Skip to content

Anthropic data sharing & exposure security checks

External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.

On Anthropic, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Anthropic connector needs.

Checks (4)

severity: medium Claude Retention Set To Indefinite fix difficulty: easy #

Set a fixed chat retention period for the Claude organization instead of retaining content indefinitely

  1. Navigate to claude.ai > Organization settings > Data retention
  2. Review the current retention configuration
  3. Set a fixed retention period appropriate for compliance requirements
  4. Save the updated retention setting

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: medium Claude Content Redaction Disabled fix difficulty: easy #

Enable content redaction for the Claude organization to reduce exposure of sensitive data

  1. Navigate to claude.ai > Organization settings > Privacy
  2. Review the content redaction configuration
  3. Enable content redaction
  4. Save the updated setting

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: medium Claude Code Execution Egress Open fix difficulty: easy #

Disable network egress from Claude code execution to prevent data exfiltration from sandboxed code

  1. Navigate to claude.ai > Organization settings > Code execution
  2. Review the network egress configuration
  3. Disable network egress for code execution
  4. Save the updated setting

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: high Secret Detected In Claude Conversation fix difficulty: medium #

Rotate the exposed credential, then remove the conversation from Claude Enterprise

  1. Rotate the exposed credential immediately at its issuing provider
  2. Navigate to claude.ai > Organization settings > Compliance API access
  3. Locate and delete the flagged chat via the Compliance API, or ask the user to delete it

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

More Anthropic checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial