Legal and compliance
Legal agreements, compliance certifications, and security information for Claude Code.
Legal agreements
License
Claude Code is provided under Anthropic’s Commercial Terms of Service.
Commercial agreements
Whether you’re using Anthropic’s API directly (1P) or accessing it through AWS Bedrock or Google Vertex (3P), your existing commercial agreement will apply to Claude Code usage, unless we’ve mutually agreed otherwise.
Compliance
Healthcare compliance (BAA)
If a customer has a Business Associate Agreement (BAA) with us, and wants to use Claude Code, the BAA will automatically extend to cover Claude Code if the customer has executed a BAA and has Zero Data Retention (ZDR) activated. The BAA will be applicable to that customer’s API traffic flowing through Claude Code.
Security and trust
Trust and safety
You can find more information in the Anthropic Trust Center and Transparency Hub.
Security vulnerability reporting
Anthropic manages our security program through HackerOne. Use this form to report vulnerabilities.
© Anthropic PBC. All rights reserved. Use is subject to Anthropic’s Commercial Terms of Service.