He ran client audits on a raw Anthropic key. Then a client asked where their evidence went.
An EU consultant can run an entire audit practice on a frontier model key and never once ask where client evidence actually goes. The moment a client's security team asks, the answer is an A.5.14 finding waiting to happen. Here is the honest fix: EU processing aliases, zero retention, and a receipt on every response.

Not long ago we saw an EU consultant demo his audit workflow: a raw Anthropic API key, a folder of client evidence, and Opus on the other end drafting his policies and findings. It was fast, it was cheap to build, and it is the exact workflow we would have built in his place. It also routes every piece of client evidence he pastes through a US provider on its default routing, on standard commercial terms that keep inputs and outputs for up to 30 days.
None of his clients had complained yet. Then one asked a completely reasonable question during a security review: where does our evidence go when you use AI on it? And the honest answer, "a US model API, retained up to 30 days", is not the answer a compliance consultant wants to give while selling A.5.14 advice.
Why the raw key is the finding
ISO 27001 control A.5.14 asks you to evaluate information transfer, and GDPR Chapter V asks you to justify transfers of personal data outside the EEA. A consultant pasting client HR records, vendor contracts, and risk registers into a US model API is doing both, whether or not the paperwork exists:
- A transfer of client data outside the EEA, on the provider's standard terms rather than anything negotiated for the engagement.
- A retention window the consultant does not control: Anthropic's commercial API terms keep inputs and outputs up to 30 days. Zero-retention arrangements exist, but only for eligible models and qualified accounts.
- A sub-processor line the consultant must maintain on every client DPA, and a transfer impact assessment to write and defend.
The consultant was, in effect, running his clients' compliance work through the exact risk his engagements exist to manage. The fix is not to give up AI on audit work. The fix is to stop making the US transfer the default.
The swap that answers the question
Our API speaks the OpenAI chat completions protocol, so scripts that already speak it change a base URL and a model name; a raw Anthropic Messages client swaps in an OpenAI-compatible client instead. What changes underneath is the part that matters for his clients:
- EU processing. The
isms-fast-euandisms-thinking-eualiases process every request on Mistral's EU-bound inference host, with no transfer of AI-model processing outside the EEA. It is published on our API sub-processor list, not asserted in a sales call. - Zero retention. Request content is not stored and never used for training. Usage metadata is kept for billing. Zero retention is the configuration here, not a negotiated upgrade.
- A receipt on every response. The
x-isms-processing-region: euheader means his answer to the client's question is not an assurance, it is a verifiable fact the client can check from the response itself. - The knowledge comes with it. Curated framework modules, 100+ of them from ISO 27001 to NIS 2, DORA, and the EU AI Act, injected at inference and disclosed per response. The corpus was the part of the raw-key workflow he was quietly maintaining by hand.
- The math improves.
isms-thinking-eubills $2.80 in / $8.80 out per million tokens, same price as our global path, against Claude Opus at $5.00/$25.00 list (both observed 2026-08-26; the console wins when prices move). Prepaid credits start at $20, with per-key spend caps.
Two honest footnotes. Anthropic's prompt caching and batch pricing are real mitigations and belong in the math if the workload fits them. And we claim no quality superiority over Opus: the one head-to-head we have published, Claude Code alone against Claude Code delegating to ISMS Copilot, was a pre-registered accuracy tie on the tested items. The case for the switch is region, retention, included knowledge, and price. Not a quality trophy.
If the work lives in Claude, not in scripts
Plenty of consultants never write the script. For them the second door is the Account MCP connector: their Claude or ChatGPT session calls the specialist, and with Advanced Data Protection enabled in the web app, all AI processing routes to Mistral with zero retention, on every plan including the $20 tier. Same specialist, same region story, no key management at all.
What we are not claiming
EU processing here is a routing choice, not a company-wide hosting claim. Our global aliases process in the United States, and we disclose that the same way we publish the EU path. The endpoint is text in, text out: no tool calling, so tool-driven agents use the sub-agent step pattern or the MCP connector. And nothing that comes out of it is an audit opinion. The consultant signs the deliverable, same as always. The difference is that when a client asks where the evidence went, the answer is a model that processed in the EU, kept nothing, and can prove it on the response.
If you are that consultant, we wrote the full use case page with the request examples, the sources, and the limits. The first key is here.
Related Posts

How AI Enhances Multi-Framework Compliance
AI unifies control mapping, automates evidence collection, and provides real-time monitoring to cut audit prep time and reduce compliance errors.

How Real-Time Alerts Reduce ISO 27001 Non-Compliance Risks
Real-time alerts detect threats fast, cut breach costs and audit failures, and keep ISO 27001 logs tamper-proof for continuous compliance.

AI Accuracy in Security: Specialized vs Generic
Specialized AI beats generic models for security compliance—higher accuracy, fewer hallucinations, and audit-ready documentation for ISO 27001 and GRC.
