Buying Claude Enterprise feels like the safe choice - and in many ways it is. Anthropic doesn't train on your business data by default, holds serious security certifications, and gives admins far more control than any consumer plan.
But an Enterprise licence is a toolbox, not a finished setup. Several defaults will surprise your data protection officer, a few settings can't be undone, and nothing in Claude Enterprise stops an employee pasting a customer spreadsheet into a chat.
At BrightBit Digital, Claude is our specialism: we set up Claude Enterprise for UK businesses and build the MCP connectors and Claude Code workflows that sit around it. This guide is what we check first on every setup. If your team is new to Claude itself, start with our Claude A to Z - the everyday habits that make everything here easier.
Every fact in this guide comes from Anthropic's own documentation, checked on 28 September 2026. Where we couldn't confirm something, we say so. Settings change quickly, so check the current versions before you rely on them.
This guide is written for two readers. Pick yours - you can switch at any time, and the choice is remembered.
How do you want to read this?
The Short Version for Leaders#
Claude Enterprise is safe to use if you set it up deliberately. Out of the box it protects you from the big risks - your data isn't used to train AI, it's encrypted, and access can be tied to your company logins. What it doesn't do is decide what data your people put into it, and some of its default settings keep more data, for longer, than most UK businesses would choose.
Under UK data protection law, your business stays responsible for the personal data your staff put into Claude - not Anthropic. So the question for you isn't "is Claude safe?" It's "have we set it up and briefed our people so that how we use it is safe?"
What You're Getting - and What You're Not#
| Claude Enterprise does this for you | This stays your job |
|---|---|
| Doesn't train AI on your business data (unless someone gives feedback or you opt in) | Deciding what data staff may put into it |
| Encrypts data when it's stored and while it travels | Choosing how long chats are kept |
| Independent security certifications (SOC 2, ISO 27001, ISO 42001) | Paperwork: a data protection impact assessment (DPIA) and a transfer risk assessment |
| Lets you control who can use which features | Actually setting those controls up |
| Records activity for audits | Switching that recording on - early |
Five Defaults That Surprise Leaders#
1. Chats are kept forever by default. Unless someone sets a retention period, every chat - including any customer details in it - stays indefinitely. UK data protection law expects you to keep personal data no longer than needed.
2. Feedback is kept for five years. When a staff member clicks thumbs up or down on an answer, that conversation can be kept for five years and used to improve Anthropic's models - outside your normal retention period.
3. The audit trail only starts when you switch it on. Anthropic's Compliance API keeps six years of activity - but only from the day it's enabled. If you wait until something goes wrong, there's no history to look at.
4. Your data is stored in the US. There's currently no option to keep Claude Enterprise chat data in the UK or EU. That's allowed under UK law, but it means extra paperwork - and it's a question your clients may ask.
5. "Zero data retention" isn't what it sounds like. It isn't a setting you can turn on. Anthropic arranges it for qualifying customers, and it only covers Claude Code - the developer tool - not everyday chats. Don't let anyone promise it to a client unless you have it in writing.
Can We Stop Customer Data Reaching Anthropic at All?#
Yes - with some engineering. The approach works like a redacted file:
- When Claude needs a customer record, a small piece of software inside your own systems fetches it and replaces personal details with codes - "Jane Smith" becomes "Customer 7F3A".
- Claude does its work using the codes: summarising complaints, drafting replies, spotting patterns.
- When Claude sends a reply or updates a record, your software swaps the codes back to the real details - again inside your own systems.
Anthropic only ever sees the codes. The customer still gets an email with their real name.
Do you lose quality? For most business tasks - summaries, drafts, triage, analysis - no. Claude doesn't need to know a customer's name to write a good reply. It does struggle with tasks that depend on the real detail, such as checking a name's spelling or validating an address. And it can't protect against someone copying data into a chat by hand, which is why staff guidance still matters.
This software is called a custom MCP server (MCP is the standard way Claude connects to other systems - explained here). It's a build project, typically measured in weeks, not a setting.
Why It's Worth Getting an Expert to Check the Setup#
The settings are spread across several admin screens, developer configuration files and your own legal documents. An expert review pays for itself in four places:
- Some choices can't be undone. Claiming every account on your email domain is one-way. Customer-managed encryption keys only protect data created after you switch them on. Audit history only exists from the day it's enabled. The order matters.
- Settings interact. Project retention settings override chat retention settings. Permission to "manage libraries" also lets someone add new connections to your systems. These are easy to miss.
- Settings must match your paperwork. Your DPIA should describe what's actually configured - and vice versa. Regulators and enterprise clients check both.
- No setting keeps personal data away from the model. That takes the engineering described above.
Your Action Plan#
This week#
- Name an owner. One person accountable for Claude Enterprise settings - usually IT or security, with your data protection lead alongside.
- Set a chat retention period. Agree a number with your data protection lead (the minimum is 30 days) and have your admin set it.
- Switch on the Compliance API so your audit history starts today.
- Decide on feedback. If you don't want conversations kept for five years via thumbs up/down, have the admin turn off chat rating.
- Send a one-page staff rule: what may and may not go into Claude. Start with the traffic-light table further down.
This month#
- Make sign-in automatic and removal instant. Company single sign-on (SSO), and automatic removal of leavers (SCIM) so access ends the moment HR processes a departure.
- Set up roles. Not everyone needs every feature. Most staff need chat; fewer need connections to your CRM or email; only developers need Claude Code.
- Turn off public sharing of Claude's outputs unless there's a business reason.
- Complete a DPIA and transfer risk assessment, and ask Anthropic to confirm how the UK data transfer rules (the UK Addendum or IDTA) apply to your contract - we couldn't find this in their public documents.
This quarter#
- Decide which systems Claude may connect to, and whether each connection may only read, or also change things.
- Plan a masking connector for any system holding customer or employee data you want Claude to work with.
- Review the settings quarterly. Anthropic adds features regularly - check new ones are off until you've decided on them.
Questions to ask your IT team#
- What's our chat retention period, and who agreed it?
- When did we switch on the Compliance API?
- Who can add new connections (connectors) to our systems?
- If someone pastes customer data into Claude today, how would we know?
- Which of our Claude settings does our DPIA describe - and do they match?
If someone pastes personal data into a chat#
Don't panic, and don't ignore it. Delete the chat - Anthropic removes deleted chats from its systems within 30 days (longer only if a chat was flagged for a safety policy breach). Tell your data protection lead so they can decide whether it needs recording, and use it as a reason to tighten the controls above.
What Enterprise Gives You Out of the Box#
- No training on your data by default. The exceptions are explicit feedback (thumbs up/down, retained for 5 years) and organisation opt-ins. Owners can disable feedback with "Rate chats" under Organization settings → Data and Privacy.
- Certifications: SOC 2 Type I and II, ISO 27001:2022, ISO/IEC 42001:2023.
- Encryption: AES-256 at rest, TLS 1.2+ in transit. Eligible Enterprise orgs can use customer-managed encryption keys (CMEK) via AWS KMS, Google Cloud KMS or Azure Key Vault - applied to new data only.
- DPA with Standard Contractual Clauses, incorporated into the commercial terms. We couldn't find the UK Addendum or IDTA stated in Anthropic's public DPA pages - confirm it for your contract.
- Residency: data is stored in the US; processing may be routed through the US, Europe, Asia or Australia. The only claude.ai Enterprise option is US-only inference (usage-based plans, billed at 1.1x). UK/EU residency is only available via the API on Bedrock, Vertex or Foundry.
Defaults and Gotchas#
| Default | Why it matters | Fix |
|---|---|---|
| Chats retained indefinitely | Conflicts with storage limitation under UK GDPR | Organization settings → Data and Privacy → custom retention (min 30 days). Project retention overrides chat retention. |
| Feedback retained 5 years, usable for training | Bypasses your retention period | Disable "Rate chats" |
| Compliance API records from enablement only | No retroactive history | Enable on day one (Organization settings → API, Primary Owner). Activity feed: 6 years. |
| Audit logs: 180 days, no chat content | Metadata only | Use the Compliance API for content; pull legal-hold data yourself - there's no native legal-hold toggle |
| Domain capture is one-way | Irreversible | Plan before enabling |
Claude Code transcripts stored in plaintext in ~/.claude/projects/ for 30 days | PII read by Claude Code sits on laptops | Lower cleanupPeriodDays; enforce disk encryption |
| ZDR is arranged by Anthropic, Claude Code only | Doesn't cover claude.ai chat, Cowork, or third-party MCP. Disables cloud sessions, Artifacts, /share and more | Don't promise ZDR for chat |
| Models covered by Anthropic's Covered Models policy (Fable 5/5.1) | Prompts and outputs retained 30 days even under ZDR | Factor into model choice for sensitive work |
Identity and Access#
- SSO: SAML (via WorkOS), with DNS TXT domain verification. We found no OIDC option documented.
- SCIM: Enterprise only - use it so offboarding is automatic.
- Session length: force re-authentication after 1, 7, 14 or 28 days. No idle timeout is documented.
- IP allowlisting: CIDR ranges, configured by Anthropic support.
- Roles: Primary Owner, Owner, Admin, User. Only Owners manage SSO and export audit logs.
Custom Roles: Your Main Control Surface#
Organization settings → Roles (Enterprise). Four tabs:
- Capabilities: Chat, Claude Code, Cowork, web search, memory, projects, artifacts, extended thinking, research.
- Connectors: per connector - Always allow, Needs approval or Blocked - with per-tool overrides via Custom. Use this to grant read tools on your CRM while blocking write tools.
- Models: enable models per role and cap the effort level per model.
- Permissions: delegated admin across Identity & Access, Billing, Analytics, Privacy, User Management, Libraries and Directory (No access / Can view / Can manage).
Least privilege in practice: few people should have Libraries: Can manage, because custom connectors can be added by Owners and by roles that manage libraries.
Feature and Sharing Toggles#
- Artifacts: separate toggles for artifacts, External sharing (public links) and external email invites. Disable external sharing by default.
- Project sharing: Data and Privacy → Sharing → "Share projects", and per role.
- Memory: off by default on Enterprise.
- Web search and code execution / file creation: Organization settings → Capabilities.
- Claude Desktop policies:
isLocalDevMcpEnabled,isDesktopExtensionEnabled,isClaudeCodeForDesktopEnabled,secureVmFeaturesEnabled,forceLoginOrgUUID, plus a desktop extension allowlist (off by default). - Claude in Chrome: org toggle with site allow and block lists.
Claude Code Managed Settings#
Deploy from the admin console (Admin Settings → Claude Code → Managed settings) or as managed-settings.json at:
- macOS:
/Library/Application Support/ClaudeCode/ - Linux/WSL:
/etc/claude-code/ - Windows:
C:\Program Files\ClaudeCode\
A reasonable baseline:
{
"permissions": {
"disableBypassPermissionsMode": "disable",
"deny": ["Read(./.env)", "Read(./.env.*)", "Read(./secrets/**)"]
},
"allowManagedPermissionRulesOnly": true,
"allowManagedMcpServersOnly": true,
"cleanupPeriodDays": 7,
"forceLoginOrgUUID": "<your-org-uuid>"
}
disableBypassPermissionsModestops developers turning off permission prompts.denyrules block reads of secrets files.allowManagedPermissionRulesOnlyandallowManagedMcpServersOnlystop local config overriding yours.forceLoginOrgUUIDensures Claude Code only signs in to your organisation.
For MCP, either ship an exclusive managed-mcp.json (same paths; an empty mcpServers map disables MCP) or use allowedMcpServers / deniedMcpServers, matching on serverUrl, serverCommand or serverName. The deny list always wins. Anthropic notes serverName matching is not a security control - match on URL or command.
Add the sandbox (sandbox.enabled, allowUnsandboxedCommands: false, sandbox.failIfUnavailable) - Seatbelt on macOS, bubblewrap on Linux - for filesystem and network isolation.
Anthropic is explicit that managed settings are "a client-side control, not a security boundary." They prevent mistakes; they don't stop a local admin. Pair them with MDM and endpoint controls.
Monitoring and DLP#
- Audit logs: Data and Privacy → Export logs (180 days): SSO sign-ins, file uploads, project visibility changes.
- Compliance API: activity feed (6 years) plus content endpoints for chats, files, projects, and Claude Code and Cowork transcripts including tool results. Anthropic lists 60+ integrations, including Microsoft Purview, Nightfall, Splunk and Relativity. ZDR and HIPAA orgs are excluded from session data.
- Inference hooks (beta, Enterprise, Owners configure): every prompt, tool response and uploaded file's text goes to your server before it reaches Claude, across Claude, Claude Code and Cowork. Your server returns allow or deny - no redaction. Netskope, Palo Alto Networks, Proofpoint and Zscaler support it. It runs in Anthropic's infrastructure, so there's no endpoint agent to deploy.
Inference hooks are the safety net for pasted data. They can't clean a payload, only block it - so masking has to happen upstream.
Masking PII With a Custom MCP Server#
Where connector data goes#
For custom connectors in claude.ai, Anthropic's cloud calls your remote MCP server - so it must be internet-reachable and authenticated, and whatever it returns enters the conversation and is sent to Anthropic. For local MCP servers in Claude Code or Claude Desktop, the server runs on the device, but its tool output still goes to the model.
So the control point is the tool response. Raw PII must never be in it.
Mask on read, unmask on write#
| Field | Source system | Tool response |
|---|---|---|
| Name | Jane Smith | [PERSON_7f3a] |
| jane.smith@example.co.uk | [EMAIL_c91e] | |
| Account | ACC-448120 | [ACCOUNT_02bd] |
| Address | 14 Hill Road, Leeds LS6 2AB | Leeds (LS6) |
| Date of birth | 3 March 1961 | 60-69 |
| Issue | "Charged twice for my March invoice" | "Charged twice for my March invoice" |
Read tools return tokens. Write tools accept tokens and detokenise server-side, so the outbound email has the real name and the model never saw it.
Choosing the technique#
| Technique | Reversible? | Model can reason over it? | Use for |
|---|---|---|---|
| Tokenisation (vault lookup) | Yes, on your side | Yes - stable references | Names, emails, anything written back |
| Keyed hash (HMAC) | No | Yes - stable, so countable and joinable | IDs, dedupe, joins |
| Generalisation | No | Yes - often better for analysis | DOB → age band, address → district |
| Encryption | Yes, with key | No - ciphertext is meaningless to the model | At rest and in transit only |
Use HMAC with a server-held secret, not a bare SHA-256: emails and phone numbers have small enough spaces to brute-force an unkeyed hash.
Minimal example (Python, official MCP SDK)#
import hashlib, hmac, os
from mcp.server.fastmcp import FastMCP
mcp = FastMCP("crm-safe")
SECRET = os.environ["PSEUDONYM_KEY"].encode() # never leaves your server
VAULT: dict[str, str] = {} # use an encrypted store with access logging in production
def mask(kind: str, value: str) -> str:
code = hmac.new(SECRET, value.lower().encode(), hashlib.sha256).hexdigest()[:8]
token = f"[{kind}_{code}]"
VAULT[token] = value
return token
@mcp.tool()
def get_ticket(ticket_id: str) -> dict:
"""Fetch a support ticket with personal details masked."""
t = crm.get_ticket(ticket_id) # your own CRM client
return {
"customer": mask("PERSON", t.name),
"email": mask("EMAIL", t.email),
"town": t.town,
"issue": redact_free_text(t.description), # run a PII detector here
}
@mcp.tool()
def send_reply(ticket_id: str, body: str) -> str:
"""Send a reply. Placeholders are replaced with real values server-side."""
for token, real in VAULT.items():
body = body.replace(token, real)
crm.send_email(ticket_id, body)
return "sent"
mcp.run()
Production checklist for this pattern:
- Free text is the hard part. Structured fields are easy; PII inside sentences needs a detector (Microsoft Presidio is a common open-source starting point) and will never be perfect. Test it against real samples.
- Scope write tools tightly.
send_replyshould only detokenise tokens belonging to that ticket, and ideally sit behind Needs approval in the role's connector settings. - Authenticate the remote server (OAuth) and log every detokenisation.
- Store the vault encrypted, with its own retention period.
- Pseudonymised data is still personal data under UK GDPR while you hold the key. Masking reduces risk and strengthens your DPIA; it doesn't remove your obligations.
Does quality hold?#
For summarisation, drafting, classification, trend analysis and triage - yes, largely. It degrades where the task depends on the literal value (spelling, address validation, cross-system matching without the shared key) and wherever the detector misses PII in free text. In claude.ai, users see tokens in the chat; design the workflow so real values surface in your systems, not the transcript.
Implementation Order#
- Enable the Compliance API and set chat retention (day one).
- SSO, SCIM, session length, IP allowlist.
- Custom roles; external sharing off; feedback decision.
- Claude Code managed settings, MCP allowlist and sandbox.
- Inference hooks with your DLP vendor.
- Masking MCP servers for each system holding personal data.
- DPIA and transfer risk assessment updated to match the actual config; quarterly review of new features.
What Can Go Into Claude: A Traffic-Light Guide#
| Data | Basic Enterprise setup | Hardened setup + masking connector |
|---|---|---|
| Public information, marketing copy | 🟢 Fine | 🟢 Fine |
| Internal documents with no personal data | 🟢 Fine | 🟢 Fine |
| Customer records (names, emails, accounts) | 🟠 Only with a DPIA and short retention | 🟢 Via the masking connector |
| Employee HR data | 🔴 Avoid | 🟠 Masked, HR-only roles, DPIA |
| Health, criminal or other special category data | 🔴 Avoid | 🟠 Only with legal advice, masking and inference hooks |
| Passwords, API keys, card numbers | 🔴 Never | 🔴 Never |
Frequently Asked Questions#
Does Anthropic train on Claude Enterprise data?#
No, not by default. Anthropic doesn't use Enterprise chats or files for training. The exceptions are feedback people choose to submit with the thumbs up or down buttons, which is kept for five years, and anything your organisation explicitly opts into. Owners can turn off chat rating in the Data and Privacy settings.
How long does Claude Enterprise keep chats?#
Indefinitely by default. Owners can set a custom retention period of at least 30 days under Organization settings, Data and Privacy. Project retention settings override chat retention, so check both.
Is Claude Enterprise GDPR compliant?#
Claude Enterprise gives you the tools to use it in a GDPR-compliant way - a data processing agreement, encryption, retention controls and audit tools - but compliance depends on how you configure and use it. Your business remains the data controller, and data is stored in the US, so you'll need a DPIA and a transfer risk assessment.
Can I stop personal data being sent to Anthropic?#
Not with a setting alone. Claude Enterprise has no built-in PII redaction. You can block messages containing personal data using inference hooks, and you can build a custom MCP server that masks personal data before Claude sees it and restores it only when actions happen in your own systems.
Does encrypting data protect it from the AI model?#
Encryption protects data while it's stored and while it travels, and Claude Enterprise already encrypts both. But the model has to read readable text to work with it. To stop the model seeing personal data, use tokenising, keyed hashing or generalising instead.
Is zero data retention available on Claude Enterprise?#
Only in a limited form. Zero data retention is arranged with Anthropic for qualified accounts, not switched on in settings, and it covers Claude Code only - not claude.ai chat.
Claude Enterprise can be a very safe way to use AI - if it's set up deliberately. Our AI consultancy reviews your Enterprise configuration against your DPIA and closes the gaps, and our MCP integration service builds masking connectors that let Claude work with your CRM, helpdesk and databases without personal data leaving your infrastructure.
AI engineer at BrightBit Digital



