Skip to content
Rush Commerce
AI & Automation3 min read

Anthropic EFS keeps Claude misuse logs in your bucket

Enterprise Frontier Safeguards puts Claude's abuse-monitoring data in your own S3, Blob or GCS bucket under your keys. Demand the pattern from every AI vendor.

Anthropic announced Enterprise Frontier Safeguards, which pairs zero data retention with misuse detection by storing the monitoring data in your cloud account instead of Anthropic's. The zero data retention trade-off has been the same for two years — keep your prompts private or let the vendor watch for abuse, pick one. EFS is the first serious attempt to stop making you pick.

What actually happened

Activity data used for misuse detection lives in the customer's Amazon S3, Azure Blob Storage or Google Cloud Storage account, under the customer's own encryption keys, access policies and audit logging (Anthropic). Automated systems analyze a rolling window of traffic across sessions and accounts for two specific things: attempts to develop offensive cyber or biological capability, and signs of stolen or leaked credentials. You pay your own cloud provider for the storage and the data operations.

Anthropic says it built EFS with more than 100 customers across financial services, healthcare, manufacturing, telecom, law, retail and the public sector, and with AWS, Google Cloud and Microsoft Azure. Support spans Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Google's Agent Platform and Microsoft Foundry.

Read the timing before you plan around it. EFS rolls out in phases starting this fall — it is not available today. Eligible customers get zero data retention on Fable 5 and Fable 5.1 in the meantime, and access is via a request form (Help Net Security). This is an enterprise-tier control, and nothing in the announcement suggests it reaches a ten-person company on a standard plan.

Why vendor log custody matters for your business

You will not buy EFS. You should still copy the shape of it, because it sets a bar you can hold every other vendor to.

Right now, ask the AI vendors you already pay three questions. Where does the record of our traffic physically sit? Who holds the key? Can we read it — not request an export, read it — during an incident? Most answers will be "our systems," "we do," and "file a ticket." That is the answer you are accepting today by default, and it is the one that hurts at 2 a.m. when you are trying to reconstruct what an agent did with a customer record.

The practical move for a small business is to own the layer you can. Log every prompt, tool call and response your own application makes, into your own bucket, with your own retention policy — before it reaches the model provider. That log answers the incident question regardless of what your vendor retains, and it survives you switching vendors, which the vendor's copy does not.

Key takeaways

  • Enterprise Frontier Safeguards stores Claude misuse-monitoring data in the customer's own S3, Azure Blob or GCS, under the customer's encryption keys and access policies
  • Automated systems scan a rolling window across sessions for offensive cyber or biological capability attempts and stolen or leaked credentials
  • Rollout is phased and starts this fall; eligible customers get zero data retention on Fable 5 and Fable 5.1 until then
  • Built with 100+ enterprise customers and AWS, Google Cloud and Microsoft Azure; this is an enterprise-tier control, not a small-business feature
  • The transferable move: log your own prompts, tool calls and responses into your own bucket before they reach any model provider

If your only record of what an agent did lives at your vendor, you do not have an audit trail — you have a support ticket. We build AI systems that write their own logs to storage you control, with retention you set. See how we structure it, or tell us which vendor you are worried about.

Sources: Anthropic, Help Net Security.

  • #anthropic
  • #data-retention
  • #vendor-risk
  • #compliance
  • #audit-logs
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.