Anthropic Launches Enterprise Frontier Safeguards with Customer-Owned Data Retention
Anthropic announced Enterprise Frontier Safeguards, allowing enterprises to maintain zero data retention on provider servers by storing monitoring logs in their own cloud storage. The framework will be supported across Claude Code, Claude Enterprise, Amazon Bedrock, Google Cloud, and Microsoft Azure Foundry.

Impact: High
Why it matters
Developers in regulated environments can adopt frontier Claude models and Claude Code without sending activity logs to external vendor infrastructure.
TL;DR
- 01EFS enables Zero Data Retention compliance by keeping audit logs in customer S3/GCS/Azure buckets.
- 02Supported across developer tools including Claude Code, Bedrock, and Azure Foundry.
- 03Security alerts are routed directly to internal security teams with no Anthropic human review.
Key facts
- Supported Storage
- Amazon S3, Azure Blob Storage, Google Cloud Storage
- Target Platforms
- Claude Code, Claude Enterprise, Bedrock, GCP, Foundry
- Interim Policy
- ZDR granted on Fable 5 / 5.1 until EFS general availability
Customer-Controlled Telemetry Architecture
Anthropic announced Enterprise Frontier Safeguards (EFS), an architectural update to reconcile Zero Data Retention (ZDR) requirements with safety monitoring. Developed in collaboration with major financial institutions and cloud partners (AWS, Google Cloud, Microsoft Azure), EFS transfers data custody entirely to the enterprise.
Platform and IDE Support
EFS will be natively supported across major development surfaces and cloud platforms:
Claude Codeand Claude Enterprise- Amazon Bedrock and Claude Platform on AWS
- Google Cloud's Agent Platform
- Microsoft Azure Foundry
In-House Log Review and Key Management
Instead of Anthropic holding monitoring logs for 30 days, activity logs reside in customer-managed object storage (Amazon S3, Azure Blob, or Google Cloud Storage) encrypted with customer-managed keys. Automated systems run safety heuristics across rolling windows, and any detected anomalies are routed directly to internal enterprise security teams with no Anthropic human review involved.
✓ When to use
- Regulated enterprise teams deploying Claude Code and frontier models on private codebases.
- Organizations that mandate customer-managed encryption keys and self-hosted audit logging.
✕ When NOT to use
- Personal side projects where standard consumer API privacy terms are completely sufficient.
- Teams without dedicated cloud infrastructure or compliance obligations for data isolation.
What to do today
- Audit existing cloud storage policies (S3/Blob/GCS) to prepare bucket permissions for EFS deployment this fall.
- Verify internal incident response pipelines for ingesting automated model security flags.
Sources