01Trust Score

Claude Code

conditional_proceed

Week 2026-W22 May 25, 2026 Vendor-Neutral
60 /100 Mixed Signals
3.4/5 (5423)
↓ PDF Report
Trust Score 60/100 CONDITIONAL
Est. Annual Cost See TCO ↓
Top Risk HIGH Reliability Overall: Medium
Priority Action Critical Security Vulnerability: Sandbox Escape ↓ PDF  · TCO  · Hardening
Enterprise: DPA: Unknown · Residency: Unknown · Lock-in: Medium (50/100)

Verified Compliance Facts

Cited and timestamped — every claim traceable to an official vendor source.

GDPR
✓ Verified
Source ↗ Checked: May 25, 2026 ✓ Verified
HIPAA
Not yet verified
No citation Checked: May 25, 2026 ⏳ Claimed
ISO/IEC 27001
✓ Verified
Source ↗ Checked: May 25, 2026 ✓ Verified
SOC 2
✓ Verified
Source ↗ Checked: May 25, 2026 ✓ Verified

Enterprise Verdict

! Conditional Approval
Risk: Medium Confidence: medium 50 sources

conditional_proceed

Priority Action

Critical Security Vulnerability: Sandbox Escape

Live Signals This Week

Detected by daily monitoring — captured outside the weekly scrape window.

Critical June 1, 2026

Anthropic AI Vulnerability Scanner in Enterprise Beta: IBM Joins Glasswing After 10,000 Flaws Found - Tech Times

1 signal(s) detected: vulnerability

This report updates every week. Weekly AI vendor intelligence — trust scores, contract red flags, competitive shifts.
02Top Risks

Risk Assessment

Seven-category enterprise risk analysis derived from community and vendor signals. Each card shows the evidence tier and the underlying finding.

High Reliability Community Data

Public documentation buyers may want to verify availability of specific uptime commitments or reliability history.

Medium Cost Predictability Community Data

Enterprises should negotiate fixed-rate contracts and monitor pricing changes for overage risks.

Medium Vendor Lock-in Community Data

Data export supported. Integration score: 60/100. Webhooks available, reducing lock-in risk.

Medium Support Quality Community Data

Insufficient public community reviews to verify support quality. Standard support channels (email/documentation) are assumed.

Medium Data Privacy Community Data

Compliance score: 96/100. GDPR status: unknown. Encryption at rest: unknown.

Low Compliance Posture Community Data

SOC 2: type_ii. ISO 27001: certified. Overall compliance score: 96/100.

High AI Transparency Verified

Vendor may train on user data. Users retain code/output ownership. Legal/ToS risk score: 45/100.

Verified — Confirmed by vendor documentation Community — Derived from community reports

Due Diligence Alerts

Priority reviews, recommended inquiries, and verified strengths — based on 0+ community data points

Recommended Inquiry Critical Critical Security Vulnerability: Sandbox Escape

A reported sandbox bypass vulnerability in Claude Code could allow for data exfiltration, posing a significant risk to sensitive corporate data and intellectual property. This is a recurring issue, as indicated by community reports from May 2026.

Recommended Inquiry High Source Code Leak Incident

Anthropic experienced an accidental leak of Claude Code's source code, which could expose internal workings and potential vulnerabilities to malicious actors. This incident was reported in May 2026.

Sources: Web ×2
Recommended Inquiry High Low Vendor Liability Cap for Damages

The vendor's total liability for loss or damage is capped at the greater of the amount paid in the preceding six months or €100, which is extremely low for enterprise-level engagements and could leave the customer significantly exposed to financial losses.

Sources: Web
Recommended Inquiry Medium Data Training Policy with Opt-Out Exceptions

While an opt-out for model training is available, user inputs and outputs may still be used for model improvement if flagged for safety review or explicitly reported as feedback, potentially exposing proprietary or sensitive data.

Sources: Web
Recommended Inquiry Medium Multiple Moderate Severity SDK Vulnerabilities Patched

Several moderate severity vulnerabilities, including insecure default file permissions and path validation race conditions, were identified and patched in the Claude SDKs for TypeScript and Python in April 2026. While patched, this indicates a need for continuous vigilance in SDK security.

Sources: Web ×4
03Security & Compliance

Security & Compliance

SOC 2 ✓ Type II
HIPAA Not documented
ISO 27001 ✓ Certified

External Registry Verification

Data Security

Encryption (At Rest): Not publicly specified
Encryption (In Transit): Not publicly specified

Enterprise Contract Intelligence

DPA availability, data residency, and contract risk signals for procurement teams

DPA: Unknown Residency: Unknown Lock-in: Medium (50/100)
📄 Data Processing Agreement Unknown

DPA availability for Claude Code is not publicly documented. Request a signed Data Processing Agreement directly from the vendor before contract execution — this is a contractual requirement under GDPR Article 28.

🌐 Data Residency Unknown

Data residency options for Claude Code are not publicly documented. EU-regulated buyers should request written confirmation of data storage location and applicable transfer mechanisms (SCCs/adequacy decision) before signing.

⚠️ Contract Risk Medium Lock-in (50/100)
Notice: 30 days
⚠ 1 contract risk flag — click to review
⚠ Auto-renewal terms and data export rights not publicly documented — verify before signing.

Full contract terms for Claude Code require direct vendor engagement. Ensure data portability on exit, notice period, and pricing lock clauses are negotiated before execution.

Compliance & Document Matrix

🛡️ Security Certifications

Certification Status Auditor Valid Until Source
⏳ Scanning in progress — check back after next weekly audit.

🔒 Data Privacy Documents

Document Status URL AI Assessment
Sub-processors ✅ Active Link ❌ Not found
AI/Model Training Policy ❌ Not Found — Unclear
Data Retention Policy ❌ Not Found ❌ Not found
Data Flow Diagram ❌ Not Found
GDPR Compliance Statement ❌ Not Found ❌ Not found
KVKK Compliance Statement ❌ Not Found ❌ Not found
CCPA Compliance Statement ❌ Not Found ❌ Not found

⚖️ Legal Contracts

See Legal & IP Assessment section above for full analysis of ToS, DPA, MSA, SLA, EULA, and AUP.

🔧 Operational Readiness

Document Status URL AI Assessment
Business Continuity Plan (BCP) ❌ Not Found ❌ Not found
Disaster Recovery Plan (DRP) ❌ Not Found ❌ Not found
Incident Response Plan ❌ Not Found ❌ Not found
3rd Party Penetration Test ❌ Not Found ❌ Not found

📋 Technical Transparency

Document Status URL AI Assessment
SBOM ❌ Not Found ❌ Not found
OSS License Inventory ❌ Not Found ❌ Not found
Vulnerability Management Policy ✅ Active Link ❌ Not found
Patch Management Policy ❌ Not Found ❌ Not found
Offboarding / Data Export Guide ❌ Not Found ❌ Not found
SIG Questionnaire ❌ Not Found
CAIQ ❌ Not Found

💰 Financial Resilience

Item Status Details
Cyber Liability Insurance ❌ Not Found ❌ Not mentioned
TCO Disclosed ❌ Not found Not publicly disclosed
New risk signals detected weekly. Weekly AI vendor intelligence — trust scores, contract red flags, competitive shifts.
04Community Signals

Community Intelligence

Recurring issues and curated signals from GitHub, Hacker News, Reddit, Stack Overflow, web sources, and enterprise review platforms.

Recurring Issues

Usage Limits & Cost Surprises 🟠 Community 4 mentions high → Stable

Enterprise Impact: Unpredictable operational costs, reduced productivity due to hitting limits, budget overruns.

Clearer pricing models and better in-app usage monitoring are needed to provide enterprises with predictable costs and prevent unexpected overages.

Session Management & Persistence Issues 🟠 Community 3 mentions high → Stable

Enterprise Impact: Loss of work, reduced developer productivity, integrity risks in collaborative environments, and issues with sandboxed environments.

Improve session management, worktree isolation, and sandbox path handling to ensure robust persistence and multi-session stability.

Integration & Plugin Reliability 🟠 Community 4 mentions medium → Stable

Enterprise Impact: Hindered adoption, reliance on manual workarounds, reduced ROI from integrated workflows due to inconsistent or failing integrations.

Enhance integration stability, error handling, and documentation for third-party plugins and core integrations like GitHub and OAuth.

Security Vulnerabilities 🟠 Community 2 mentions critical ↗ Worsening

Enterprise Impact: Significant data exfiltration risk, intellectual property compromise, reputational damage due to sandbox bypasses and source code leaks.

Implement more robust sandbox security, conduct regular third-party penetration testing, and improve incident response transparency and speed.

Sources: HN Web

Source Signals

05Financial Impact

Financial Impact Panel

Cost intelligence and pricing signals for enterprise procurement decisions

Pricing data from public sources — enterprise rates differ. Verify with vendor.

TCO Calculator

Pricing Not Available

Enterprise pricing information could not be obtained for this vendor. This may be due to custom/private pricing models or limited publicly available data.

Estimated Annual TCO — 100 Users ±20% confidence band

SMB / Pay-as-you-go
Pricing not disclosed
Assumptions
  • Pricing not publicly disclosed — contact vendor for quote.
Mid-market / Per-seat
Pricing not disclosed
Assumptions
  • Pricing not publicly disclosed — contact vendor for quote.
Enterprise / Provisioned
Pricing not disclosed
Assumptions
  • Pricing not publicly disclosed — contact vendor for quote.

Pricing data not available — all estimates undisclosed.

Don't evaluate blind next quarter. Weekly AI vendor intelligence — trust scores, contract red flags, competitive shifts.

Synthesized from 20+ independent public sources: developer forums & repositories, security databases, vendor disclosures, regulatory filings, and community review platforms. Not affiliated with any vendor. Corrections?

Download PDF Report

Create a free account to download the full enterprise audit PDF.

Sign up — it's free →

Already have an account? Log in