
Security and data processing by Claude and Copilot
Who are we actually entrusting our data to when using Claude and Copilot in the workplace? In the following article, we break down data retention, access, and security in both tools.
In a previous article, I described the new Claude features for Microsoft 365 users, and mentioned that I would come back separately to the topic of security. In conversations with clients who are rolling out AI assistants for everyday work, sooner or later the same question comes up: what actually happens to the data we hand over to it.
This matters not because it involves “artificial intelligence,” but because it comes down to the same things as any decision to entrust company data to an external provider: where the data is physically stored and for how long, who can access it and under what circumstances, and whose terms and legal obligations it falls under. In this article, I break down how Claude and Copilot answer these questions.
All the information in this article concerns the business versions – Claude Enterprise and Microsoft 365 Copilot for business. Free and consumer accounts work under different rules and are outside the scope of this piece.
Where do Claude and Copilot physically run?
Before we get into retention and access, it’s worth establishing something basic: running language models requires enormous computing power, so both Anthropic and Microsoft rely on large-scale cloud infrastructure. Claude runs on Amazon Web Services (AWS) and Google Cloud Platform (GCP) infrastructure – two providers that are also major investors in Anthropic. The data we send to Claude therefore ends up in these clouds.
What matters here, though, isn’t just which provider hosts the infrastructure, but also data residency – the physical location of the servers. Standard Claude Enterprise (the web app and the direct API) doesn’t offer an option to store data in the European Union – regardless of where our company is registered, the data always ends up on servers in the United States. The processing-region setting (the so-called inference geo) only accepts two values: „us” or „global” – there’s simply no „eu” option, and the workspace itself is created exclusively in the US region and can’t be changed afterward.
Copilot, on the other hand, runs entirely inside Microsoft Azure – the same ecosystem where a company already keeps its Microsoft 365 services. Specifically, Copilot processes prompts using the Azure OpenAI Service, not the publicly available OpenAI service. This is an important distinction, because Azure OpenAI doesn’t cache (store) customer content, and prompts and responses stay within the boundaries of the Microsoft 365 service, in line with Microsoft’s privacy and compliance commitments.
With Copilot, data residency works differently – it depends on where the company set up its Microsoft 365 tenant and Azure resources. If the tenant was registered in Europe, the data (including Copilot conversations) stays within the region covered by Microsoft’s EU Data Boundary and isn’t moved outside the European Union. This is a fundamental difference from Claude: Copilot’s residency is flexible and depends on the company’s configuration, while Claude’s residency is fixed to the US, regardless of where our organization uses it from.
This seemingly technical distinction – data held by an external provider versus data within one’s own Microsoft environment – forms the foundation for everything discussed below. Given that the data physically resides somewhere, the question arises: how long does it remain there?
Does Claude store data, even on the Enterprise plan?
Short answer: yes – but under completely different rules than in the free version. The key distinction here is purpose. Data isn’t stored in order to train algorithms, but so that the product works the way we expect it to.
Here’s what data retention actually looks like on the Claude for Work / Claude Enterprise plans:
- No model training: Anthropic does not train its models on prompts or files submitted by corporate users. In this respect, company data is 100% separated from algorithm development.
- Storage “inside the product” (operational retention): so that we can see our chat history after logging in and return to previous conversations, the data has to be physically stored on Anthropic’s database servers. If our organization doesn’t configure anything else, the data is kept indefinitely, until we or the organization’s administrator delete it manually. If, on the other hand, the administrator sets a custom retention policy in the admin panel (e.g., 30, 60, or 90 days), data older than the chosen period is deleted automatically.
- What happens when you click “Delete”? The conversation disappears from view immediately, and is permanently deleted from Anthropic’s backup systems and backend servers within a maximum of 30 days.
A separate policy applies to the most powerful models – the so-called Covered Models (currently the Mythos/Fable class, i.e., Claude Fable 5 and Claude Mythos 5). Queries and responses are logged for at least 30 days to automatically detect abuse (e.g., malicious code generation or hate speech) – on every platform where these models are available. If the system detects a violation of the terms of use, the data may be frozen for up to 2 years for investigation purposes.
Can you get zero data retention (ZDR)?
Yes – although usually not from within the standard Claude Enterprise web app. If a company has strict legal requirements (e.g., in healthcare or banking), Zero Data Retention (ZDR) can be achieved in two ways, which I’ll only touch on briefly without going into detail.
-
Via the API: using direct developer access (the Anthropic API). Since September 14, 2025, the default API log retention period is 7 days (it can be extended to 30 days via a DPA addendum), and qualified customers can negotiate full ZDR, where data disappears from server memory as soon as the response is generated.
-
Partner clouds: Claude models can be run inside your own Amazon Bedrock or Google Vertex AI environment. In that case, the data doesn’t reach Anthropic at all – processing takes place on AWS/Google servers under your own cloud subscription, where you control the retention policy.
- No model training: Anthropic does not train its models on prompts or files submitted by corporate users. In this respect, company data is 100% separated from algorithm development.
- Storage “inside the product” (operational retention): so that we can see our chat history after logging in and return to previous conversations, the data has to be physically stored on Anthropic’s database servers. If our organization doesn’t configure anything else, the data is kept indefinitely, until we or the organization’s administrator delete it manually. If, on the other hand, the administrator sets a custom retention policy in the admin panel (e.g., 30, 60, or 90 days), data older than the chosen period is deleted automatically.
- What happens when you click “Delete”? The conversation disappears from view immediately, and is permanently deleted from Anthropic’s backup systems and backend servers within a maximum of 30 days.
What about Copilot?
When we use Copilot on a work or school account (e.g., in Teams, Word, or the Edge browser – with the green shield icon), our data is subject to strict rules and never leaves our own digital environment, the so-called tenant. There’s no external provider where the data “lands” – everything stays within our own Microsoft 365 subscription.
Where do conversations physically end up?
- Hidden folder in the mailbox (Exchange Online): the entire history of prompts and AI responses is saved in hidden folder in our mailbox database.
- Why there specifically? The folder is invisible during everyday use of Outlook. It’s placed there so that the company’s IT department can manage the data using Microsoft Purview tools – for audits, archiving, or eDiscovery.
- Files uploaded to the chat: documents pasted into Copilot or generated pages (Copilot Pages) end up in our OneDrive for Business folder or on the company’s SharePoint sites.
- Geographic location (data residency, so-called geofencing): the data resides in the same region as the rest of the company’s Microsoft 365 services. If the account was registered in Europe, chats stay on Microsoft’s servers within the European Union (EU Data Boundary).
Importantly, on the OpenAI servers that process the query “on the fly,” the session is completely cleared the moment the chat window is closed – the AI model itself doesn’t remember anything. Microsoft has no visibility into these conversations; they are visible only to an authorized IT administrator within our own company, in line with internal security policy.
Who can actually read our conversations?
This question became a hot topic after the introduction of a restrictive policy for the most powerful models (Covered Models, the Mythos/Fable class). The change caused enough of a stir in the enterprise market that even Microsoft – simultaneously an investor in Anthropic and a distributor of its models – restricted its own employees’ internal access to Claude Fable 5 in the company’s GitHub Copilot, while older models (Opus 4.8, Sonnet 4.6, Haiku 4.5) remained available under the same ZDR terms as before. Microsoft’s legal teams are assessing whether the new retention policy is consistent with how the company wants to protect its own data and that of its customers.
Anthropic’s documentation states that in strictly defined situations, designated people may have access to this data – but this does not mean that any Anthropic employee can browse our conversation history at any time.
Data access
- First line (automated): every query is analyzed by automated safety classifiers looking for violations – attempts to generate malicious code, jailbreak attacks, or fraud. As long as the scanner doesn’t detect anything suspicious, no human looks at our data during the standard 30-day retention period.
- Who has access when a safety flag is raised? When the automated system flags something suspicious, the conversation is routed to the Trust and Safety Team – a small, specially authorized, and vetted group of analysts who may open such a log solely to verify the threat.
How is this access secured?
Anthropic describes, in its technical documentation, mechanisms designed to prevent abuse of these permissions:
- No default access: regular software engineers, AI engineers, or support staff are, by default, completely barred from reading conversations and have no technical way to do so.
- Tamper-proof logs: every attempt by an authorized analyst to open a chat is automatically recorded. This creates a digital trail that cannot be deleted or modified – auditors can see exactly who accessed a conversation, when, and why.
What happens when data is frozen for 2 years?
If an analyst confirms a serious attack or an attempt to extract data using Claude, the conversation is moved to an isolated, secure archive for up to 2 years.
- Dostęp do tych danych mają wyłącznie zespoły cyberbezpieczeństwa i działu prawnego.
- Dane są analizowane po to, by zrozumieć metodę ataku i wdrożyć lepsze zabezpieczenia modelu przed nowymi wektorami zagrożeń.
How does Microsoft Copilot compare??
This is where the consequence of the model described earlier becomes clear. Because, in the commercial version, Copilot stores data in our own Microsoft 365 tenant:
- Microsoft employees have no technical access to our conversations whatsoever.
- Microsoft’s security systems scan queries for threats, but any alerts go to the IT administrators within our own company – not to Microsoft employees. No one outside the organization has any visibility into our data.
What about Anthropic's models in Copilot?
For some time now, Microsoft has offered model choice in Microsoft 365 Copilot: alongside OpenAI models, you can also select Anthropic models – including Claude Opus 4.8 — in Researcher, Copilot Chat, Copilot Studio, and in Copilot within Word, Excel, and PowerPoint, among other places.
Does processing happen outside Microsoft's environment?
Microsoft states this explicitly: when an organization enables Anthropic models, processing for those models takes place outside the Microsoft-managed environment, and in practice also outside the EU Data Boundary. In other words – in this specific scenario, the data genuinely leaves the Microsoft 365 environment.
Anthropic currently acts as a subprocessor for Microsoft – meaning its use is covered by Microsoft’s Product Terms and DPA, even though the processing itself still happens outside the EU Data Boundary. In practice, this means the data may be transferred to servers in the US – Anthropic’s infrastructure runs mainly on AWS and Google Cloud, in US data centers, not in Azure.
What this means in practice?
- Default Copilot (OpenAI models): the data stays within our Microsoft 365 tenant – this is the scenario described in the sections above.
- Copilot with a selected Anthropic model: processing moves outside Microsoft’s environment and outside the EU Data Boundary, though since May 2026 this happens under Microsoft’s Product Terms and DPA (with Anthropic as subprocessor).
- The Anthropic integration in Copilot works on the same basis as the Claude API, which means the data may be stored on Anthropic’s servers.
So it’s clear that Copilot isn’t a single, fixed privacy profile – where the data goes depends on the model you choose, which is exactly why it’s worth knowing which model is actually handling a given conversation.
Summary
It’s worth remembering that both solutions are cloud-based models running at an external provider. For organizations with the strictest requirements (government, healthcare, the financial sector), an alternative is sometimes locally deployed models – such as the increasingly used Polish model, Bielik – which never send data outside your own infrastructure. Not every company needs such models, though, and even fewer are able to support them: they require their own hardware, implementation expertise, and maintenance, and their capabilities still lag behind the largest models.
Regardless of which path you choose, it’s worth being careful and approaching the rollout of an AI assistant thoughtfully. Before introducing a new tool at a company – in this case, Claude’s integrations for Microsoft 365 – you need to think through what data you’ll be processing with these models, and consciously decide which data can leave your corporate environment and which should stay with you alone.

