Anthropic routes its authorized paths through AWS and Google Cloud

On Anthropic's own government page the authorizations are stated as available on AWS and Google Cloud, up to FedRAMP High and IL5 — not as authorizations held by the direct commercial API. Treat the hosting boundary, not the model, as the thing that is authorized.

Commercial multi-tenant SaaS

Is Claude (Claude.ai, Claude for Work and the Anthropic API) safe for CUI?

by Anthropic

As of July 27, 2026. FedRAMP authorizations, DoD Impact Level approvals and vendor data-handling terms change. Every finding below links to the primary source it came from — open it and confirm the current status before you make a boundary decision.

What this verdict rests on

The 2 sources the finding above is drawn from, quoted so you can check the reading rather than take our word for it.

Primary source

Available on AWS and Google Cloud with authorizations up to FedRAMP High and IL5 ... Claude in Amazon Bedrock: Approved for use in FedRAMP High and DoD IL4/5 workloads

AnthropicClaude for government — deployment options and authorizations · read 2026-07-27

Primary source

If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.

Acquisition.gov (DFARS, MAY 2024 revision)DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27

FedRAMP

Not established for the direct commercial API

DoD Impact Level

Not established for the direct commercial API

Deployment pattern

Commercial multi-tenant SaaS

Overview

Claude reaches defence contractors three ways — the Claude.ai apps, Claude for Work, and the Anthropic API called from an internal tool. Anthropic's own government materials describe the compliance story as an availability story on someone else's authorized infrastructure, which is the right way to read it: what carries the authorization is where the inference runs.

Where does the data physically go?

The first question in any CUI boundary decision is not whether a product is secure — it is which system boundary the data lands in, and whose authorization covers that boundary.

Data location

Not established. We could not establish, from a primary source we read, where prompts to the direct commercial Anthropic API are processed or what data-residency options exist. Anthropic's trust portal is client-rendered and did not yield readable content. Verify with Anthropic for your contract.

Model training and retention

Anthropic states that by default it does not use inputs or outputs from its commercial products — Claude for Work, the Anthropic API and Claude Gov are the examples given — to train its models. As everywhere on this page, that is a separate question from which authorization boundary the data sits in.

Primary source

By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models.

Anthropic Privacy CenterIs my data used for model training? · read 2026-07-27

What authorization exists?

A platform-level authorization does not automatically extend to every service running on it. What matters is whether this specific AI service is named in the authorization scope.

FedRAMP authorization

Anthropic publishes its government availability as running on other providers' authorizations: available on AWS and Google Cloud with authorizations up to FedRAMP High and IL5, with Claude in Amazon Bedrock described as approved for use in FedRAMP High and DoD IL4/5 workloads. We did not establish a FedRAMP authorization held by Anthropic for the direct commercial API; check the registry yourself before relying on that either way.

Primary source

Available on AWS and Google Cloud with authorizations up to FedRAMP High and IL5 ... Claude in Amazon Bedrock: Approved for use in FedRAMP High and DoD IL4/5 workloads

AnthropicClaude for government — deployment options and authorizations · read 2026-07-27

DoD Impact Level

The Impact Levels Anthropic cites are attached to the hosting platforms, not to the direct API. On the same page Anthropic labels its own Claude for Government application at IL5 as in pilot rather than available.

Primary source

Available on AWS and Google Cloud with authorizations up to FedRAMP High and IL5 ... Claude in Amazon Bedrock: Approved for use in FedRAMP High and DoD IL4/5 workloads

AnthropicClaude for government — deployment options and authorizations · read 2026-07-27

Vendor's own position on CUI

Not established. Anthropic's government page makes no statement about CUI, DFARS 252.204-7012 or ITAR — none of those terms appear on it. We therefore make no claim about Anthropic's CUI position; verify in writing with the vendor.

What DFARS 252.204-7012 and NIST 800-171 require of this pattern

Quoted from the regulation itself, not paraphrased.

DFARS 252.204-7012(b)(2)(ii)(D) — the external cloud service provider test

This is the paragraph that decides most AI questions. The moment an external cloud service provider stores, processes or transmits covered defense information, the contractor must require and ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline — and that it complies with the clause's incident reporting, malicious software, media preservation, forensic access and damage assessment paragraphs. A commercial AI endpoint is an external cloud service provider. The obligation to ensure equivalency sits on the contractor, not the vendor.

Primary source

If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.

Acquisition.gov (DFARS, MAY 2024 revision)DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27

NIST SP 800-171 — the control set itself

The security requirements DFARS 7012 imports. Rev. 3 (May 2024) is the current final publication; which revision binds a given contract is set by the solicitation, so check the clause in your award rather than assuming. For an AI deployment the load-bearing families are access control, audit and accountability, and system and communications protection — an assistant that reaches CUI must be inside the same access, logging and boundary-protection regime as any other system that touches it.

Primary source

This publication provides federal agencies with recommended security requirements for protecting the confidentiality of CUI when the information is resident in nonfederal systems and organizations.

NIST Computer Security Resource CenterNIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations · read 2026-07-27

NIST 800-171 controls this decision turns on

These are the controls an assessor works through when CUI reaches an AI service. They are the controls at stake, not a finding against the vendor.

The compliant pattern

Use the same model through a boundary that is already authorized rather than through the direct commercial endpoint: Claude in Amazon Bedrock inside AWS GovCloud (US), which AWS records as FedRAMP High authorized and Anthropic describes as approved for FedRAMP High and DoD IL4/5 workloads, or Claude on Google Cloud inside an Assured Workloads folder. The model is the same; the authorization boundary is the entire difference, and it is the boundary your assessor will ask about.

Patterns with an authorized path for CUI

Sources for this page

Every finding above rests on one of these. Nothing on this page is asserted without one.

  1. AnthropicClaude for government — deployment options and authorizations · read 2026-07-27
  2. Acquisition.gov (DFARS, MAY 2024 revision)DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
  3. Anthropic Privacy CenterIs my data used for model training? · read 2026-07-27

Authorization records move and this page does not. Search the FedRAMP Marketplace for the current record set before you rely on anything above.

Frequently Asked Questions

Is Claude FedRAMP authorized?

Anthropic publishes its government availability through AWS and Google Cloud, with authorizations up to FedRAMP High and IL5, and describes Claude in Amazon Bedrock as approved for FedRAMP High and DoD IL4/5 workloads. We did not establish an Anthropic-held authorization covering the direct commercial API — a different question with a different answer.

Does Anthropic train on my prompts?

Anthropic states that by default it will not use inputs or outputs from its commercial products — Claude for Work, the Anthropic API and Claude Gov — to train its models. That is a data-use commitment, not an authorization, and DFARS 252.204-7012 asks about the latter.

What is the compliant way to use Claude on CUI work?

Run it inside a boundary that already holds the authorization — Amazon Bedrock in AWS GovCloud (US), or Google Cloud under Assured Workloads — and document that boundary in your SSP rather than documenting "Claude".

Your AI tools are one row in the boundary

Audit the rest of the stack — storage, email, collaboration — against the same FedRAMP test.

Launch CUI Auditor

The tool-by-tool question does not end at one tool

This Claude (Claude.ai, Claude for Work and the Anthropic API) CUI review settles one boundary decision. AI Integration Assessment settles the whole question: a sequenced build plan with rough-order-of-magnitude costs and a route to a fixed price, plus the four things that decide whether it can start on time — who can get access and how long that takes, who is allowed to approve what, whether your records can carry an automated process, and where the system is allowed to run, boundary drawn against DFARS 252.204-7012(b)(2)(ii)(D). $12,500, fixed scope, fixed price, 4–6 weeks, exclusions published. Credits in full against an implementation engagement.

See the assessment

Related: how much CMMC certification costs — DoD’s own priced figures