Claude Compliance API feeds chats to 100+ security tools

Claude Compliance API feeds chats to 100+ security tools

Companies running Claude Enterprise can now send employee chats, uploaded files and coding sessions to the security and compliance tools they already use. More than 100 vendors have built integrations with the Claude Compliance API, including CrowdStrike, Microsoft Purview, Splunk, Palo Alto Networks, Cloudflare and Zscaler.

The API is designed to let an organization route Claude activity into its existing monitoring stack. Security teams do not need to build a separate process to review how staff use the AI assistant.

What the feed contains

For Enterprise customers, the feed is broad. It includes the conversations themselves, the files users upload, and their projects. It also covers Cowork and Claude Code sessions, down to individual prompts, model responses and tool calls.

On top of that, the API delivers an audit trail. This shows who signed in, what administrators did, and which settings were changed.

In practice, a defender can review what employees paste into Claude and see which tools a coding session invoked. Session records from the Microsoft 365 add-ins and from Claude Science are also available, although both are still in beta.

Who is plugged in

The partner list covers several product categories. Data loss prevention (DLP) tools flag sensitive data leaving a company. SIEM platforms collect security logs for investigation. Other partners work in identity, eDiscovery (the search and preservation of electronic records for legal cases) and AI security posture management.

Some integrations serve specific industries. Hadrius and Shield archive conversations for financial firms that must meet recordkeeping obligations.

Vendors do not all see the same data. Salt Security and Torch Security read no conversation content at all. Datadog ingests audit logs from Claude Platform.

Enterprise vs. Platform

Both Claude Enterprise and Claude Platform customers can use the API, but the scope differs. Platform customers receive activity events only. They get no prompts and no model responses.

Access is also tightly restricted on the Enterprise side. Only the Primary Owner can switch the API on. Owners can create access keys for their own organization, while Admins do not see the settings page at all.

Rollout timeline

Not every integration is live yet. Netskope's integration is in private preview, and Okta's is moving to beta for select customers.

KnowBe4 plans general availability in November 2026. Vanta's integration is in beta for select customers, with general availability planned for January 2027.

Our Take

For security teams, this closes a gap that has been growing since generative AI tools entered the workplace. Employees paste source code, customer records and internal documents into chat windows every day, and until now much of that activity sat outside the view of DLP and SIEM systems. Feeding it into tools such as Purview or Splunk means AI usage can be treated like email or file sharing: logged, searchable and subject to policy.

The inclusion of Claude Code sessions and tool calls is arguably the more important detail. AI agents that run commands and call tools are becoming an attack surface in their own right. Recent incidents, such as the PixelLeak case where AI agents leaked screenshots to GitHub, and the SalesBleed flaws in Salesforce Agentforce, show how agent behavior can go wrong. Having a record of what an agent actually did gives incident responders something concrete to work with.

There is a flip side. A feed that captures full conversations is itself a sensitive data store. It may contain personal information, trade secrets or credentials that users should never have typed in the first place. Organizations will need to think carefully about which vendors receive content, how long it is retained, and who can read it. The fact that some partners, like Salt Security and Torch Security, work without conversation content suggests there is room to choose a narrower scope. Employees may also be unaware how closely their chats can be reviewed, which raises workplace privacy questions in some jurisdictions.

The access model, limited to the Primary Owner, looks like a sensible safeguard against a compromised admin account quietly enabling bulk export. It is worth watching whether other AI vendors follow with comparable compliance feeds, and how quickly the beta and preview integrations reach general availability over the coming months.