Claude for Work / API is generally safe for workplace use on a corporate plan. Our verdict for a typical 50–500 person company handling client or regulated data, assessed 29 July 2026: Approved. Anthropic states it does not train on commercial customers’ inputs or outputs by default, and Team/Enterprise plans add the admin and retention controls a policy needs. The corporate-tier counterpart to consumer claude.ai — same capability, materially different data terms.
This verdict reflects Anthropic’s published terms as we read them on 29 July 2026. A vendor can change its terms the day after; the primary sources below are how you check.
| Vendor | Anthropic |
|---|---|
| Category | General assistant |
| Our tier verdict | Approved (assessed 29 July 2026) — Anthropic states it does not train on commercial customers’ inputs or outputs by default, and Team/Enterprise plans add the admin and retention controls a policy needs. source |
| Trains on your data? | No (per vendor terms) No, by default. Anthropic states that by default it will not use your inputs or outputs from its commercial products (Claude for Work, the Anthropic API, Claude Gov) to train its models — unless you submit feedback or otherwise choose to allow it. If someone does hit the thumbs up/down button, Anthropic states it stores the entire related conversation for up to 5 years, which is why Enterprise admins can turn feedback off. source |
| Data retention | Anthropic documents custom data-retention controls for Enterprise plans, set by a Primary Owner or Owner under Organization settings. Retention runs from the last observed activity — the last message in a chat, or the last update to a project — with a 30-day minimum, and retention changes and deletions are recorded in audit logs. source |
| Admin controls | Enterprise plans include Primary Owner / Owner roles, organisation-level data and privacy settings (including a Rate chats setting that disables feedback submission), configurable retention, and audit logs covering retention changes and deletion events. source |
| Compliance certifications | Anthropic operates a Trust Center for commercial customers; its current certification list did not render in a machine-readable form when we checked, so we do not restate it here. Ask Anthropic for the current report. |
| HIPAA / BAA | Enterprise- or plan-dependent — Yes on the Enterprise plan or the first-party API — but only once someone switches it on. Anthropic states it "provides a BAA covering our HIPAA-ready services, such as use of our first-party API or Enterprise plans", and that coverage is not automatic: the Primary Owner must activate HIPAA compliance in the organisation’s "Data and privacy" settings and accept the BAA, because "Standard Claude Enterprise plans do not include BAA coverage without action from a Primary Owner." Coverage is also per-organisation and per-feature — Anthropic excludes Workbench, Claude Console, Claude Cowork and beta features such as Claude in Office and Claude Design, treats connectors, MCP and Enterprise Search as usable but not covered when data goes to a third party, and states that Covered Models require 30-day retention and are not available with zero data retention enabled. Read the feature table before assuming your workflow is inside the BAA. source |
No, by default. Anthropic states that by default it will not use your inputs or outputs from its commercial products (Claude for Work, the Anthropic API, Claude Gov) to train its models — unless you submit feedback or otherwise choose to allow it. If someone does hit the thumbs up/down button, Anthropic states it stores the entire related conversation for up to 5 years, which is why Enterprise admins can turn feedback off.
Retention: Anthropic documents custom data-retention controls for Enterprise plans, set by a Primary Owner or Owner under Organization settings. Retention runs from the last observed activity — the last message in a chat, or the last update to a project — with a 30-day minimum, and retention changes and deletions are recorded in audit logs.
Yes on the Enterprise plan or the first-party API — but only once someone switches it on. Anthropic states it "provides a BAA covering our HIPAA-ready services, such as use of our first-party API or Enterprise plans", and that coverage is not automatic: the Primary Owner must activate HIPAA compliance in the organisation’s "Data and privacy" settings and accept the BAA, because "Standard Claude Enterprise plans do not include BAA coverage without action from a Primary Owner." Coverage is also per-organisation and per-feature — Anthropic excludes Workbench, Claude Console, Claude Cowork and beta features such as Claude in Office and Claude Design, treats connectors, MCP and Enterprise Search as usable but not covered when data goes to a third party, and states that Covered Models require 30-day retention and are not available with zero data retention enabled. Read the feature table before assuming your workflow is inside the BAA. As a rule: no signed Business Associate Agreement means no protected health information (PHI) — a BAA is the gate, not the security posture. A vendor can hold every certification on the market and still be the wrong place for PHI, because what makes PHI processing lawful for a covered entity is the contract, not the encryption.
Comparing vendors on this specifically? See BAA status for all 26 tools →
Not verified from a primary document on this check date. Anthropic operates a Trust Center for commercial customers; its current certification list did not render in a machine-readable form when we checked, so we do not restate it here. Ask Anthropic for the current report. Ask for the current SOC 2 report under NDA before you rely on it. A certification is also not a contract: it describes how Claude for Work runs its controls, not what your agreement with them permits.
HIPAA is the gate: Yes on the Enterprise plan or the first-party API — but only once someone switches it on. Anthropic states it "provides a BAA covering our HIPAA-ready services, such as use of our first-party API or Enterprise plans", and that coverage is not automatic: the Primary Owner must activate HIPAA compliance in the organisation’s "Data and privacy" settings and accept the BAA, because "Standard Claude Enterprise plans do not include BAA coverage without action from a Primary Owner." Coverage is also per-organisation and per-feature — Anthropic excludes Workbench, Claude Console, Claude Cowork and beta features such as Claude in Office and Claude Design, treats connectors, MCP and Enterprise Search as usable but not covered when data goes to a third party, and states that Covered Models require 30-day retention and are not available with zero data retention enabled. Read the feature table before assuming your workflow is inside the BAA. Until a BAA is confirmed in writing, treat Claude for Work / API as off-limits for anything containing PHI — patient names, appointment details, clinical notes, even "anonymized" summaries that could be re-identified.
For SEC/FINRA-regulated firms the questions are recordkeeping and confidentiality: can communications through Claude for Work / API be captured for books-and-records requirements, and do the data terms hold up in vendor due diligence? Enterprise plans include Primary Owner / Owner roles, organisation-level data and privacy settings (including a Rate chats setting that disables feedback submission), configurable retention, and audit logs covering retention changes and deletion events.
The privilege question comes first: entering client-confidential facts into any third-party AI service must be evaluated as a potential disclosure. Claude for Work / API’s no-training terms on corporate plans help, but confidentiality duties still require client-consent and matter-sensitivity judgment.
Every vendor claim above traces to a document the vendor publishes, and every document below is one we actually opened and read — each carries the date we read it. All of them were read on 29 July 2026. The verdict date on this page is not a build stamp and is not "today": it is the oldest of those dates, because a verdict is only as current as the stalest document under it. Rebuilding the site does not move it.
Where a fact is not in one of these documents, the page says so rather than filling the gap. That is why some rows read "not publicly documented" or "not established from a primary source" instead of naming a certification or rounding an open question to a convenient answer.
Why the tier verdict is "generic": Approved is the right starting classification for most 50–500 person companies — but a healthcare company, a law firm, and a SaaS startup should not have identical tool lists. The $79 policy kit classifies Claude for Work / API and 25 other tools specifically for your industry, company size, and the data your team handles.
And a verdict has a shelf life: vendor data policies change quietly — a terms update can move a tool between tiers overnight. This page states what we read on 29 July 2026. The $149/mo Monitor plan exists precisely because that date keeps receding.
Claude for Work / API is generally safe for workplace use on a corporate plan. Our verdict for a typical 50–500 person company handling client or regulated data, assessed 29 July 2026: Approved. Anthropic states it does not train on commercial customers’ inputs or outputs by default, and Team/Enterprise plans add the admin and retention controls a policy needs. The corporate-tier counterpart to consumer claude.ai — same capability, materially different data terms.
No, by default. Anthropic states that by default it will not use your inputs or outputs from its commercial products (Claude for Work, the Anthropic API, Claude Gov) to train its models — unless you submit feedback or otherwise choose to allow it. If someone does hit the thumbs up/down button, Anthropic states it stores the entire related conversation for up to 5 years, which is why Enterprise admins can turn feedback off.
Yes on the Enterprise plan or the first-party API — but only once someone switches it on. Anthropic states it "provides a BAA covering our HIPAA-ready services, such as use of our first-party API or Enterprise plans", and that coverage is not automatic: the Primary Owner must activate HIPAA compliance in the organisation’s "Data and privacy" settings and accept the BAA, because "Standard Claude Enterprise plans do not include BAA coverage without action from a Primary Owner." Coverage is also per-organisation and per-feature — Anthropic excludes Workbench, Claude Console, Claude Cowork and beta features such as Claude in Office and Claude Design, treats connectors, MCP and Enterprise Search as usable but not covered when data goes to a third party, and states that Covered Models require 30-day retention and are not available with zero data retention enabled. Read the feature table before assuming your workflow is inside the BAA. As a rule: no signed Business Associate Agreement means no protected health information (PHI) — a BAA is the gate, not the security posture. A vendor can hold every certification on the market and still be the wrong place for PHI, because what makes PHI processing lawful for a covered entity is the contract, not the encryption.
Not verified from a primary document on this check date. Anthropic operates a Trust Center for commercial customers; its current certification list did not render in a machine-readable form when we checked, so we do not restate it here. Ask Anthropic for the current report. Ask for the current SOC 2 report under NDA before you rely on it. A certification is also not a contract: it describes how Claude for Work runs its controls, not what your agreement with them permits.
We classify Claude for Work / API as Approved for a typical 50–500 person company, assessed 29 July 2026. Anthropic states it does not train on commercial customers’ inputs or outputs by default, and Team/Enterprise plans add the admin and retention controls a policy needs. Your own classification should reflect your industry, data types, and which plan or account type your company actually uses.
New to the topic? Start with what shadow AI is — definition, examples and risks, then measure your own exposure with the shadow AI scorer.
Your team is using Claude for Work. Does your AI policy cover it?
Most policies name a handful of tools and go stale the month after they are written. Two ways to find out where yours stands: check an existing policy for gaps in 30 seconds, or generate a policy that classifies Claude for Work by name — free preview, no account. Starting from scratch? The free 14-section AI acceptable use policy template is the document itself, ungated.
A 4-document AI policy kit — acceptable use policy, tool tier list, acknowledgment form, manager FAQ — that classifies Claude for Work / API and 25 other tools for your company, industry, and data. Generated in about 10 minutes.
Generate my policy kit →We re-check vendor terms monthly and alert you when Claude for Work / API’s data policy changes — plus regenerate your whole kit so it never goes stale. This directory is a snapshot — Monitor is the live feed.
See Monitor plan →Already have an AI policy? Check it for gaps in 30 seconds →