Claude Compliance API Lets Security Teams Monitor Chats, Files and Agent Activity
Anthropic's Compliance API lets enterprises export Claude chats, files, and agent activity into security tools.
Anthropic launched a Compliance API so Claude Enterprise and Claude Platform customers can export AI activity into existing governance and security platforms. Enterprise coverage includes conversations, uploaded files, projects, Cowork and Claude Code transcripts, and Microsoft 365 add-ins for Excel, Word, PowerPoint, and Outlook. Platform customers can retrieve administrative and resource events, including API-key creation, but not prompts or model responses. CrowdStrike, Splunk, Microsoft Purview, and Proofpoint are cited integrations. Endpoints under /v1/compliance share a 600-request-per-minute limit, and the API is for post-event evidence rather than inline enforcement.
- The Compliance API is offered to Claude Enterprise and Platform customers.
- Enterprise data includes chats, files, projects, Cowork, Claude Code, and Microsoft 365.
- Platform customers receive admin events but not prompts or responses.
- Named integrations include CrowdStrike, Splunk, Purview, and Proofpoint.
- It supports after-the-fact monitoring, not real-time blocking of inference.
Full article668 words · extracted from gbhackers.com · click to collapse
Anthropic has enhanced enterprise security visibility for its AI assistant, Claude, with the Compliance API. This feature lets organizations extract data on activity, conversations, files, projects, and agent sessions into their existing governance and security operations platforms.
The Compliance API is available to both Claude Enterprise and Claude Platform customers, although the breadth of accessible data varies by product.
The API helps security, legal, and compliance teams monitor how Claude is used across an organization. It helps investigate potential data exposure, retain records for regulatory purposes, and correlate AI activity with identity, endpoint, cloud, and SaaS telemetry.
Claude Compliance API
For Claude Enterprise customers, the Compliance API provides access to chat conversations, uploaded files, and projects. It also includes session transcripts from Cowork and Claude Code, which comprise prompts, model responses, tool-call content, and skills or artifacts presented as transcript text.
Coverage also extends to Claude’s Microsoft 365 add-ins for Excel, Word, PowerPoint, and Outlook, as well as Claude Science, which Anthropic lists as a beta capability.
This data can include prompts and responses alongside generated document text, formulas, and drafted emails, potentially creating a valuable audit trail for enterprise AI use.
The API also provides Activity Feed records that cover user logins, administrative actions, configuration changes, and other events.
Claude Platform customers can access administrative, system, and resource events such as membership changes, API Key creation, account-setting changes, file creation, downloads, and skill changes. However, the Compliance API does not expose prompts or model responses for Claude Platform environments.
Anthropic lists integrations covering DLP (Data Loss Prevention), SASE (Secure Access Service Edge), SIEM (Security Information and Event Management), security operations, identity governance, eDiscovery, AI security posture management, and telemetry infrastructure.
Security vendors can use the feed to detect sensitive data exposure, investigate suspicious behavior, monitor server usage, identify unauthorized agents, and enforce governance policies without additional standalone dashboards.
Examples of this integration include CrowdStrike, which integrates Claude activity into its Falcon platform for SIEM and automated response workflows; Splunk, which provides normalized events, detections, dashboards, and usage analytics; Microsoft Purview, which centralizes Claude activity and chat insights for data security posture management and audits; and Proofpoint, which implements DLP, insider threat detection, eDiscovery, and retention capabilities for AI interactions.
This ecosystem is significant because agent-based workflows introduce new monitoring requirements. Beyond chat prompts, teams may need to understand the tools, skills, connectors, servers, and artifacts an AI-enabled workflow invokes, as well as which identity initiated the activity.
The Compliance API utilizes endpoints under /v1/compliance/* and requires authentication through an API Key. A Compliance Access Key can access all supported endpoints, whereas an Admin API Key is limited to the Activity Feed. Anthropic maintains a shared rate limit of 600 requests per minute per parent organization for compliance endpoints.
For Claude Enterprise, only the organization’s Primary Owner can enable the API through Organization settings > API. This role can create a key that covers linked organizations, while Owners can create keys limited to their own organization; standard Administrators do not have access to this setting.
The Compliance API primarily serves as a tool for post-event monitoring and evidence collection, rather than as an inline enforcement mechanism. Anthropic differentiates it from inference hooks, which can process regulated prompts before inference and potentially deny requests in real time.
For security professionals, the API supports a practical investigation process: it lets them identify a risky upload or prompt, retrieve related activity and transcript data, correlate it with the initiating user, IP address, device, or endpoint telemetry, and determine whether a connected tool or agent executed any follow-on actions.
This makes Claude activity more accessible to established Security Operations Centers (SOCs), DLP, insider risk, and compliance workflows, especially as enterprises adopt AI technologies.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.