justo

Is Claude safe for client data?

Updated August 10, 2026 · 4 min read

Is Claude safe for client data?

Claude can be configured to protect client data: on Team and Enterprise plans, Anthropic does not train models on your content by default, and the business tiers add single sign-on, role-based access, audit logs, and retention controls, as of August 2026. Whether Claude is safe in your office is decided less by the model and more by the rules around it: who may use it, on which data, with whose review. Justo’s position is that the written policy comes before the rollout, every time.

Does Claude train on your business data?

Not by default on the business plans. As of August 2026, Team and Enterprise content is excluded from model training by default, which is the single fact most owners are actually asking about. On individual plans, training preferences are a setting to check rather than an assumption to make.

Verify rather than trust this guide: the current terms are at claude.com, and Anthropic publishes its security and compliance documentation publicly. A fact this important should be confirmed at the source and then written into your policy with the date you checked.

What security controls come with the business plans?

The business tiers carry the controls a data-protection review looks for, and the table below maps them to what they actually do for a small office, as of August 2026.

Business-tier controls and what they mean, checked August 10, 2026
ControlWhat it does for youWhere it starts
No training on your content by defaultClient material does not become model training dataTeam
Single sign-on and admin controlsOne place to grant and remove access, tied to your identity systemTeam
Audit logsA record of activity you can actually reviewEnterprise
Custom data retentionYou decide how long content persistsEnterprise
SCIM provisioningJoiners and leavers sync from your directory automaticallyEnterprise
IP allowlistingAccess only from networks you nameEnterprise
HIPAA-ready configurationA path for work that touches health informationEnterprise

Which tier a given office needs is a cost question as much as a controls question; the arithmetic is in What Claude actually costs a small business.

Where do client-data problems actually come from?

From the rollout decisions, far more than from the platform. The failure patterns we design engagements against are ordinary and human:

  • Personal accounts. Staff quietly paste client material into consumer AI tools where none of the business-tier protections apply, which is exactly what a ban without an approved alternative produces.
  • Over-broad access. A connector pointed at the whole drive when the task needed one folder. Every connection should be scoped to what the work requires.
  • No review rule. Output goes straight out because nobody wrote down that it must not. The review step is a rule, not a vibe.
  • No offboarding. Someone leaves; their access does not. Business tiers make this fixable in one place, but only if someone owns it.
  • Nothing in writing. The office "knows" the rules until the week it turns out everyone knew different ones.

What does policy-first mean in practice?

Policy-first means the rules are written, signed, and trained before the tool goes to work, not patched in after an incident. In our engagements the AI use policy is a deliverable with a date: plain language, covering approved tools, allowed data, supervision, and disclosure, and it is signed before go-live.

A good policy is short enough to be followed. If it cannot be read in one sitting by the newest hire, it is a compliance document, not a working rule.

What that document contains, section by section, with a sample clause to adapt for each one, is drafted out in An AI use policy for a small firm.

This is the governance piece of our flat-fee engagement, from $3,500, alongside setup and training. The full scope is on the pricing section of our main page.

Which data should stay out of AI entirely?

The usual entries: material under a protective order or court seal, anything a client has restricted in writing, trade secrets you have contracted to keep siloed, and data a regulator has already ruled on when nobody in the office has read the ruling. Every office has a version of this list; the point is that it is written down rather than intuited.

The excluded list is also allowed to shrink. As controls are verified and comfort grows, categories can move from excluded to allowed-with-review. That direction of travel, cautious first, is a feature of the approach and not a cost of it.

How do you verify the setup is holding?

By checking, on a date someone owns. Access reviews confirm the right people and only the right people; audit logs, on plans that carry them, get read rather than merely collected; the training-data and retention settings get re-confirmed rather than remembered.

Justo’s engagements build this in as the day-30 check: usage and access reviewed, the audit trail confirmed, and time saved measured against the baseline captured before rollout. A firm with ongoing obligations can keep the same review running monthly through the managed option. For the law-firm version of this whole analysis, privilege included, read Claude for law firms.

Straight questions

Is Claude HIPAA compliant?

Anthropic offers a HIPAA-ready configuration path on Enterprise as of August 2026, with the agreements that work requires. Compliance is a property of your whole setup, agreements, access, and process together, not a checkbox a vendor hands you.

What certifications does Anthropic hold?

Anthropic publishes its current security certifications and compliance documentation on its trust page. Check the source directly rather than relying on any third-party summary, ours included, and note the date you did.

Is a consumer Claude account good enough for business use?

For evaluating the tool, yes. For client data, no: the business tiers exist precisely to add the no-training default, shared administration, and access controls that client work calls for.

Can we write the AI policy ourselves?

Yes, and some offices should. The ingredients are in this guide: approved tools, allowed data, review rules, disclosure, offboarding. What an engagement buys is speed, the configuration work to match, and training so the policy describes how people actually work.

More guides

Book a call

Thirty minutes. You describe how your business runs; we tell you where AI fits and where it does not. Nothing to prepare, nothing to install. If we are not the right fit, we will say so on the call and point you somewhere better.