Skip to content

Anthropic configuration hardening security checks

Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.

On Anthropic, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Anthropic connector needs.

Checks (7)

severity: low Archived Workspace Not Deleted fix difficulty: easy #

Delete archived Anthropic workspaces that are no longer needed

  1. Navigate to Console > Workspaces
  2. Find the archived workspace
  3. Review if any API keys still reference this workspace
  4. Delete the workspace if confirmed no longer needed

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Stale Workspace fix difficulty: medium #

Archive or clean up Anthropic workspaces showing no recent activity

  1. Navigate to Console > Workspaces
  2. Find old workspace
  3. Review recent API key usage and member activity
  4. Archive if inactive or document continued use
  5. Clean up unused API keys within

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Usage Spike Detected fix difficulty: medium #

Investigate Anthropic usage spikes exceeding 3x the average token consumption

  1. Navigate to Anthropic Console > Usage
  2. Review token usage for the affected workspace and model
  3. Identify the source of increased usage
  4. Adjust rate limits or API keys if unauthorized usage is detected

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Workspace Default Rate Limits fix difficulty: medium #

Configure custom rate limits for Anthropic workspaces instead of inheriting organization defaults

  1. Navigate to Anthropic Console > Workspaces
  2. Select the affected workspace
  3. Configure custom rate limits appropriate for the workspace usage
  4. Save the rate limit configuration

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Web Search Tool Usage fix difficulty: medium #

Review API usage that includes web search tool requests to ensure prompts are not exposing sensitive data

  1. Navigate to Anthropic Console > Usage
  2. Identify API keys and workspaces generating web search requests
  3. Review whether web search tool usage is authorized
  4. Disable web search tool access if not required

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Claude Code High Session Count fix difficulty: easy #

Review users with unusually high Claude Code session counts to verify authorized usage

  1. Navigate to Anthropic Console > Usage > Claude Code
  2. Review the user's session activity
  3. Verify the session count aligns with expected usage
  4. Consider workspace scoping or rate limiting if usage is excessive

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Rate Limit High Requests Per Minute fix difficulty: medium #

Review and reduce overly permissive Anthropic rate limits exceeding 4000 requests per minute

  1. Navigate to Anthropic Console > Workspaces or Organization settings
  2. Review the rate limit configuration for the affected scope
  3. Reduce requests_per_minute to an appropriate level
  4. Monitor usage to ensure the new limit is sufficient

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

More Anthropic checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial