ISMS Copilot
Guides

He ran client audits on a raw Anthropic key. Then a client asked where their evidence went.

An EU consultant can run an entire audit practice on a frontier model key and never once ask where client evidence actually goes. The moment a client's security team asks, the answer is an A.5.14 finding waiting to happen. Here is the honest fix: EU processing aliases, zero retention, and a receipt on every response.

by ISMS Copilot··5 min read
He ran client audits on a raw Anthropic key. Then a client asked where their evidence went.

Not long ago we saw an EU consultant demo his audit workflow: a raw Anthropic API key, a folder of client evidence, and Opus on the other end drafting his policies and findings. It was fast, it was cheap to build, and it is the exact workflow we would have built in his place. It also routes every piece of client evidence he pastes through a US provider on its default routing, on standard commercial terms that keep inputs and outputs for up to 30 days.

None of his clients had complained yet. Then one asked a completely reasonable question during a security review: where does our evidence go when you use AI on it? And the honest answer, "a US model API, retained up to 30 days", is not the answer a compliance consultant wants to give while selling A.5.14 advice.

Why the raw key is the finding

ISO 27001 control A.5.14 asks you to evaluate information transfer, and GDPR Chapter V asks you to justify transfers of personal data outside the EEA. A consultant pasting client HR records, vendor contracts, and risk registers into a US model API is doing both, whether or not the paperwork exists:

  • A transfer of client data outside the EEA, on the provider's standard terms rather than anything negotiated for the engagement.
  • A retention window the consultant does not control: Anthropic's commercial API terms keep inputs and outputs up to 30 days. Zero-retention arrangements exist, but only for eligible models and qualified accounts.
  • A sub-processor line the consultant must maintain on every client DPA, and a transfer impact assessment to write and defend.

The consultant was, in effect, running his clients' compliance work through the exact risk his engagements exist to manage. The fix is not to give up AI on audit work. The fix is to stop making the US transfer the default.

The swap that answers the question

Our API speaks the OpenAI chat completions protocol, so scripts that already speak it change a base URL and a model name; a raw Anthropic Messages client swaps in an OpenAI-compatible client instead. What changes underneath is the part that matters for his clients:

  • EU processing. The isms-fast-eu and isms-thinking-eu aliases process every request on Mistral's EU-bound inference host, with no transfer of AI-model processing outside the EEA. It is published on our API sub-processor list, not asserted in a sales call.
  • Zero retention. Request content is not stored and never used for training. Usage metadata is kept for billing. Zero retention is the configuration here, not a negotiated upgrade.
  • A receipt on every response. The x-isms-processing-region: eu header means his answer to the client's question is not an assurance, it is a verifiable fact the client can check from the response itself.
  • The knowledge comes with it. Curated framework modules, 100+ of them from ISO 27001 to NIS 2, DORA, and the EU AI Act, injected at inference and disclosed per response. The corpus was the part of the raw-key workflow he was quietly maintaining by hand.
  • The math improves. isms-thinking-eu bills $2.80 in / $8.80 out per million tokens, same price as our global path, against Claude Opus at $5.00/$25.00 list (both observed 2026-08-26; the console wins when prices move). Prepaid credits start at $20, with per-key spend caps.

Two honest footnotes. Anthropic's prompt caching and batch pricing are real mitigations and belong in the math if the workload fits them. And we claim no quality superiority over Opus: the one head-to-head we have published, Claude Code alone against Claude Code delegating to ISMS Copilot, was a pre-registered accuracy tie on the tested items. The case for the switch is region, retention, included knowledge, and price. Not a quality trophy.

If the work lives in Claude, not in scripts

Plenty of consultants never write the script. For them the second door is the Account MCP connector: their Claude or ChatGPT session calls the specialist, and with Advanced Data Protection enabled in the web app, all AI processing routes to Mistral with zero retention, on every plan including the $20 tier. Same specialist, same region story, no key management at all.

What we are not claiming

EU processing here is a routing choice, not a company-wide hosting claim. Our global aliases process in the United States, and we disclose that the same way we publish the EU path. The endpoint is text in, text out: no tool calling, so tool-driven agents use the sub-agent step pattern or the MCP connector. And nothing that comes out of it is an audit opinion. The consultant signs the deliverable, same as always. The difference is that when a client asks where the evidence went, the answer is a model that processed in the EU, kept nothing, and can prove it on the response.

If you are that consultant, we wrote the full use case page with the request examples, the sources, and the limits. The first key is here.

Related Posts