AI Governance

Claude Security Explained: How Secure Is Claude AI for Enterprise Use

Share via:
Written by:
CloudEagle.ai Team
Reviewed by
Nidhi Jain
Last Updated:
August 8, 2026
blog-cms-banner-bg
Little-Known Negotiation Hacks to Get the Best Deal on Slack
cta-bg-blogDownload Your Copy

HIPAA Compliance Checklist for 2025

Download PDF

Claude is inside more enterprise workflows than most IT teams realize. Developers are running Claude Code locally. Teams are using Claude.ai for strategy and planning. Engineers are connecting Claude to internal systems via MCP integrations.

And in many of those cases, IT has no visibility into what Claude can access, what it's doing with that access, or whether the accounts being used are managed or personal.

Claude security isn't primarily a question of whether Anthropic's infrastructure is trustworthy. At the platform level, it largely is. The question is what your team has connected to it, what data flows through it, and whether you have governance controls that treat Claude like the privileged access tool it has effectively become.

To track Claude spend and governance at scale, organizations need visibility into every Claude deployment: managed accounts, personal accounts, API integrations, and Claude Code instances.

This guide covers what Anthropic secures, what you still own, the real vulnerabilities that have been disclosed, and exactly what to do about them.

‍

1. Is Claude Already Inside Your Enterprise Workflows?

Anthropic's Claude is shifting from passive AI to high-privilege, agentic workflows across web and developer tools. With 8 of the Fortune 10 now using it, security teams need granular governance, not blanket bans.

As Claude adoption spreads, organizations have to move beyond reactive bans toward proactive frameworks that control AI sprawl while still enabling the work it's genuinely good at. The question worth asking isn't whether Claude is safe in the abstract. It's whether your specific deployment of it is.

How Does Claude Access Your Data Across Claude.ai, Claude Code, and API Integrations?

Claude isn't a single surface. It's three distinct deployment contexts, each with a different security profile.

Claude.ai is the browser-based interface. In its default configuration, it has access to conversation history and memory. With integrations enabled, it can connect to Google Drive, file systems, and other tools. Every integration expands what Claude can access, and what an attacker could potentially reach if Claude is compromised.

Claude Code is a command-line coding agent. It runs locally with direct access to your file system, terminal, and repository-level configurations. It can execute shell commands, initialize external services via MCP, and interact with APIs. It operates with the same permissions as the developer running it.

API integrations connect Claude to internal systems, knowledge bases, and third-party services. The security posture of an API-connected Claude deployment depends entirely on what scopes have been granted, what data those systems hold, and how the connection is governed.

‍

Claude Isn't Just One Entry Point.

Discover AI tools accessing your data across apps, APIs, and systems outside traditional IT visibility.
Find Hidden AI

‍

What's the Security Difference Between Claude Free, Team, and Enterprise Plans?

‍

Feature Free Team Enterprise
Data used for model training Yes by default No No
SOC 2 Type II coverage No Yes Yes
SSO / SAML No No Yes
Admin controls and usage visibility No Basic Full
Audit logs No Limited Yes
Data retention controls No No Configurable
Priority support and SLAs No No Yes

‍

Worth a Read: https://www.cloudeagle.ai/blogs/how-enterprises-can-track-claude-cursor-and-gemini-spend-in-one-place

‍

2. What Does Anthropic Secure, and What Does Your Team Still Own?

Based on Anthropic's Claude for Work model, security splits cleanly between what Anthropic secures (infrastructure) and what your team owns (data and inputs).

What Built-In Protections Does Claude Have?

Anthropic has invested significantly in infrastructure-level security.

  • AES-256 encryption at rest and TLS 1.3 in transit.
  • SOC 2 Type II and ISO 27001:2022 certification, plus ISO/IEC 42001:2023 for AI management systems (Anthropic's own certification list).
  • No training on enterprise customer data by default on paid plans.
  • Anthropic Safety Level 3 (ASL-3) protocols for high-capability model deployment.
  • A bug bounty program and regular penetration testing.
  • 24/7 security monitoring and incident response.

Where Does Anthropic's Responsibility End, and Your Governance Gap Begin?

Anthropic secures the platform. Everything else is your team's responsibility:

  • What data employees type or paste into Claude prompts.
  • Which MCP servers and integrations are connected to Claude Code.
  • Whether personal API keys are in use across your developer team.
  • Which repositories developers are cloning and running Claude Code against.
  • Whether Claude.ai accounts are managed or personal. The Claude AI Licenses guide explains how unmanaged personal accounts create both governance and cost problems.
  • How Claude access is provisioned, reviewed, and revoked as your team changes.

‍

3. What Are the Real Claude Security Risks Organizations Underestimate?

What Was the Claudy Day Vulnerability, and What Did It Expose?

In March 2026, Oasis Security disclosed Claudy Day, a chain of three vulnerabilities in Claude.ai that enabled silent data exfiltration.

How the attack worked

  • Hidden HTML instructions embedded in a Claude URL parameter that pre-fills the chat box.
  • Delivered via spoofed links, including through Google Ads, posing as legitimate URLs.
  • Claude processed both the visible and the hidden prompt instructions.
  • Sensitive data (chat history, financials, strategy) was extracted and exfiltrated via the Files API.

Why it matters

  • No integrations, tools, or MCP servers required.
  • Worked in a default Claude session.
  • Prompt integrity breaks if the delivery channel is compromised.

Oasis Security reported the findings through Anthropic's Responsible Disclosure Program before publishing. Anthropic has patched the prompt injection flaw; the related open-redirect and Files API issues were still being addressed as of the disclosure.

How Did Claude Code Become an Attack Surface via CVE-2025-59536 and CVE-2026-21852?

In February 2026, Check Point Research disclosed two related flaws in Claude Code's project-load and trust-dialog logic.

  • CVE-2025-59536 (CVSS 8.7, High): a bug in the startup trust dialog let a specially crafted repository execute shell commands the moment it was opened in Claude Code, before the user ever approved the trust prompt.
  • CVE-2026-21852 (CVSS 5.3–7.5 depending on scoring version): a separate logic flaw let a malicious repository set a manipulated ANTHROPIC_BASE_URL, redirecting API requests, including the user's Anthropic API key, to an attacker-controlled server before the trust prompt appeared.

Both are fixed in Claude Code 2.0.65 and later. Anthropic's advisories are public: GHSA-4fgq-fpq9-mr3g and GHSA-jh7p-qr78-84p7.

What was at stake

  • Full machine compromise from simply opening an untrusted repository.
  • Anthropic API key theft.
  • Potential access to shared workspace data across teams.

How Did GTG-1002 Weaponize Claude Code for Autonomous Cyberattacks?

In November 2025, Anthropic disclosed that it had detected and disrupted a campaign by a threat actor it designated GTG-1002, assessed with high confidence to be Chinese state-sponsored, marking one of the first documented AI-orchestrated cyber-espionage operations at scale.

How it operated

  • Multiple Claude Code instances, coordinated via MCP, were tasked to operate as autonomous penetration-testing agents.
  • The operation targeted roughly 30 organizations across tech, finance, chemical manufacturing, and government.
  • The attackers used role-play framing, posing the work as legitimate security testing, to get Claude to execute tasks it would otherwise decline.

Outcome

  • Anthropic assessed that the AI executed 80-90% of tactical operations independently, with humans intervening at only a handful of decision points per target.
  • A small number of intrusions succeeded before the campaign was detected and disrupted; accounts were banned and detections improved.

Why it matters

  • It's real-world evidence of agentic AI carrying out most of an attack with minimal human involvement.
  • It establishes AI agents as a viable, enterprise-scale threat vector, not just a theoretical one.

‍

4. What Are the Claude Security Best Practices for Enterprise Teams?

Implementing Claude in the enterprise takes a defense-in-depth approach across identity, data, and agentic features like Claude Code: SSO, granular permissions, and sandboxed tools, to prevent unauthorized access and data leakage.

These six practices are what actually make Claude safe to use at enterprise scale, not just at the individual level.

1. Enforce Least Privilege Before Enabling Claude Code or API Access

  • Audit what each developer's account can access in your environment.
  • Restrict Claude Code from running in directories containing production secrets or sensitive data.
  • Use separate API keys per developer rather than shared team keys.
  • Rotate API keys regularly and monitor for anomalous usage.

2. Audit and Govern Every MCP Server and Third-Party Integration Connected to Claude

  • Maintain an approved list of MCP servers and integrations.
  • Review .mcp.json and .claude/settings.json files before opening any cloned repository in Claude Code.
  • Never open repositories from untrusted sources in Claude Code without reviewing configuration files first.
  • Apply least privilege to every MCP connection scope.

3. Apply DLP Controls to Prevent Sensitive Data in Prompts

  • Define clear categories of data that must not enter Claude prompts: PII, source code with credentials, legal documents, and financial forecasts.
  • Use DLP tools that can scan prompt content before submission, where possible.
  • Train employees on what not to put into Claude, with specific examples relevant to your industry.

4. Treat Claude Code Like a Privileged User, Not a Productivity Tool

  • Require IT approval before Claude Code is installed on developer machines.
  • Restrict Claude Code from accessing production environments or credential stores.
  • Apply the same security controls to Claude Code sessions that you apply to privileged shell access.

5. Log All Claude Activity and Establish a Human Review Loop for Agentic Tasks

  • Enable audit logging for all Claude API usage and Claude.ai Enterprise accounts.
  • Integrate Claude logs into your SIEM.
  • Require human approval for Claude Code actions that involve file deletion, network requests, or credential access.
  • Review logs regularly for anomalous patterns.

6. Define an Acceptable Use Policy Covering What Employees Can and Cannot Input

  • Specify prohibited data categories for Claude prompts.
  • Define approved Claude tiers and account types.
  • Establish a process for reporting accidental sensitive data submission.
  • Build acknowledgment into onboarding for any employee who uses Claude for work.

‍

5. How CloudEagle.ai Helps You Govern Claude Access, Usage, and Spend Across Your Organization?

Native controls from Microsoft and Anthropic primarily govern approved accounts. They may not provide visibility into personal Claude.ai usage, unmanaged Claude Code installations, or how AI activity connects with broader SaaS governance and compliance processes.

CloudEagle.ai brings Claude and other AI applications into a broader SaaS security, AI governance, and identity governance framework, giving security and IT teams visibility into access, usage, spend, and compliance across human and non-human identities.

AI Governance

CloudEagle.ai brings Claude into a broader AI governance framework, giving security and IT teams visibility into AI usage, access, and policy compliance across the organization.

‍

‍

  • Identify approved and unapproved AI tools across the environment.
  • Apply governance policies to Claude and other AI applications.
  • Monitor AI usage across human and non-human identities.
  • Connect AI governance activities with broader security and compliance requirements.

Shadow AI Discovery

CloudEagle.ai helps identify AI tools being used across the environment, including:

‍

‍

  • Personal Claude accounts used outside managed environments.
  • Unsanctioned Claude Code installations across developer devices.
  • AI usage patterns detected through SSO, browser activity, and financial signals.

This gives security teams greater visibility into shadow AI before it creates security or compliance concerns.

Access Governance

Claude access can be managed through structured identity and access workflows:

‍

‍

  • Provision access based on role and business need.
  • Conduct periodic access reviews to identify unnecessary permissions.
  • Revoke access when employees change roles or leave the organization.

This extends SaaS access governance to Claude and other AI applications.

‍

"Once AI adoption accelerated across teams, visibility alone wasn't enough. We needed clear rules around who could use AI tools, under what conditions, and how those decisions were enforced and reviewed. CloudEagle helped us move from ad-hoc approvals to structured, defensible AI governance."
— Aditya Khosla, CTO, Iterative Health

‍

AI Usage and Spend Visibility

CloudEagle.ai helps organizations understand how approved AI tools are being used, not just which tools are in the environment:

‍

‍

  • Track token consumption: Monitor token usage across teams, users, and projects.
  • Analyze model usage: See which models are being used and where consumption is concentrated.
  • Set budgets and spend limits: Establish controls around AI spending and identify usage that exceeds defined thresholds.
  • Connect usage to spend: Attribute AI consumption to the appropriate teams, users, or projects to understand where costs are coming from.
  • Assess usage against ROI: Identify high-cost usage patterns and evaluate whether AI spend is delivering sufficient business value.

‍

‍

6. How Secure Is Claude AI? A Quick Decision Framework

Claude AI is generally safe for low-stakes use and is built with safeguards like Constitutional AI.

Features like Computer Use and Claude Code can still introduce risk if they access local files or execute commands without proper controls, which is why the controls above matter more as usage gets more agentic.

What Questions Should You Answer Before Enabling Claude Enterprise-Wide?

  • Are all Claude accounts tied to corporate SSO, or are personal accounts in use? If SSO isn't standardized yet, our guide to the best single sign-on tools is a place to start.
  • Do you have an inventory of every MCP server connected to Claude Code across your developer fleet?
  • Are Claude API keys individual or shared, and when were they last rotated?
  • Have you mapped Claude data flows into your SOC 2, GDPR, and HIPAA compliance scopes? If not, our ITGC audit guide covers the control areas that typically map to those requirements.
  • Do you have audit logging enabled and flowing into your SIEM?
  • Is there a human review checkpoint for any agentic Claude workflow?

When Should You Layer Third-Party Governance Tools on Top of Anthropic's Native Controls?

‍

Scenario Recommended Approach
Standard enterprise Claude.ai usage with managed accounts Enterprise plan with SSO, audit logging, and an acceptable use policy.
Developer teams using Claude Code Repository config auditing, separate API keys, and least-privilege enforcement.
Multi-AI environment with shadow Claude usage CloudEagle.ai for cross-stack discovery and governance.
High-sensitivity regulated data Restrict Claude access to non-regulated workflows, or deploy via API with strict scoping.

‍

7. How Do You Keep Claude Secure as It Scales Across Your Enterprise?

At the infrastructure level, Anthropic has built strong protections into Claude, including encryption, enterprise data controls, and secure platform design. For most organizations, the foundation itself isn't the primary concern.

The real risks show up in how Claude is used across the enterprise. From MCP configurations and personal Claude.ai accounts to agentic workflows like Claude Code, sensitive data and high-privilege access can quickly move outside traditional security boundaries.

Incidents like Claudy Day, CVE-2025-59536, and GTG-1002 make one thing clear: AI is now an active attack surface, not a theoretical one. CloudEagle.ai helps you stay ahead by providing the visibility and governance needed to manage Claude securely across your entire environment.

‍

Frequently Asked Questions

  1. Is Claude Safe to Use?
    Yes, for most everyday tasks. Anthropic secures the underlying infrastructure with encryption, access controls, and independent audits. The bigger question for a business isn't whether Claude itself is safe, but whether your employees are using managed, governed accounts instead of personal ones with no oversight.
  2. Is Claude Secure Enough for Enterprise Use?
    At the infrastructure level, yes: SOC 2 Type II, ISO 27001, and ISO/IEC 42001 certifications back that up. Whether it's secure enough for your enterprise specifically depends on the governance you add on top: SSO, DLP at the prompt layer, MCP and connector auditing, and continuous monitoring.
  3. How Safe Is Claude Compared to Other AI Tools?
    Claude, ChatGPT, and Gemini all publish similar infrastructure-level certifications (SOC 2, ISO 27001) at their enterprise tiers, and all three face the same real-world risk: employees using personal accounts and pasting sensitive data into prompts outside IT visibility. The safety difference between tools matters less than whether you're governing whichever ones your teams have already adopted.
  4. How Does CloudEagle.ai Detect Personal Claude.ai Accounts Used Outside Managed Environments?
    CloudEagle.ai identifies shadow Claude usage by cross-referencing SSO data, browser-based activity signals, and financial transaction records for personal subscription charges. This gives IT teams a complete picture of Claude access across the organization, including accounts that were never provisioned through official channels.
  5. Can CloudEagle.ai Integrate Claude's Audit Logs Into a Broader SIEM or Compliance Reporting Workflow?
    Yes. CloudEagle.ai connects Claude API and usage data to your existing compliance stack, so Claude activity feeds into the same reporting workflows you use for the rest of your SaaS portfolio, rather than requiring a separate governance stream.

‍

Advertisement for a SaaS Subscription Tracking Template with a call-to-action button to download and a partial graphic of a tablet showing charts.Banner promoting a SaaS Agreement Checklist to streamline SaaS management and avoid budget waste with a call-to-action button labeled Download checklist.Blue banner with text 'The Ultimate Employee Offboarding Checklist!' and a black button labeled 'Download checklist' alongside partial views of checklist documents from cloudeagle.ai.Digital ad for download checklist titled 'The Ultimate Checklist for IT Leaders to Optimize SaaS Operations' by cloudeagle.ai, showing checklist pages.Slack Buyer's Guide offer with text 'Unlock insider insights to get the best deal on Slack!' and a button labeled 'Get Your Copy', accompanied by a preview of the guide featuring Slack's logo.Monday Pricing Guide by cloudeagle.ai offering exclusive pricing secrets to maximize investment with a call-to-action button labeled Get Your Copy and an image of the guide's cover.Blue banner for Canva Pricing Guide by cloudeagle.ai offering a guide to Canva costs, features, and alternatives with a call-to-action button saying Get Your Copy.Blue banner with white text reading 'Little-Known Negotiation Hacks to Get the Best Deal on Slack' and a white button labeled 'Get Your Copy'.Blue banner with text 'Little-Known Negotiation Hacks to Get the Best Deal on Monday.com' and a white button labeled 'Get Your Copy'.Blue banner with text 'Little-Known Negotiation Hacks to Get the Best Deal on Canva' and a white button labeled 'Get Your Copy'.Banner with text 'Slack Buyer's Guide' and a 'Download Now' button next to images of a guide titled 'Slack Buyer’s Guide: Features, Pricing & Best Practices'.Digital cover of Monday Pricing Guide with a button labeled Get Your Copy on a blue background.Canva Pricing Guide cover with a button labeled Get Your Copy on a blue gradient background.

Enter your email to
unlock the report

Oops! Something went wrong while submitting the form.
License Count
Benchmark
Per User/Per Year

Enter your email to
unlock the report

Oops! Something went wrong while submitting the form.
License Count
Benchmark
Per User/Per Year

Enter your email to
unlock the report

Oops! Something went wrong while submitting the form.
Notion Plus
License Count
Benchmark
Per User/Per Year
100-500
$67.20 - $78.72
500-1000
$59.52 - $72.00
1000+
$51.84 - $57.60
Canva Pro
License Count
Benchmark
Per User/Per Year
100-500
$74.33-$88.71
500-1000
$64.74-$80.32
1000+
$55.14-$62.34

Enter your email to
unlock the report

Oops! Something went wrong while submitting the form.

Enter your email to
unlock the report

Oops! Something went wrong while submitting the form.
Zoom Business
License Count
Benchmark
Per User/Per Year
100-500
$216.00 - $264.00
500-1000
$180.00 - $216.00
1000+
$156.00 - $180.00

Enter your email to
unlock the report

Oops! Something went wrong while submitting the form.

Get the Right Security Platform To Secure Your Cloud Infrastructure

Please enter a business email
Thank you!
The 2023 SaaS report has been sent to your email. Check your promotional or spam folder.
Oops! Something went wrong while submitting the form.

Access full report

Please enter a business email
Thank you!
The 2023 SaaS report has been sent to your email. Check your promotional or spam folder.
Oops! Something went wrong while submitting the form.

TL;DR

  • Claude AI security: Claude has strong enterprise security controls, including SOC 2 Type II, ISO 27001, ISO/IEC 42001, and AES-256 encryption.
  • Key security risks: Organizations still need to address risks such as prompt injection, Claude Code supply-chain attacks, and employees using personal Claude accounts.
  • Claudy Day: A series of vulnerabilities in Claude.ai enabled silent data exfiltration through a crafted link. The prompt injection flaw has been patched.
  • Claude Code vulnerabilities: CVE-2025-59536 and CVE-2026-21852 created risks involving code execution and API key theft through untrusted repositories.
  • CloudEagle.ai: Helps organizations discover unsanctioned Claude usage, govern access, monitor AI spend, and connect Claude governance with compliance requirements.

Claude is inside more enterprise workflows than most IT teams realize. Developers are running Claude Code locally. Teams are using Claude.ai for strategy and planning. Engineers are connecting Claude to internal systems via MCP integrations.

And in many of those cases, IT has no visibility into what Claude can access, what it's doing with that access, or whether the accounts being used are managed or personal.

Claude security isn't primarily a question of whether Anthropic's infrastructure is trustworthy. At the platform level, it largely is. The question is what your team has connected to it, what data flows through it, and whether you have governance controls that treat Claude like the privileged access tool it has effectively become.

To track Claude spend and governance at scale, organizations need visibility into every Claude deployment: managed accounts, personal accounts, API integrations, and Claude Code instances.

This guide covers what Anthropic secures, what you still own, the real vulnerabilities that have been disclosed, and exactly what to do about them.

‍

1. Is Claude Already Inside Your Enterprise Workflows?

Anthropic's Claude is shifting from passive AI to high-privilege, agentic workflows across web and developer tools. With 8 of the Fortune 10 now using it, security teams need granular governance, not blanket bans.

As Claude adoption spreads, organizations have to move beyond reactive bans toward proactive frameworks that control AI sprawl while still enabling the work it's genuinely good at. The question worth asking isn't whether Claude is safe in the abstract. It's whether your specific deployment of it is.

How Does Claude Access Your Data Across Claude.ai, Claude Code, and API Integrations?

Claude isn't a single surface. It's three distinct deployment contexts, each with a different security profile.

Claude.ai is the browser-based interface. In its default configuration, it has access to conversation history and memory. With integrations enabled, it can connect to Google Drive, file systems, and other tools. Every integration expands what Claude can access, and what an attacker could potentially reach if Claude is compromised.

Claude Code is a command-line coding agent. It runs locally with direct access to your file system, terminal, and repository-level configurations. It can execute shell commands, initialize external services via MCP, and interact with APIs. It operates with the same permissions as the developer running it.

API integrations connect Claude to internal systems, knowledge bases, and third-party services. The security posture of an API-connected Claude deployment depends entirely on what scopes have been granted, what data those systems hold, and how the connection is governed.

‍

Claude Isn't Just One Entry Point.

Discover AI tools accessing your data across apps, APIs, and systems outside traditional IT visibility.
Find Hidden AI

‍

What's the Security Difference Between Claude Free, Team, and Enterprise Plans?

‍

Feature Free Team Enterprise
Data used for model training Yes by default No No
SOC 2 Type II coverage No Yes Yes
SSO / SAML No No Yes
Admin controls and usage visibility No Basic Full
Audit logs No Limited Yes
Data retention controls No No Configurable
Priority support and SLAs No No Yes

‍

Worth a Read: https://www.cloudeagle.ai/blogs/how-enterprises-can-track-claude-cursor-and-gemini-spend-in-one-place

‍

2. What Does Anthropic Secure, and What Does Your Team Still Own?

Based on Anthropic's Claude for Work model, security splits cleanly between what Anthropic secures (infrastructure) and what your team owns (data and inputs).

What Built-In Protections Does Claude Have?

Anthropic has invested significantly in infrastructure-level security.

  • AES-256 encryption at rest and TLS 1.3 in transit.
  • SOC 2 Type II and ISO 27001:2022 certification, plus ISO/IEC 42001:2023 for AI management systems (Anthropic's own certification list).
  • No training on enterprise customer data by default on paid plans.
  • Anthropic Safety Level 3 (ASL-3) protocols for high-capability model deployment.
  • A bug bounty program and regular penetration testing.
  • 24/7 security monitoring and incident response.

Where Does Anthropic's Responsibility End, and Your Governance Gap Begin?

Anthropic secures the platform. Everything else is your team's responsibility:

  • What data employees type or paste into Claude prompts.
  • Which MCP servers and integrations are connected to Claude Code.
  • Whether personal API keys are in use across your developer team.
  • Which repositories developers are cloning and running Claude Code against.
  • Whether Claude.ai accounts are managed or personal. The Claude AI Licenses guide explains how unmanaged personal accounts create both governance and cost problems.
  • How Claude access is provisioned, reviewed, and revoked as your team changes.

‍

3. What Are the Real Claude Security Risks Organizations Underestimate?

What Was the Claudy Day Vulnerability, and What Did It Expose?

In March 2026, Oasis Security disclosed Claudy Day, a chain of three vulnerabilities in Claude.ai that enabled silent data exfiltration.

How the attack worked

  • Hidden HTML instructions embedded in a Claude URL parameter that pre-fills the chat box.
  • Delivered via spoofed links, including through Google Ads, posing as legitimate URLs.
  • Claude processed both the visible and the hidden prompt instructions.
  • Sensitive data (chat history, financials, strategy) was extracted and exfiltrated via the Files API.

Why it matters

  • No integrations, tools, or MCP servers required.
  • Worked in a default Claude session.
  • Prompt integrity breaks if the delivery channel is compromised.

Oasis Security reported the findings through Anthropic's Responsible Disclosure Program before publishing. Anthropic has patched the prompt injection flaw; the related open-redirect and Files API issues were still being addressed as of the disclosure.

How Did Claude Code Become an Attack Surface via CVE-2025-59536 and CVE-2026-21852?

In February 2026, Check Point Research disclosed two related flaws in Claude Code's project-load and trust-dialog logic.

  • CVE-2025-59536 (CVSS 8.7, High): a bug in the startup trust dialog let a specially crafted repository execute shell commands the moment it was opened in Claude Code, before the user ever approved the trust prompt.
  • CVE-2026-21852 (CVSS 5.3–7.5 depending on scoring version): a separate logic flaw let a malicious repository set a manipulated ANTHROPIC_BASE_URL, redirecting API requests, including the user's Anthropic API key, to an attacker-controlled server before the trust prompt appeared.

Both are fixed in Claude Code 2.0.65 and later. Anthropic's advisories are public: GHSA-4fgq-fpq9-mr3g and GHSA-jh7p-qr78-84p7.

What was at stake

  • Full machine compromise from simply opening an untrusted repository.
  • Anthropic API key theft.
  • Potential access to shared workspace data across teams.

How Did GTG-1002 Weaponize Claude Code for Autonomous Cyberattacks?

In November 2025, Anthropic disclosed that it had detected and disrupted a campaign by a threat actor it designated GTG-1002, assessed with high confidence to be Chinese state-sponsored, marking one of the first documented AI-orchestrated cyber-espionage operations at scale.

How it operated

  • Multiple Claude Code instances, coordinated via MCP, were tasked to operate as autonomous penetration-testing agents.
  • The operation targeted roughly 30 organizations across tech, finance, chemical manufacturing, and government.
  • The attackers used role-play framing, posing the work as legitimate security testing, to get Claude to execute tasks it would otherwise decline.

Outcome

  • Anthropic assessed that the AI executed 80-90% of tactical operations independently, with humans intervening at only a handful of decision points per target.
  • A small number of intrusions succeeded before the campaign was detected and disrupted; accounts were banned and detections improved.

Why it matters

  • It's real-world evidence of agentic AI carrying out most of an attack with minimal human involvement.
  • It establishes AI agents as a viable, enterprise-scale threat vector, not just a theoretical one.

‍

4. What Are the Claude Security Best Practices for Enterprise Teams?

Implementing Claude in the enterprise takes a defense-in-depth approach across identity, data, and agentic features like Claude Code: SSO, granular permissions, and sandboxed tools, to prevent unauthorized access and data leakage.

These six practices are what actually make Claude safe to use at enterprise scale, not just at the individual level.

1. Enforce Least Privilege Before Enabling Claude Code or API Access

  • Audit what each developer's account can access in your environment.
  • Restrict Claude Code from running in directories containing production secrets or sensitive data.
  • Use separate API keys per developer rather than shared team keys.
  • Rotate API keys regularly and monitor for anomalous usage.

2. Audit and Govern Every MCP Server and Third-Party Integration Connected to Claude

  • Maintain an approved list of MCP servers and integrations.
  • Review .mcp.json and .claude/settings.json files before opening any cloned repository in Claude Code.
  • Never open repositories from untrusted sources in Claude Code without reviewing configuration files first.
  • Apply least privilege to every MCP connection scope.

3. Apply DLP Controls to Prevent Sensitive Data in Prompts

  • Define clear categories of data that must not enter Claude prompts: PII, source code with credentials, legal documents, and financial forecasts.
  • Use DLP tools that can scan prompt content before submission, where possible.
  • Train employees on what not to put into Claude, with specific examples relevant to your industry.

4. Treat Claude Code Like a Privileged User, Not a Productivity Tool

  • Require IT approval before Claude Code is installed on developer machines.
  • Restrict Claude Code from accessing production environments or credential stores.
  • Apply the same security controls to Claude Code sessions that you apply to privileged shell access.

5. Log All Claude Activity and Establish a Human Review Loop for Agentic Tasks

  • Enable audit logging for all Claude API usage and Claude.ai Enterprise accounts.
  • Integrate Claude logs into your SIEM.
  • Require human approval for Claude Code actions that involve file deletion, network requests, or credential access.
  • Review logs regularly for anomalous patterns.

6. Define an Acceptable Use Policy Covering What Employees Can and Cannot Input

  • Specify prohibited data categories for Claude prompts.
  • Define approved Claude tiers and account types.
  • Establish a process for reporting accidental sensitive data submission.
  • Build acknowledgment into onboarding for any employee who uses Claude for work.

‍

5. How CloudEagle.ai Helps You Govern Claude Access, Usage, and Spend Across Your Organization?

Native controls from Microsoft and Anthropic primarily govern approved accounts. They may not provide visibility into personal Claude.ai usage, unmanaged Claude Code installations, or how AI activity connects with broader SaaS governance and compliance processes.

CloudEagle.ai brings Claude and other AI applications into a broader SaaS security, AI governance, and identity governance framework, giving security and IT teams visibility into access, usage, spend, and compliance across human and non-human identities.

AI Governance

CloudEagle.ai brings Claude into a broader AI governance framework, giving security and IT teams visibility into AI usage, access, and policy compliance across the organization.

‍

‍

  • Identify approved and unapproved AI tools across the environment.
  • Apply governance policies to Claude and other AI applications.
  • Monitor AI usage across human and non-human identities.
  • Connect AI governance activities with broader security and compliance requirements.

Shadow AI Discovery

CloudEagle.ai helps identify AI tools being used across the environment, including:

‍

‍

  • Personal Claude accounts used outside managed environments.
  • Unsanctioned Claude Code installations across developer devices.
  • AI usage patterns detected through SSO, browser activity, and financial signals.

This gives security teams greater visibility into shadow AI before it creates security or compliance concerns.

Access Governance

Claude access can be managed through structured identity and access workflows:

‍

‍

  • Provision access based on role and business need.
  • Conduct periodic access reviews to identify unnecessary permissions.
  • Revoke access when employees change roles or leave the organization.

This extends SaaS access governance to Claude and other AI applications.

‍

"Once AI adoption accelerated across teams, visibility alone wasn't enough. We needed clear rules around who could use AI tools, under what conditions, and how those decisions were enforced and reviewed. CloudEagle helped us move from ad-hoc approvals to structured, defensible AI governance."
— Aditya Khosla, CTO, Iterative Health

‍

AI Usage and Spend Visibility

CloudEagle.ai helps organizations understand how approved AI tools are being used, not just which tools are in the environment:

‍

‍

  • Track token consumption: Monitor token usage across teams, users, and projects.
  • Analyze model usage: See which models are being used and where consumption is concentrated.
  • Set budgets and spend limits: Establish controls around AI spending and identify usage that exceeds defined thresholds.
  • Connect usage to spend: Attribute AI consumption to the appropriate teams, users, or projects to understand where costs are coming from.
  • Assess usage against ROI: Identify high-cost usage patterns and evaluate whether AI spend is delivering sufficient business value.

‍

‍

6. How Secure Is Claude AI? A Quick Decision Framework

Claude AI is generally safe for low-stakes use and is built with safeguards like Constitutional AI.

Features like Computer Use and Claude Code can still introduce risk if they access local files or execute commands without proper controls, which is why the controls above matter more as usage gets more agentic.

What Questions Should You Answer Before Enabling Claude Enterprise-Wide?

  • Are all Claude accounts tied to corporate SSO, or are personal accounts in use? If SSO isn't standardized yet, our guide to the best single sign-on tools is a place to start.
  • Do you have an inventory of every MCP server connected to Claude Code across your developer fleet?
  • Are Claude API keys individual or shared, and when were they last rotated?
  • Have you mapped Claude data flows into your SOC 2, GDPR, and HIPAA compliance scopes? If not, our ITGC audit guide covers the control areas that typically map to those requirements.
  • Do you have audit logging enabled and flowing into your SIEM?
  • Is there a human review checkpoint for any agentic Claude workflow?

When Should You Layer Third-Party Governance Tools on Top of Anthropic's Native Controls?

‍

Scenario Recommended Approach
Standard enterprise Claude.ai usage with managed accounts Enterprise plan with SSO, audit logging, and an acceptable use policy.
Developer teams using Claude Code Repository config auditing, separate API keys, and least-privilege enforcement.
Multi-AI environment with shadow Claude usage CloudEagle.ai for cross-stack discovery and governance.
High-sensitivity regulated data Restrict Claude access to non-regulated workflows, or deploy via API with strict scoping.

‍

7. How Do You Keep Claude Secure as It Scales Across Your Enterprise?

At the infrastructure level, Anthropic has built strong protections into Claude, including encryption, enterprise data controls, and secure platform design. For most organizations, the foundation itself isn't the primary concern.

The real risks show up in how Claude is used across the enterprise. From MCP configurations and personal Claude.ai accounts to agentic workflows like Claude Code, sensitive data and high-privilege access can quickly move outside traditional security boundaries.

Incidents like Claudy Day, CVE-2025-59536, and GTG-1002 make one thing clear: AI is now an active attack surface, not a theoretical one. CloudEagle.ai helps you stay ahead by providing the visibility and governance needed to manage Claude securely across your entire environment.

‍

Frequently Asked Questions

  1. Is Claude Safe to Use?
    Yes, for most everyday tasks. Anthropic secures the underlying infrastructure with encryption, access controls, and independent audits. The bigger question for a business isn't whether Claude itself is safe, but whether your employees are using managed, governed accounts instead of personal ones with no oversight.
  2. Is Claude Secure Enough for Enterprise Use?
    At the infrastructure level, yes: SOC 2 Type II, ISO 27001, and ISO/IEC 42001 certifications back that up. Whether it's secure enough for your enterprise specifically depends on the governance you add on top: SSO, DLP at the prompt layer, MCP and connector auditing, and continuous monitoring.
  3. How Safe Is Claude Compared to Other AI Tools?
    Claude, ChatGPT, and Gemini all publish similar infrastructure-level certifications (SOC 2, ISO 27001) at their enterprise tiers, and all three face the same real-world risk: employees using personal accounts and pasting sensitive data into prompts outside IT visibility. The safety difference between tools matters less than whether you're governing whichever ones your teams have already adopted.
  4. How Does CloudEagle.ai Detect Personal Claude.ai Accounts Used Outside Managed Environments?
    CloudEagle.ai identifies shadow Claude usage by cross-referencing SSO data, browser-based activity signals, and financial transaction records for personal subscription charges. This gives IT teams a complete picture of Claude access across the organization, including accounts that were never provisioned through official channels.
  5. Can CloudEagle.ai Integrate Claude's Audit Logs Into a Broader SIEM or Compliance Reporting Workflow?
    Yes. CloudEagle.ai connects Claude API and usage data to your existing compliance stack, so Claude activity feeds into the same reporting workflows you use for the rest of your SaaS portfolio, rather than requiring a separate governance stream.

‍

CloudEagle.ai recognized in the 2025 Gartner® Magic Quadrant™ for SaaS Management Platforms
Download now
gartner chart
5x
Faster employee
onboarding
80%
Reduction in time for
user access reviews
30k
Workflows
automated
$15Bn
Analyzed in
contract spend
$2Bn
Saved in
SaaS spend

Streamline SaaS governance and save 10-30%

Book a Demo with Expert
CTA image