Skip to content

Audit & Compliance

Last verified: 13 February 2026 | Applies to: Enterprise

Enterprise plans provide audit logs, a compliance API, and data exports for monitoring and governing Claude usage across your organisation. These tools let you track who’s using Claude, what they’re doing, and maintain records for regulatory compliance. One critical gap: Cowork sessions are not captured.

ToolWhat it does
Audit logsTimestamped records of user activity — conversations started, features used, connectors accessed
Compliance APIProgrammatic access to audit data for integration with your compliance tools (SIEM, GRC)
Data exportsBulk export of conversation data for archival or analysis

Audit logs capture:

  • User identity — who performed the action (email, SSO identity)
  • Timestamp — when the action occurred
  • Action type — conversation started, connector used, plugin activated, file created
  • Feature — Chat, Cowork (usage only, not content), Connectors, Code
  • Metadata — conversation ID, session duration, model used

Audit logs do not capture:

  • Full conversation content (available via Data Exports if enabled)
  • Cowork session content
  • Files processed locally in Cowork

The Compliance API provides programmatic access to audit data:

  • Integrate with your SIEM — pipe Claude audit data into Splunk, Datadog, or your existing security monitoring
  • Feed your GRC tools — automated compliance reporting for SOC 2, ISO 27001, and other frameworks
  • Custom dashboards — build internal reporting on Claude usage

Contact Anthropic’s enterprise team for API documentation and access.

Bulk export conversation data for:

  • Archival — retain records per your data retention policy
  • Analysis — understand usage patterns across the organisation
  • Compliance — provide records to auditors or regulators on request

Exports are available in standard formats. Frequency and format options available through the enterprise dashboard.

FrameworkClaude Enterprise support
SOC 2 Type IIAnthropic maintains certification. Request the report.
GDPRDPA available. Review sub-processor list and data processing locations.
HIPAAContact Anthropic for healthcare-specific guidance. Not standard.
PCI DSSNot currently certified. Do not process payment card data through Claude.
ISO 27001Check with Anthropic for current certification status.

Something wrong or outdated? Let us know →

Get weekly workflows — subscribe to the newsletter.