Compliance frameworks, security audits, and quality certifications this company maintains.
Anthropic complies with the California Consumer Privacy Act and CPRA, giving California users of Claude rights to access, delete, and opt out of the sale or sharing of their personal data.
Anthropic is pursuing FedRAMP authorization for its Claude API and enterprise products, enabling US federal government agencies to deploy Claude models in compliant cloud environments for sensitive workloads.
Anthropic aligns its responsible AI development processes with the NIST AI Risk Management Framework, using its structured approach to identify, assess, and mitigate risks across Claude model development and deployment.
Anthropic maintains PCI DSS Level 1 certification for its billing infrastructure processing payments from Claude Pro, Claude Team, and Claude Enterprise subscribers worldwide.
Anthropic holds SOC 2 Type II certification covering security, availability, and confidentiality of the Claude API and Claude.ai consumer platforms.
Anthropic is ISO 27001:2022 certified for its information security management system governing model training infrastructure and customer data handling.
Quality
ISO/IEC 42001:2023
CertifiedAnthropic was among the first AI companies globally to achieve ISO 42001 certification, the international standard for responsible AI management systems.
Claude for Enterprise offers HIPAA-configurable deployment options enabling healthcare organizations to use Claude for clinical documentation and medical workflows.
Anthropic complies with GDPR for all EU user data processed through Claude.ai and the API, with zero data retention options available for enterprise customers.
Security
ASL-3 (AI Safety Level 3)
CertifiedAnthropic activated ASL-3 safety protections in May 2025 for models approaching capabilities that could provide serious uplift to CBRN or cyberattack development.