Vannus has not established which model this vendor runs, and does not infer one. Every finding below is quoted to the vendor’s own document, or marked not disclosed where the vendor publishes nothing.
Anthropic's AI assistant known for long-context, safety, and nuanced reasoning
Claude Opus 4.8 was trained on data up until January 2026.
Applies to: Claude for Work (Team and Enterprise), Anthropic API / Claude Platform, Claude Gov; Enterprise plan for custom retention; API + Claude Code for Enterprise for ZDR
From the privacy centre article (Commercial Customers collection) + Commercial Terms of Service: “By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models.” privacy.claude.com ↗
Training and retention posture varies by plan. The default-plan row above describes the vendor’s free or standard tier; the paid-plan row is quoted from the document linked beside it. A negotiated contract can override either. Check your own agreement before relying on this.
This is a separate question from the grade above. The grade measures resilience — whether the tool endures and whether you could leave it. This describes who controls the vendor. A tool can score modestly on one and strongly on the other, and many do.
On U.S. CLOUD Act reach specifically: the statute reaches a provider subject to U.S. jurisdiction over data in its possession, custody or control. Corporate control is a strong indicator of that and it is what we can evidence from published documents — but it is not the whole test. A company founded outside the U.S. can still contract through a U.S. entity or run substantial U.S. operations. Treat this as a starting point for your own review, not a legal determination, and take advice on anything that matters.
The vendor's published or catalog-recorded posture — the concrete facts this grade is built from. A full audit verifies each against the vendor's current documentation.
Taken from the vendor’s own published material. Vannus does not hold these reports and has not reviewed their scope or dates — ask the vendor for the current report before relying on any of them.
Vannus publishes a nine-dimension trust framework — data sovereignty, training privacy, compliance posture, operational resilience, exit portability, and more. The heaviest criterion asks whether the tool builds its own AI or resells someone else's model; where the vendor discloses it, the grade cites the vendor's own documentation. No paid placements — scoring is walled off from affiliate revenue. See the methodology →