IEC 42001:2023 standard for our AI management system.
The Anthropic trust center page is publicly accessible and contains the quoted statement, confirming a maintained compliance portal.
Here you can find our compliance artifacts, request documentation, and view high-level details on controls we adhere to.
Anthropic’s own privacy page confirms a BAA exists for the API but can only be activated after the primary owner signs it and coordinates with sales, satisfying the sales‑gated criteria.
Important: To use the 1P API with PHI, your organization’s Primary Owner will need to sign a BAA and then reach out to your Anthropic contact or our Sales team to get this turned on.
The DPA is publicly available, defines SCCs, and authorizes Subprocessors listed in Schedule 4, which Anthropic publishes at https://trust.anthropic.com/subprocessors, satisfying the requirement.
A.8. "Standard Contractual Clauses" or "SCCs" means Module Two (controller to processor) or Module Three (processor to processor) of the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679... C.1. Customer grants Anthropic general authorization to engage the Subprocessors listed in Schedule 4, and any additional Subprocessors in accordance with Section C.3. below.
Verified verbatim on Anthropic's own privacy domain, covering the Anthropic API by name; a public commitment with no gate, so yes_public is correct.
By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models.
Anthropic’s official docs publicly describe data retention and state ZDR is available only after contacting the sales team, matching yes_sales_gated.
To request ZDR for your organization, contact the Anthropic sales team.
Anthropic's official data residency docs confirm self‑serve region pinning exists but is limited to US only, so EU pinning is not possible, matching a partial answer.
Workspace geo is set when you create a workspace and can't be changed afterward. Currently, "us" is the only available workspace geo. ... Inference geo: Only "us" and "global" are available.
Anthropic is listed among the signatories on the EU Commission's public GPAI Code of Practice signatory list.
Anthropic
Anthropic lists the training‑data summary PDFs in its Trust Center but the page requires a request‑access step, so the Art. 53 summary is not publicly available.
To access sensitive documents, please click the "request access" button at the top of the page and complete the request form.
Spotted an error? Submit a correction with evidence, corrections with a primary source are folded in and credited in the changelog.