Anthropic data sharing & exposure security checks
External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.
On Anthropic, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Anthropic connector needs.
Checks (4)
severity: medium Claude Retention Set To Indefinite fix difficulty: easy #
Set a fixed chat retention period for the Claude organization instead of retaining content indefinitely
- Navigate to claude.ai > Organization settings > Data retention
- Review the current retention configuration
- Set a fixed retention period appropriate for compliance requirements
- Save the updated retention setting
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: medium Claude Content Redaction Disabled fix difficulty: easy #
Enable content redaction for the Claude organization to reduce exposure of sensitive data
- Navigate to claude.ai > Organization settings > Privacy
- Review the content redaction configuration
- Enable content redaction
- Save the updated setting
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: medium Claude Code Execution Egress Open fix difficulty: easy #
Disable network egress from Claude code execution to prevent data exfiltration from sandboxed code
- Navigate to claude.ai > Organization settings > Code execution
- Review the network egress configuration
- Disable network egress for code execution
- Save the updated setting
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: high Secret Detected In Claude Conversation fix difficulty: medium #
Rotate the exposed credential, then remove the conversation from Claude Enterprise
- Rotate the exposed credential immediately at its issuing provider
- Navigate to claude.ai > Organization settings > Compliance API access
- Locate and delete the flagged chat via the Compliance API, or ask the user to delete it
Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11