RL Written by Robert LabardeeFounder and CEO

Claude security and compliance for regulated enterprises

Lightbridge Labs guides regulated enterprises on consuming Claude securely. There are three commercial paths, Amazon Bedrock, the Anthropic API, and Claude.ai Enterprise, and each resolves to a different processor of record, data-handling posture, and evidence surface. This reference maps a Claude deployment to SOC 2, ISO 27001, SOX, and GDPR controls.

A regulated enterprise can consume Claude through three distinct paths.

There are three commercial ways to use Claude, and the choice determines the processor of record, the network-isolation architecture available, the admin console that drives configuration, and which DPA and BAA apply. The paths are not interchangeable. They diverge most on the contractual instrument, the default retention posture, and the network-isolation architecture.

Amazon Bedrock

A private, AWS-operated Claude deployment running inside the AWS account boundary on Anthropic licensed model weights. Prompts and completions stay inside AWS and never reach Anthropic. AWS is the sole processor of record under the AWS Customer Agreement, AWS DPA, and AWS BAA.

Anthropic API

A first-party REST API reached at the public api.anthropic.com endpoint, with Anthropic as the operating processor under the Anthropic Commercial Terms. Data sits inside the Anthropic plane. There is no customer-private endpoint, so isolation depends on customer-side IP allowlisting.

Claude.ai Enterprise

The enterprise tier of the Claude.ai product, with SSO, domain capture, role-based permissions, audit-log export, and a Compliance API. Anthropic is the processor under the Commercial Terms plus an order form. Web access only, with the workspace as the administrative boundary.

On Amazon Bedrock, Claude runs as a private deployment inside the customer AWS account.

Amazon Bedrock provisions and operates a private Claude deployment that runs Anthropic licensed model weights inside the AWS service plane. Anthropic licenses the model to AWS, and AWS runs the inference, so customer prompts and completions stay inside AWS and never reach Anthropic. A request reaches the regional Bedrock runtime endpoint, is dispatched to an AWS-operated deployment the model provider cannot reach, encrypted with KMS at rest, optionally logged to a tenant-owned S3 bucket, and visible in CloudTrail at the API-metadata layer.

The auditor-defensible baseline depends on several toggles that ship off by default. Lightbridge Labs treats four as the configurations an auditor will look for: model-invocation logging to an SSE-KMS S3 bucket with a customer-managed key and Object Lock, CloudTrail data events for Bedrock, PrivateLink interface endpoints with a deny-by-default policy, and a service control policy scoping the invoke action to approved model identifiers. None of the four is defaulted on. Building that baseline is part of a Claude deployment designed under our AI governance practice.

On the Anthropic-direct paths, posture is decided in the contract record, not the admin console.

On the Anthropic API and Claude.ai Enterprise, the data sits inside the Anthropic plane rather than a customer AWS account, and the controlling instruments are the DPA, the sub-processor list, and the contracting entity. Anthropic states that it does not train its models on inputs or outputs from its commercial products, and it evidences its encryption and security posture through SOC 2 Type II and ISO 27001 reports available in its trust center. Claude.ai Enterprise exposes the workspace as the administrative boundary, with SSO, SCIM provisioning, audit-log export, and a Compliance API that returns activity logs filtered by user and time range.

Several platform defaults route to the executed contract rather than a public page. Default API retention windows, the mechanics of any zero-retention path, the availability of an EU-resident inference plane, and any tenant customer-managed-key option are resolved in the DPA or order form, not a self-service toggle. The workspace settings control observability and admin reach; they do not move retention, residency, or training-use commitments off the contract. Treat these as contract-instrument controls and confirm each one with the Anthropic account team against the controlling DPA section.

The three Claude paths diverge most on contract, retention, and network isolation.

Twelve compliance-bearing dimensions separate the paths, but three divergences carry the most weight for a security, IT, or legal lead deciding which path to approve. These are the dimensions where the gap between paths is structural rather than a matter of configuration.

Contractual instrument

On Bedrock, AWS sits as the sole processor under the AWS Customer Agreement and AWS DPA. On both Anthropic-direct paths, Anthropic is the processor under its own Commercial Terms. An auditor who accepts a SOC 2 report on one processor will not automatically accept it on the other.

Retention default

Bedrock stores no prompts or completions for service operation, and model-invocation logging is off by default. Claude.ai Enterprise retains workspace data indefinitely until an administrator sets a finite retention window with a documented minimum of 30 days.

Network isolation

Bedrock is reachable through PrivateLink interface endpoints with no public-internet egress. The Anthropic-direct paths terminate on the public api.anthropic.com endpoint or a web origin, so a regulated buyer cannot place inference behind a private path.

A Claude deployment maps to SOC 2, ISO 27001, SOX, and GDPR through concrete configuration.

Compliance for Claude is not a promise; it is a set of platform settings and contract instruments an external auditor accepts as evidence. The overview below maps common Claude-deployment controls to the four frameworks regulated enterprises are most often asked about. It is a representative subset, not a full control library, and it shows where each control is configured rather than asserting an outcome.

Identity and access

Federate workforce access through the corporate identity provider via SAML SSO, enforce MFA, and manage user lifecycle with SCIM. Replace standing admin access with just-in-time elevation.

SOC 2 CC6.1, CC6.2, CC6.3; ISO 27001 A.5.15, A.5.16, A.8.5; SOX ITGC Access; GDPR Art. 32

Encryption

Require TLS 1.2 or higher in transit. On Bedrock, encrypt managed resources and invocation logs at rest with customer-managed KMS keys, separated by data-classification tier, with annual rotation.

SOC 2 CC6.7; ISO 27001 A.8.24; GDPR Art. 32

Logging and audit export

Enable Bedrock model-invocation logging and CloudTrail data events to an immutable, object-locked log archive. Pull the Claude.ai Enterprise Compliance API into a tenant-owned SIEM on a defined cadence.

SOC 2 CC7.2, CC7.3; ISO 27001 A.8.15, A.8.16; SOX ITGC Operations; GDPR Art. 30

Change management

Protect production branches, forbid author self-approval, and require dual review on financial-reporting code paths. Pin invoked Claude model versions to a dated identifier rather than an alias.

SOC 2 CC8.1; ISO 27001 A.5.3, A.8.32; SOX ITGC Program Changes

Residency and transfers

Pin Bedrock inference to a named AWS Region. On Anthropic-direct paths, identify the processing Region and the Article 46 transfer mechanism in the executed DPA residency annex, because these are not self-service toggles.

SOC 2 CC6.1, P4.1; ISO 27001 A.5.31, A.5.34; GDPR Art. 44, Art. 45, Art. 46

Sub-processor governance

Execute a GDPR Article 28 DPA with each processor, and a BAA where protected health information is in scope. Review the sub-processor list at every notified change with a documented objection window.

SOC 2 CC9.2; ISO 27001 A.5.19, A.5.20, A.5.21; GDPR Art. 28

Eight or more control areas rest primarily on signed contract instruments rather than platform settings, including the DPA, the BAA, sub-processor governance, the residency annex, and the transfer mechanism. Designing both the platform configuration and the governing contracts is the work Lightbridge Labs does as an independent advisor, and the deterministic enforcement points are built through custom AI development.

Claude security controls become the substrate for an ISO 42001 AI management system.

SOC 2 and ISO 27001 govern security and operational controls. ISO 42001 sits one layer up as the AI management-system standard: it governs how an organization decides what AI to run, how it monitors that AI, and how it retains evidence and oversight. The security controls described here are the enforceable substrate an ISO 42001 program requires, because an AI-governance policy is only as strong as the deterministic enforcement points behind it. A retention setting, a logging configuration, and a change-control rule on a model-invoking code path each turn a governance statement into something an auditor can test.

Lightbridge Labs builds the governance framework and the technical controls together. For the management-system design, see our ISO 42001 advisory and broader AI governance practice. For teams that need to operate these controls day to day, our responsible AI governance training covers the practices that keep a Claude deployment defensible after launch.

Claude security and compliance: frequently asked questions

Is Claude safe for regulated industries?
Claude can be deployed in a way that satisfies the controls regulated industries are asked to evidence, but safety is a property of the deployment, not of the model alone. Across all three commercial paths, Anthropic does not train base models on enterprise inputs or outputs by default, and AWS does not share Bedrock inputs or outputs with model providers. The remaining posture, encryption, logging, retention, identity, residency, and contract instruments, is configured by the organization. Lightbridge Labs helps a CISO, CIO, or compliance function design that configuration and produce the evidence an auditor will accept.
What is the difference between using Claude via the Anthropic API, Amazon Bedrock, and Claude.ai Enterprise?
The three paths are not interchangeable. On Amazon Bedrock, Claude runs as a private, AWS-operated deployment inside the AWS account boundary; AWS is the sole processor of record and prompts and completions never reach Anthropic. On the Anthropic API and Claude.ai Enterprise, the data sits inside the Anthropic plane and Anthropic is the operating processor under its own Commercial Terms. The sharpest divergences are the contractual instrument, the default retention posture, and the network-isolation architecture. Bedrock supports PrivateLink with no public-internet egress, while the Anthropic-direct paths terminate on a public endpoint or a web origin.
Does Anthropic train on enterprise data?
No, not by default. Anthropic states that it will not use inputs or outputs from its commercial products, which include the Anthropic API and Claude for Work, to train its models, and the Commercial Terms restate this as a product representation. The narrow exception is feedback a user voluntarily submits, which organizations on Team and Enterprise plans can disable. On Amazon Bedrock, AWS states that customer inputs and outputs are not shared with model providers and are not used to train any base foundation model, and the model provider has no access to the AWS-operated deployment. Verify the current commitment against the canonical vendor source before relying on it.
How does a Claude deployment map to SOC 2, ISO 27001, and ISO 42001?
SOC 2 and ISO 27001 are security and control frameworks: a Claude deployment maps to them through concrete configuration, including SSO and SCIM identity controls (SOC 2 CC6, ISO 27001 A.5 and A.8), KMS encryption (CC6.7, A.8.24), audit logging to an immutable store (CC7.2, A.8.15), and change management on any code path that invokes Claude (CC8.1, A.8.32). ISO 42001 is the AI management-system standard and sits one layer up: it governs how the organization decides what AI to run, monitors it, and retains evidence. The security controls become the enforceable substrate for an ISO 42001 program. Anthropic and AWS evidence their own SOC 2 Type II and ISO 27001 posture through their trust centers.
What is the default data-retention posture for each Claude path?
Amazon Bedrock does not store prompts or completions for service operation, and model-invocation logging is disabled by default; when an organization enables it, retention follows the customer S3 lifecycle or CloudWatch setting. Claude.ai Enterprise retains workspace data indefinitely until an administrator configures a finite retention window, documented with a minimum of 30 days. Default retention windows for the Anthropic API, and the mechanics of any zero-retention contractual path, are resolved in the executed DPA rather than a public toggle, so confirm them with the Anthropic account team and treat retention as a contract-instrument control until then.
Can a non-developer use Claude Code to change production code without breaking SOX controls?
Yes, when the source-control system enforces separation of duties. The agent does not relax the SOX perimeter; it shifts where an auditor looks for authorization and evidence. Branch protection requires an approving review from someone other than the author, and CODEOWNERS routes the pull request to a qualified engineering owner. Financial-reporting code paths should require two approvals, one engineering owner and one finance-IT control owner, and the model version invoked on those paths should be pinned to a dated identifier so a vendor update is a planned change rather than a surprise. All enforcement lives in the source-control system, not in Claude Code.
How does Lightbridge Labs help with Claude governance?
Lightbridge Labs is an independent AI-governance advisor. We help an organization choose the right Claude consumption path for its risk profile, design the deployment configuration that satisfies its SOC 2, ISO 27001, SOX, and GDPR obligations, and stand up the AI management system that an ISO 42001 program requires. We are not affiliated with Anthropic or AWS, and our certifications are in progress: Lightbridge Labs is pursuing SOC 2, ISO 27001, and ISO 42001 and operates to those controls while the audits proceed. The work connects to our practices in AI governance, ISO 42001, custom AI development, and responsible AI governance training.

Important notices

General advisory: this page is general guidance, not a warranty, and not a substitute for testing a configuration in your own environment.

Not professional advice: this is not legal, accounting, audit, or tax advice. The statements here about SOX, IT general controls, GDPR, SOC 2, ISO 27001, and ISO 42001 are simplified summaries of complex regimes. Consult your own counsel, auditor, and compliance functions before relying on any control mapping.

Vendor freshness: vendor product surfaces and compliance attestations change. Verify any specific claim against the canonical vendor source, including docs.anthropic.com, the Anthropic trust center, and the AWS documentation and trust resources, before relying on it.

Trademarks: Claude and Anthropic are trademarks of Anthropic, PBC. AWS and Bedrock are trademarks of Amazon. Lightbridge is not affiliated with, endorsed by, or sponsored by any of these vendors.

From a Claude path to a defensible deployment.

When the question shifts from how Claude handles data to how your organization proves it, Lightbridge Labs designs the deployment, maps the controls, and stands up the AI management system that governs it.