Govern Govern

Claude compliance: SOC 2, ISO, HIPAA, enterprise

For a regulated team, compliance is the gate before capability: the model does not matter until the paperwork clears. Anthropic maintains the security certifications a review asks for, including SOC 2 Type II and ISO 27001, offers HIPAA support with a BAA on eligible plans, and provides enterprise controls like SSO and data governance. Running Claude through your own cloud can inherit compliance you already have. Confirm the current scope in Anthropic's Trust Center for your plan.

Overview

The first time Claude nearly did not happen at my company, it was not a capability problem, it was a compliance one. Our security review would not let us use any vendor without SOC 2, full stop, and until that box was checked, nothing about how good the tool was mattered. I learned the hard way that in a regulated shop, compliance is the gate you pass before anyone will even look at the model.

This guide is that gate, mapped. The certifications a security review asks for, the healthcare and enterprise controls, how where you run Claude changes the compliance story, and how to walk your own review through it. Because certifications and their scope shift over time and by plan, the standing advice is to confirm the current specifics in Anthropic's Trust Center rather than take any list as fixed.

Compliance is the gate before capability

Compliance is the gate before capability

In a regulated organization, the order of operations is not what you might expect. You do not evaluate the tool and then check compliance; you check compliance and only then are you allowed to evaluate the tool. A brilliant model with the wrong paperwork does not get piloted, because the security and legal review sits in front of adoption, not after it.

This is worth internalizing because it changes how you champion Claude internally. The winning move is to bring the compliance answers to the review up front, rather than getting excited about capability and stalling at the gate. Know what your organization requires, and know what Claude offers against it, before you make the case.

Security certifications

Security certifications

The certifications that clear most security reviews are audited attestations that a vendor follows recognized security practices. Anthropic maintains the ones companies typically require, including SOC 2 Type II, which attests to controls over security and related principles over a period of time, and ISO 27001, an international standard for information security management. These are the boxes a standard vendor review checks first.

Having these matters precisely because they are what a security team is trained to ask for. When the reviewer asks for the SOC 2 report, the answer being yes, here it is turns a potential blocker into a formality. The specific certifications and their current scope are listed in the Trust Center, which is where you get the actual documents to hand your reviewer.

What a security review asks for
01Security certificationsaudited controls
SOC 2 Type IIISO 27001
02Healthcarea BAA on eligible plans
HIPAA support
03Enterprise controlsthe admin layer
SSOauditdata governance
The certifications and controls that clear a security review. Availability varies by plan, so confirm current scope with Anthropic.
Healthcare: HIPAA and BAAs

Healthcare: HIPAA and BAAs

Teams handling protected health information have a stricter bar: HIPAA, which governs how that data is handled, and requires a Business Associate Agreement, a BAA, between you and any vendor that touches it. Anthropic offers HIPAA support with a BAA on eligible plans, which is what makes it possible to use Claude in a healthcare-adjacent workflow at all.

The important nuance is eligible plans. HIPAA support is not a default on every tier; it is tied to specific plans and requires the BAA to be in place. So if you are in healthcare or selling into it, the questions are which plan provides HIPAA support and getting the BAA signed, not just does it support HIPAA. Confirm the current eligibility with Anthropic before you build anything touching PHI.

💡

TipFor any workflow touching protected health information, the BAA is not optional and not automatic. Confirm which plan provides HIPAA support and get the BAA in place before PHI goes anywhere near the tool.

Where you run it changes the story

Where you run it changes the story

One of the most useful compliance facts is that running Claude through a cloud platform you already use, Bedrock, Vertex, Foundry, can let you inherit compliance posture you have already established. If your data and governance already live in AWS under agreements your security team approved, reaching Claude through Bedrock means it runs inside that approved boundary, which can dramatically shorten the review.

This was, in the end, how my company got there. The blocker was never the model; it was standing up a new vendor relationship and data path from scratch. Running through a cloud we had already cleared turned a months-long procurement into a configuration change. Where you run Claude is a compliance lever, not just a technical one.

Data handling and residency

Data handling and residency

Compliance is not only certifications; it is also what happens to your data, which ties directly to the data and privacy story. A security review will ask whether your data trains the models, no, on business tiers by default, how long it is retained, and whether zero data retention is available, all of which are part of the compliance picture, not separate from it.

Data residency, where your data is processed and stored, also comes up for organizations with jurisdictional requirements, and is one of the reasons running through a specific cloud platform and region can matter. The through-line is that the data terms and the certifications are two halves of the same review, and you want crisp answers on both.

Enterprise controls

Enterprise controls

Beyond certifications, a security review looks for the controls that let an organization actually govern usage: single sign-on so access runs through your identity system, audit capabilities so you can see what happened, and data governance controls appropriate to an enterprise. These are typically part of enterprise-tier offerings, and they are what turn Claude from a tool individuals use into one a company can administer.

These controls overlap with the teams-and-admin story, but from the compliance angle the point is that a reviewer expects them. Being able to say access is behind our SSO, usage is auditable, and we control the data governance is a large part of clearing an enterprise review, and it is a reason the enterprise tier exists.

How to clear your own review

How to clear your own review

The practical playbook is to run the review proactively instead of reactively. Gather your organization's actual requirements first, from security, legal, and any regulatory obligations, so you know the real bar. Then pull the corresponding evidence from Anthropic's Trust Center, the SOC 2 report, the certifications, the data terms, the BAA if you need it, and bring it to the review as a package.

The other move that saves weeks is involving security early rather than presenting them a decision. A reviewer handed the documents up front, with the requirements already mapped to the evidence, can say yes quickly. A reviewer surprised by an already-chosen tool with unanswered questions will, correctly, slow you down. The homework is the shortcut.

💡

TipBring security in early with the requirements mapped to the evidence, don't present them a done deal. A reviewer handed the SOC 2 report and the data terms up front clears you fast; one surprised at the finish line does not.

Where it goes wrong

Where it goes wrong

The first mistake is assuming parity across plans and platforms, treating a certification or a control as present everywhere when it is tied to specific tiers or a specific way of running Claude. HIPAA support, enterprise controls, and some data terms depend on the plan, so verify for the exact plan you will use, not in general.

The second is trying to DIY compliance, hand-waving a security review with I read a blog post instead of the actual attestations. Security teams want the documents, and the documents exist, so get them from the Trust Center. And the third is leaving compliance to the end, discovering the gate after you have invested in a rollout, which is the expensive way to learn that compliance comes first.

  • Assuming a certification or control is present on every plan and platform; verify for yours.
  • Hand-waving the review instead of pulling the actual attestations from the Trust Center.
  • Leaving compliance to the end, after investing in a rollout you cannot yet approve.
  • Overlooking that where you run Claude, your own cloud, can change the compliance story.
The GTM version

The GTM version

For GTM this matters the moment your automation touches customer data at a company with a real security function, which is most companies worth selling to. The research agent, the enrichment pipeline, the scoring job, all of them run into the compliance gate, and clearing it, the right certifications, the right data terms, running where governance already lives, is what lets them exist at all.

The reframe I wish I had started with: the model was never going to be the hard part. The gate was. Do the compliance homework first, bring the documents, involve security early, and you turn a months-long blocker into a formality. What does your own security review require, and do you have the evidence ready to hand it?

How to set it up

How to set it up

Gather your organization's real requirements

Get the actual bar from security, legal, and any regulators: which certifications are mandatory, whether you handle PHI, what data terms and residency you need. You cannot clear a review you have not scoped.

Pull the matching evidence from the Trust Center

Collect the corresponding documents, the SOC 2 report, ISO and other certifications, data terms, and the BAA if you need HIPAA, from Anthropic's Trust Center, for the exact plan you intend to use.

💡

TipVerify each requirement against the specific plan and platform you will run, not in general. Certifications, HIPAA support, and enterprise controls can be tied to particular tiers.

Decide where to run it

Consider running Claude through a cloud you already have approved, Bedrock, Vertex, or Foundry, so you inherit compliance and shorten the review, especially if a new vendor path would be slow.

Bring security in early

Present the requirements mapped to the evidence as a package, up front, rather than surprising the review with an already-chosen tool. Early involvement plus the documents is what turns the gate into a formality.

FAQ

Frequently asked questions

Why is compliance the first thing to handle?

Because in a regulated organization the security and legal review sits in front of adoption. A great model with the wrong paperwork does not get piloted, so you clear compliance before capability even gets evaluated.

What certifications does Claude have?

Anthropic maintains the audited certifications reviews typically require, including SOC 2 Type II and ISO 27001. The current list and scope are in the Trust Center, where you can get the actual reports to hand your reviewer.

Can I use Claude with healthcare data?

On eligible plans, with a Business Associate Agreement in place, Anthropic offers HIPAA support. HIPAA is not a default on every tier, so confirm which plan provides it and sign the BAA before any PHI is involved.

Does where I run Claude affect compliance?

Yes. Running through a cloud platform you already use, like Bedrock or Vertex, can let you inherit compliance posture you have already established, which can turn a months-long vendor review into a configuration change.

What enterprise controls matter for a review?

Single sign-on, audit capabilities, and data governance controls, typically part of enterprise offerings. A reviewer expects to see that access is behind SSO, usage is auditable, and data governance is in your control.

How do I clear my own security review?

Gather your organization's requirements first, pull the matching evidence from the Trust Center, decide where to run Claude, and bring security in early with the requirements mapped to the documents. The homework is the shortcut.

Is compliance the same across all plans?

No. Certifications, HIPAA support, enterprise controls, and some data terms can be tied to specific plans and platforms, so verify for the exact plan you will use rather than assuming parity.

Where do I get the compliance documents?

Anthropic's Trust Center, which holds the certifications, reports, and data terms for the relevant plans. Since scope changes over time, treat it as the authoritative, current source rather than any static summary.

Sources

Sources & further reading

Claude ships fast. This page was last reviewed Aug 23, 2026; verify time-sensitive details against the official docs above before relying on them.

Get the AI-for-GTM playbook in your inbox

New Claude guides, use cases, and prompts every couple of weeks.

Subscribe →