Most company data problems with an AI assistant start before anyone types a prompt. They start with which account the work happens in. Claude is sold through consumer plans, team and enterprise plans, and an API, and the data terms are not the same across them. Getting that one decision right does more for your company data than any clever prompt rule.
Start with the plan, not the prompt
Anthropic's commercial offerings, Team, Enterprise and the API, are covered by commercial terms, and the published position is that conversations on those plans are not used to train its models. Consumer accounts work differently: there, training use is a setting the individual controls, and it has changed over time. The practical rule is simple. Work data belongs in a work account that the company owns and administers, never in someone's personal login. Before you rely on any of this, read the current terms and privacy pages on Anthropic's own site, because plans and policies are revised and a blog post, including this one, can be out of date.
Decide what never goes in
A paid plan is a control on how Anthropic handles data. It is not a reason to paste everything. Write a one-page rule that names the categories that stay out: customer personal data, credentials and API keys, unreleased financials, legal matters, and anything covered by a contract or regulation your company is bound to. Give people a safe alternative for each, such as a redacted sample or a synthetic record, so the rule gets followed instead of quietly ignored.
Use the admin controls you are paying for
The higher tiers add the controls that matter for a company: single sign-on, role-based access, and on Enterprise, audit logging and configurable retention. Features differ by plan and change, so check the current plan comparison rather than assuming. Then use what you have. Turn on single sign-on so access ends when someone leaves. Restrict who can invite new members. Decide who can create shared projects and what those projects are allowed to contain, because a shared project is a shared document library.
Treat every connector as a new door
Connectors and MCP servers let Claude read from and act in other systems, which is exactly where company data lives. Each one widens what a mistake or a malicious instruction can reach. Approve connectors one at a time. Ask who maintains each one, what it can read and write, and where its credentials are stored. Start read-only. A document, web page or email that Claude reads can contain instructions written by someone else, so an assistant with write access to a system should not be reading untrusted content on the same task without a person in the loop.
Plan for retention and deletion
Know how long conversations are kept, who can delete them, and what happens to a departed employee's history. On plans with configurable retention, set it deliberately rather than leaving the default, and make sure it matches any legal hold or records policy you already have. If you need a data processing agreement or specific data residency, settle that with Anthropic before the rollout, not after a customer asks.
Keep credentials out entirely
The safest secret in an AI workflow is one the model never sees. Store tokens and passwords in a password manager or secrets store, reference them by name, and keep them out of prompts, project files and shared documents. If a workflow runs unattended, give it its own narrowly scoped account so a leak is contained and easy to rotate.
Make it auditable
Write down who approved the plan, which connectors are enabled, and what the usage rules are, and review that list on a schedule. The goal is that if someone asks how your company data is handled in Claude, you can answer with a document instead of a guess. That is the same discipline we apply to content pipelines: a human gate, a record of what ran, and access that is only as wide as the job requires.