AI and your data: how Secure ISS protects client information

Some of our clients have asked how their data is handled when artificial intelligence (AI) plays a part in our service delivery. This is a fair question, and we want to answer it plainly.

Why we use AI

Secure ISS uses AI to help our analysts investigate and respond to threats faster. Within Lumara SecOps Cloud, AI assists with tasks such as summarising alerts, enriching investigations and preparing reports. Our Australian analysts review every output and make every decision. AI supports our people; it never replaces their judgement. Our AI capability runs on Claude, developed by Anthropic. We selected Anthropic because its commercial terms provide strong protections for client data, including a commitment that Anthropic never uses customer data to train its models.

How long Anthropic holds data

Secure ISS accesses Claude under Anthropic's commercial terms. For the Claude models we use in service delivery, Anthropic does not retain conversation content by default. Any data held briefly to operate the service is deleted within 30 days at the latest, and Anthropic never uses commercial customer data to train its models.

Frontier models

Anthropic applies a stricter safety regime to its most advanced frontier models. Anthropic retains prompts and outputs on those designated models for 30 days as a safety measure, then deletes them automatically. No Anthropic personnel can read that data by default; access can occur only through a controlled review path for flagged content, and Anthropic records every access in a tamper-proof log. The models we use in delivering your service are not in this category, so no conversation content is retained by default.

The limited exceptions

We prefer to be straightforward about the boundaries of any commitment. Anthropic may hold data beyond the limits above in two narrow situations: where the law requires it, or where Anthropic detects activity that breaches its usage policy and needs to investigate. These exceptions keep the platform safe and lawful. They do not change the core position: Anthropic does not retain conversation content by default and never uses it for training.

Where your data lives

The security data we collect and manage for you stays within infrastructure that Secure ISS operates, monitored around the clock by our sovereign Security Operations Centre (SOC) on the Gold Coast and staffed by Australian professionals. When AI assists with an investigation, we send only the minimum information the task requires. Anthropic processes it, returns the result, and does not keep it beyond the retention limits described above.

Independent assurance

You do not need to take our word for any of this. Anthropic publishes its security certifications, including SOC 2 Type II, ISO 27001 and ISO 42001 (the international standard for AI management systems), through the Anthropic Trust Center. Its data retention and privacy policies are available through the Claude Privacy Center, and its broader safety commitments are documented in the Anthropic Transparency Hub.

Secure ISS is also a member of Anthropic's Cyber Verification Program. Anthropic runs this application-based program to vet cybersecurity organisations before granting access to advanced capabilities for legitimate defensive work. Our membership reflects independent verification of Secure ISS as a trusted security provider.

Questions

We welcome scrutiny of our data handling. If your team would like the supporting documentation, including Anthropic's published retention policies, please speak with your Secure ISS account manager.