OPERATING STANDARD
Is Claude Safe for CRE Data? Depends Which Claude You Bought.
Where does the data go? Every CRE firm evaluating Claude asks it, and for regulated managers it is the question that decides the purchase. The answer depends entirely on which Claude: the consumer plans and the commercial products run under different terms, with different training defaults and different retention. Here is the record as Anthropic publishes it, organized the way a compliance review actually proceeds.
Direct answer
Direct answer to is Claude safe for business data
For firm work, use Claude under commercial terms: Claude for Work (Team and Enterprise), or the API. Anthropic states that commercial customers’ prompts, data, and results are not used to train its models by default, and the September 2025 consumer-terms change that introduced a five-year retention option for users who opt into training explicitly does not apply to commercial products. Claude Enterprise adds SSO, SCIM, audit logs, and data retention controls; the API offers zero data retention arrangements for qualifying customers. What Anthropic cannot do for a firm: classify its data, trim its permissions, or review its vendor terms. Those stay in-house.

The direct answer: which Claude are you asking about?
The single most load-bearing fact in a Claude security review is that Anthropic runs two regimes. Consumer plans, Free, Pro, and Max, including Claude Code used from those accounts, operate under consumer terms, and since a September 2025 update those users choose whether their chats may be used to improve models, with data retention extending to five years for those who allow it and remaining thirty days for those who do not. Commercial products are the other regime, and Anthropic’s update announcing the consumer change states plainly that it does not apply to services under its commercial terms, naming Claude for Work, which includes the Team and Enterprise plans, the API, Amazon Bedrock, Google Cloud’s Vertex AI, and the government and education products.
For the commercial regime, Anthropic’s enterprise materials state the default that matters to a compliance reviewer: your prompts, data, and results are not used to train Anthropic’s models by default. Its API documentation goes further for retained operational data, stating that retained data is never used for model training without express permission, and that zero data retention arrangements are available for qualifying API customers, under which inputs and outputs are not stored beyond abuse screening. The practical consequence for a CRE firm is blunt: an employee pasting a rent roll into a personal Pro account and a team working inside a Claude Enterprise workspace are in different legal and technical postures, and a firm that has not made the distinction organizationally has made it accidentally.
The commercial tiers, read as a compliance reviewer
The table below organizes what Anthropic publishes as of August 16, 2026. The pattern to notice is that the controls a regulated manager needs concentrate at the top: Claude Enterprise carries single sign-on and SAML, domain capture, SCIM provisioning, role-based access control, audit logs, and data retention controls, and Anthropic lists SOC 2, ISO 27001, GDPR and CCPA compliance across the platform with a HIPAA-ready offering. A firm under SEC examination or investor side-letter obligations should treat those features not as luxuries but as the mechanism by which the firm can answer, in writing, who accessed what and when.
Two verification habits keep the review honest. First, check the primary pages at review time rather than relying on any summary, this article included: vendor terms move, and Anthropic maintains a trust center precisely so reviewers can pull current documents. Second, distinguish what the vendor controls from what the firm controls. Anthropic’s terms govern training and retention on its side. They do nothing about which employees can reach investor social security numbers, whether the diligence folder is overshared, or whether a departing analyst’s access was revoked. In PSV’s experience the sharpest data concerns CRE principals raise, investor PII, wiring details, LP correspondence, are governed almost entirely by the firm’s own permissioning, and connecting any AI tool simply inherits it.
| Path | Training on your data | Retention | Controls |
|---|---|---|---|
| Consumer Free / Pro / Max | User’s choice; opting in permits training | Five years if opted in, thirty days if not | Personal account settings only; no firm visibility |
| Claude for Work: Team | Not used for training by default, per commercial terms | Standard commercial retention | Workspace administration, central billing |
| Claude for Work: Enterprise | Not used for training by default, per commercial terms | Data retention controls available | SSO and SAML, domain capture, SCIM, role-based access, audit logs |
| Claude API, including cloud platforms | Not used to train without express permission | Minimal by design; zero data retention available for qualifying customers | Firm’s own application layer; compliance API and usage controls |
The workflow PSV would run for the approval
Treat the Claude decision as a standard vendor review with one addition, and sequence it. First, classification: a one-page inventory of what the firm considers restricted, investor PII, banking and wiring detail, LP agreements, anything under NDA, and where it lives. Second, the plan decision: commercial terms for anything touching firm data, which in practice means Team at minimum and Enterprise where SSO, audit logs, and retention controls are required, with the consumer-account boundary written into policy so the personal-Pro-account posture cannot happen innocently. Third, permissioning: the restricted inventory becomes unreachable by ordinary seats before any AI connects, per the same least-privilege sequence PSV recommends for the Yardi connector. Fourth, the paper: pull the current terms, the trust center documents, and the data processing agreement, and file them with the review.
The addition specific to AI is an interrogation habit for outputs rather than inputs. The reviewer who signs the vendor approval should also name where AI-derived work products may go: a variance memo drafted with Claude can circulate internally, but nothing AI-derived reaches an LP, a lender, or a counterparty without a named person’s sign-off, which is the same approval gate PSV attaches to every production workflow. The output gate is not an Anthropic control and no vendor can sell it. It is the firm’s own operating standard, and it is what turns a safe tool into a safe practice.
What stays human, and the open questions worth tracking
The operator read
Finish with the judgment call.
The reported facts are above. Enter your email for PSV's operator conclusion and a year of access to every newsroom brief.
Free. No card. Privacy policy. Unsubscribe anytime.
by PSVLiveBuild the workflow behind this analysis. Train with the operators doing it.
Real deal files, live builds, and production-ready CRE AI workflows inside the CRE AI Institute.
Clear answers
Common questions about is Claude safe for business data
Does Anthropic train Claude on business data?
Not by default under commercial terms. Anthropic’s enterprise materials state that commercial customers’ prompts, data, and results are not used to train its models by default, and its API documentation states that retained data is never used for model training without express permission. The September 2025 consumer terms update, which introduced a training choice and a five-year retention period for consumer users who opt in, explicitly does not apply to commercial products: Anthropic’s announcement names Claude for Work including Team and Enterprise, the API, Amazon Bedrock, Google Cloud’s Vertex AI, and its government and education products as excluded. The load-bearing distinction for any firm is consumer account versus commercial workspace, and policy should make that boundary explicit.
What security features does Claude Enterprise provide?
Per Anthropic’s published materials as of August 2026: single sign-on and SAML, domain capture, SCIM provisioning, role-based access control, audit logs, usage analytics, spend controls, and data retention controls, which Anthropic notes are available on the Enterprise tier. Across the platform Anthropic lists SOC 2, ISO 27001, GDPR and CCPA compliance, a compliance API, and a HIPAA-ready offering, with a trust center for pulling current documents. For API customers, zero data retention arrangements are available for qualifying accounts, under which inputs and outputs are not stored beyond abuse screening. For a regulated manager these are the mechanisms for answering, in writing, who accessed what and when.
How should a CRE firm run a Claude compliance review?
As a standard vendor review, sequenced, with one AI-specific addition. First, classify: a one-page inventory of restricted data, investor PII, wiring detail, LP agreements, and where it lives. Second, choose the plan: commercial terms for anything touching firm data, Enterprise where SSO, audit logs, and retention controls are required, with the consumer-account boundary written into policy. Third, permission: make the restricted inventory unreachable by ordinary seats before any AI connects. Fourth, file the paper: current terms, trust center documents, and the data processing agreement. The AI-specific addition is an output gate: nothing AI-derived reaches an LP, lender, or counterparty without a named person’s sign-off. Re-pull the terms annually and at renewal, because vendor terms evolve.
Can I upload confidential deal documents to Claude?
Only if the documents’ own terms allow it, and then only under commercial terms: a confidentiality agreement, loan documents or a data license decide first, and the Claude plan decides second. Anthropic’s Enterprise page, read September 24, 2026, says prompts, data and results are not used to train its models by default, and lists SSO, SCIM, audit logs and custom data retention, with retention controls on Enterprise only. Anthropic’s consumer terms update, which lets Free, Pro and Max users allow training with five-year retention, expressly does not apply to Team, Enterprise or the API, and its API documentation says retained data is never used for training without express permission. So use a Team or Enterprise workspace or the API, never a personal account. The documents’ own terms can forbid the upload whatever Anthropic’s policy says: a confidentiality agreement, a lender’s confidentiality clause or a data license. Keep investor personal data and wiring details out unless the compliance review has cleared them.
Can I put an OM I received under a confidentiality agreement into Claude or ChatGPT?
Read the confidentiality agreement first, because it decides the question before any AI vendor’s policy does. Check three things: the permitted-use clause (for example, use solely to evaluate the transaction), who may receive the material (often a defined list of Representatives), and anything on outside service providers, storage, or return and destruction of materials. If an AI provider does not fit those words, uploading the OM may breach the agreement however good the provider’s data terms are. If it does fit, the plan matters next: Anthropic’s consumer plans let users allow training with five-year retention, while its commercial terms for Team, Enterprise and the API are excluded from that change, and Anthropic says commercial data is not used for training by default. For ChatGPT, read OpenAI’s current terms for the plan in use; this article covers Anthropic’s published record only. When the agreement is silent or unclear, ask the broker or counsel before uploading. This is general information, not legal advice.
Primary sources and operating references
These references support the control, research, and operating standards used in this guide. PSV’s workflow recommendations are original analysis.
- Anthropic: Updates to Consumer Terms and Privacy Policy, including the products excluded from the change (2025)
- Claude Enterprise: security, administration, and compliance features
- Claude Platform documentation: API and data retention, including zero data retention
- Wikimedia Commons: Racked servers in a data center, by Victor Grigas, CC BY-SA 3.0 (source of the lead photograph)
Topics
Related PSV analysis
CRE PROPTECH NEWS
Claude Talks to Yardi Now. Most Operators Haven’t Caught Up.
Does Claude integrate with Yardi? It is one of the most common questions in PSV client scoping calls and Institute office hours, and the answer changed while most of the industry was not looking. Yardi announced Virtuoso Connectors in September 2025, and by June 2026 it had published two MCP connectors on Anthropic’s marketplace: live Yardi operational data and Yardi Matrix market data, both readable from inside Claude.
CRE AI ADOPTION
Why Claude and Copilot Pilots Flop in CRE. It’s Never the Model.
How should a CRE firm structure SharePoint or Drive so Claude, Copilot, or any AI tool can actually use it? Multiple operating teams have put the same question to PSV in almost the same words, usually after a pilot underperformed and the tool took the blame. The uncomfortable finding is that the AI was fine and the files were the problem: five versions of the rent roll, three naming conventions, and the real number in someone’s inbox.
AI TOOL SELECTION
Can You Put a CoStar Export Into Claude or ChatGPT? Read the July 2026 Clause First
Can you upload a CoStar export to Claude or ChatGPT, paste comps into a chat, or connect CoStar through an MCP server? CoStar revised its Terms of Use and its License Agreement Terms and Conditions on July 6, 2026, and both now address AI directly. Here is what the clauses say, which version binds your firm, and the AI work that stays clearly allowed.
Related guides
Cornerstone PSV guides on the workflows in this article.
Claude vs ChatGPT for CRE
An operator's comparison of Claude and ChatGPT for commercial real estate underwriting, and why the grounded setup matters more than the model brand.
Read the guideThe CRE AI Data & Security Audit
The five-pass audit a CRE firm runs on its own document estate before connecting an assistant: folder access, document provenance, and the approval bands.
Read the guideCRE AI Training
Hands-on CRE AI training for practicing operators, routing into the CRE AI Institute. No coding required, built on a real practice deal.
Read the guide
by PSVLiveYou read the operator view. Now learn to run the workflow.
The AI MBA for commercial real estate: the workflows these briefs describe, taught end to end on real deal files, with live builds and a community of CRE operators.





