Anthropic routes its authorized paths through AWS and Google Cloud
On Anthropic's own government page the authorizations are stated as available on AWS and Google Cloud, up to FedRAMP High and IL5 — not as authorizations held by the direct commercial API. Treat the hosting boundary, not the model, as the thing that is authorized.
Is Claude (Claude.ai, Claude for Work and the Anthropic API) safe for CUI?
by Anthropic
As of July 27, 2026. FedRAMP authorizations, DoD Impact Level approvals and vendor data-handling terms change. Every finding below links to the primary source it came from — open it and confirm the current status before you make a boundary decision.
What this verdict rests on
The 2 sources the finding above is drawn from, quoted so you can check the reading rather than take our word for it.
Primary source
“Available on AWS and Google Cloud with authorizations up to FedRAMP High and IL5 ... Claude in Amazon Bedrock: Approved for use in FedRAMP High and DoD IL4/5 workloads”
Anthropic — Claude for government — deployment options and authorizations · read 2026-07-27
Primary source
“If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
FedRAMP
Not established for the direct commercial API
DoD Impact Level
Not established for the direct commercial API
Deployment pattern
Commercial multi-tenant SaaS
Overview
Claude reaches defence contractors three ways — the Claude.ai apps, Claude for Work, and the Anthropic API called from an internal tool. Anthropic's own government materials describe the compliance story as an availability story on someone else's authorized infrastructure, which is the right way to read it: what carries the authorization is where the inference runs.
Where does the data physically go?
The first question in any CUI boundary decision is not whether a product is secure — it is which system boundary the data lands in, and whose authorization covers that boundary.
Data location
Not established. We could not establish, from a primary source we read, where prompts to the direct commercial Anthropic API are processed or what data-residency options exist. Anthropic's trust portal is client-rendered and did not yield readable content. Verify with Anthropic for your contract.
Model training and retention
Anthropic states that by default it does not use inputs or outputs from its commercial products — Claude for Work, the Anthropic API and Claude Gov are the examples given — to train its models. As everywhere on this page, that is a separate question from which authorization boundary the data sits in.
Primary source
“By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models.”
Anthropic Privacy Center — Is my data used for model training? · read 2026-07-27
What authorization exists?
A platform-level authorization does not automatically extend to every service running on it. What matters is whether this specific AI service is named in the authorization scope.
FedRAMP authorization
Anthropic publishes its government availability as running on other providers' authorizations: available on AWS and Google Cloud with authorizations up to FedRAMP High and IL5, with Claude in Amazon Bedrock described as approved for use in FedRAMP High and DoD IL4/5 workloads. We did not establish a FedRAMP authorization held by Anthropic for the direct commercial API; check the registry yourself before relying on that either way.
Primary source
“Available on AWS and Google Cloud with authorizations up to FedRAMP High and IL5 ... Claude in Amazon Bedrock: Approved for use in FedRAMP High and DoD IL4/5 workloads”
Anthropic — Claude for government — deployment options and authorizations · read 2026-07-27
DoD Impact Level
The Impact Levels Anthropic cites are attached to the hosting platforms, not to the direct API. On the same page Anthropic labels its own Claude for Government application at IL5 as in pilot rather than available.
Primary source
“Available on AWS and Google Cloud with authorizations up to FedRAMP High and IL5 ... Claude in Amazon Bedrock: Approved for use in FedRAMP High and DoD IL4/5 workloads”
Anthropic — Claude for government — deployment options and authorizations · read 2026-07-27
Vendor's own position on CUI
Not established. Anthropic's government page makes no statement about CUI, DFARS 252.204-7012 or ITAR — none of those terms appear on it. We therefore make no claim about Anthropic's CUI position; verify in writing with the vendor.
What DFARS 252.204-7012 and NIST 800-171 require of this pattern
Quoted from the regulation itself, not paraphrased.
DFARS 252.204-7012(b)(2)(ii)(D) — the external cloud service provider test
This is the paragraph that decides most AI questions. The moment an external cloud service provider stores, processes or transmits covered defense information, the contractor must require and ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline — and that it complies with the clause's incident reporting, malicious software, media preservation, forensic access and damage assessment paragraphs. A commercial AI endpoint is an external cloud service provider. The obligation to ensure equivalency sits on the contractor, not the vendor.
Primary source
“If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
NIST SP 800-171 — the control set itself
The security requirements DFARS 7012 imports. Rev. 3 (May 2024) is the current final publication; which revision binds a given contract is set by the solicitation, so check the clause in your award rather than assuming. For an AI deployment the load-bearing families are access control, audit and accountability, and system and communications protection — an assistant that reaches CUI must be inside the same access, logging and boundary-protection regime as any other system that touches it.
Primary source
“This publication provides federal agencies with recommended security requirements for protecting the confidentiality of CUI when the information is resident in nonfederal systems and organizations.”
NIST Computer Security Resource Center — NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations · read 2026-07-27
NIST 800-171 controls this decision turns on
These are the controls an assessor works through when CUI reaches an AI service. They are the controls at stake, not a finding against the vendor.
The compliant pattern
Use the same model through a boundary that is already authorized rather than through the direct commercial endpoint: Claude in Amazon Bedrock inside AWS GovCloud (US), which AWS records as FedRAMP High authorized and Anthropic describes as approved for FedRAMP High and DoD IL4/5 workloads, or Claude on Google Cloud inside an Assured Workloads folder. The model is the same; the authorization boundary is the entire difference, and it is the boundary your assessor will ask about.
Patterns with an authorized path for CUI
Sources for this page
Every finding above rests on one of these. Nothing on this page is asserted without one.
- Anthropic — Claude for government — deployment options and authorizations · read 2026-07-27
- Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
- Anthropic Privacy Center — Is my data used for model training? · read 2026-07-27
Authorization records move and this page does not. Search the FedRAMP Marketplace for the current record set before you rely on anything above.
Frequently Asked Questions
Is Claude FedRAMP authorized?
Anthropic publishes its government availability through AWS and Google Cloud, with authorizations up to FedRAMP High and IL5, and describes Claude in Amazon Bedrock as approved for FedRAMP High and DoD IL4/5 workloads. We did not establish an Anthropic-held authorization covering the direct commercial API — a different question with a different answer.
Does Anthropic train on my prompts?
Anthropic states that by default it will not use inputs or outputs from its commercial products — Claude for Work, the Anthropic API and Claude Gov — to train its models. That is a data-use commitment, not an authorization, and DFARS 252.204-7012 asks about the latter.
What is the compliant way to use Claude on CUI work?
Run it inside a boundary that already holds the authorization — Amazon Bedrock in AWS GovCloud (US), or Google Cloud under Assured Workloads — and document that boundary in your SSP rather than documenting "Claude".
Your AI tools are one row in the boundary
Audit the rest of the stack — storage, email, collaboration — against the same FedRAMP test.
Launch CUI AuditorThe tool-by-tool question does not end at one tool
This Claude (Claude.ai, Claude for Work and the Anthropic API) CUI review settles one boundary decision. AI Integration Assessment settles the whole question: a sequenced build plan with rough-order-of-magnitude costs and a route to a fixed price, plus the four things that decide whether it can start on time — who can get access and how long that takes, who is allowed to approve what, whether your records can carry an automated process, and where the system is allowed to run, boundary drawn against DFARS 252.204-7012(b)(2)(ii)(D). $12,500, fixed scope, fixed price, 4–6 weeks, exclusions published. Credits in full against an implementation engagement.
See the assessment