5.1 Module 5 · Trust & Governance

The Data & Safety Posture

For a business audience, capability is only half the decision. The other half is "can I defend this to risk, legal and the board?" Claude's governance posture is a genuine selling point — not a PR line.

Governance Q&A AI Governance

Interactive: the three questions every business asks

Tap the question your IT, legal or finance team would raise — and get the answer you can give them.

Certifications & enterprise controls

SOC 2 Type I & II ISO 27001:2022 ISO/IEC 42001:2023 HIPAA-ready (with BAA) GDPR — DPA + SCCs

Enterprise toolkit: audit logs (180 days), SCIM provisioning, the Compliance API, customer-managed encryption keys, US-only inference, and managed policy settings (tool permissions, file-access, MCP configs). HIPAA-readiness with a BAA is on sales-assisted Enterprise. Reports live at trust.anthropic.com. (FedRAMP isn't confirmed — verify if it matters to you.)

The ad-free pledge

No sponsored links, no advertiser-influenced answers. Structurally credible because ~80% of Anthropic's revenue is business customers — it isn't dependent on ads. "There are many good places for advertising. A conversation with Claude is not one of them."

RSP & AI Safety Levels

The Responsible Scaling Policy uses graduated safeguards (ASL-3 currently active, with real-time "Constitutional Classifiers"). Constitutional AI trains Claude against a written set of principles. The Fable 5 suspension shows the framework working under real regulatory pressure.

Key takeaway

On business plans your data isn't used for training, the certifications are in place, and the safety governance is real. That's what makes Claude defensible — not just useful. Governance is the slide that gets you the budget.