Use cases / Claude security

Start governing

Enterprise security for the whole Anthropic suite.

Extend your security, identity and governance policy to every prompt from every Anthropic product with Speakeasy's AI control plane. Identity, shadow AI detection, and data loss prevention on one platform.

Trusted byVerizonMistralCloudinaryLaunchDarklyFivetranPlanetScale

01 / The problem

Your existing security tools
don't cover Claude.

Speakeasy does.

Shadow AI
Traditional security

Claude Chat, Claude Design, and Claude Code Web run past the endpoint agent, the browser extension, and the network filter. Nobody can list who uses what

With Speakeasy

Every surface, connector, and MCP server people reach from Claude, by team and by person, with access approved per group

Identity
Traditional security

Connectors and MCP servers run under shared service accounts. No prompt is tied to a person, access is all or nothing, and every compliance record has a hole where the name should be

With Speakeasy

Every Claude action runs as the person behind the prompt, with their permissions from your identity provider, so each connector call is attributable to a name

Data loss
Traditional security

DLP profiles built for email and file shares see a prompt after it has left, if at all. Nothing returns a verdict before inference

With Speakeasy

Risk policies and classifiers judge every prompt before the model runs, so a regulated record stops at the point it would leave

Audit trail
Traditional security

Compliance exports the chat later. The export carries no verdict, no policy, and no link between the person and the decision

With Speakeasy

Every turn lands in Agent Sessions with the person, the surface, and the verdict attached, streamed to your SIEM as OTLP

The browser-based approach we relied on just doesn't work for AI-based workflows.

Thierry Dang

Security Operations, MoonPay

MoonPay

02 / The solution

Full enterprise security
for Claude.

Claude Chat, Claude Design, and Claude Code Web run through one governed path on the Speakeasy AI Control Plane. Understand how Claude is used across the company, define what it can access, and enforce those rules on every prompt before the model runs.

Apply controls to every Anthropic productClaudeClaude DesignClaude CoworkClaude Tagclaude.ai

Govern Claude

Understand how Claude is used across the company and define what it can access. One catalog of approved tools and Skills for every Claude surface, access scoped by team and role through the identity provider you already run, and every session recorded in Agent Sessions.

Approved tools and Skills by team and roleAccess follows your identity providerEvery Claude session in one audit trail

Secure Claude

Enforce those rules on every prompt. Each Claude session holds only the access its role allows, and every prompt is checked against your risk policies and classifiers before it reaches the model. Prompt injection, personal information, and leaked credentials are blocked in flight.

Policy verdict on every promptLeast-privilege access for every sessionInjection, PII, and secrets caught in flight

03 / Features

Every Claude prompt
identified, secured, governed.

Anthropic holds each prompt from Claude Chat, Claude Design, and Claude Code Web until Speakeasy answers allow, deny, or review. One configuration covers every surface, with no per-surface agent to install and no device to wait on. Four controls run on every prompt.

Becoming AI-native meant that we needed an entirely new governance & security stack. You can't use old tools to cover your team's new way of working.

Shreyas Kumar

Co-founder, Fermat

Fermat

04 / How it works

From setup to enforcement in four steps

Anthropic Inference hooks is the protocol underneath. A Claude Enterprise organization names Speakeasy as its AI security server, and Anthropic holds every prompt until Speakeasy answers. Nothing changes for the employee, and nothing is installed on the device.

  1. 01

    Name Speakeasy as the AI security server

    In the Speakeasy dashboard, create a project-bound Anthropic Inference Hooks instance. Configure Anthropic with the HTTPS endpoint, the API key, and the project headers Speakeasy shows you once, then paste Anthropic's signing secret back into Speakeasy.

  2. 02

    Resolve who sent it

    Each prompt arrives with the Claude Enterprise user behind it. The session is attributed to that person through your identity provider, so there is no shared key and no anonymous turn.

  3. 03

    Return the verdict before inference

    Anthropic holds the prompt while Speakeasy runs your risk policies and classifiers, then returns allow, deny, or review. Shadow mode records the verdict; enforcing mode stops the turn.

  4. 04

    Record and export

    The turn lands in Agent Sessions in real time with its verdict. Risk events stream as OTLP to Datadog, Grafana Cloud, or any OpenTelemetry collector as they happen.

Fermat

Case study

Claude, org-wide in two days

Fermat made Claude the operating system for the whole company on the Speakeasy AI Control Plane, with every employee on governed access and every session in one record. Usage grew after the rollout instead of being throttled by it.

Read the Fermat story

100%

Employee adoption of governed Claude access

2 days

From first connection to company-wide rollout

+500%

Month-over-month growth in AI usage after rollout


Every agent

The same policies for every agent

Claude is rarely the only agent in the building. The risk policies, classifiers, and session record on this page apply to Cursor, Codex, Gemini, and the agents your teams build, from the same control plane.

AnthropicThis page
OpenAIGoogleCursor
GitHub Copilot
OpenCode
Devin
Custom agents

Questions

Which Anthropic surfaces does this cover?
Claude Chat on desktop, web, and mobile, Claude Design, and Claude Code Web for Claude Enterprise organizations. Speakeasy returns allow or deny before the model runs, and the session lands in Agent Sessions in real time.
How do we turn it on?
Create a project-bound Anthropic Inference Hooks instance in the Speakeasy dashboard, point Anthropic at the HTTPS endpoint with the API key and project headers Speakeasy issues, paste the signing secret, and set shadow or enforcing in Anthropic. The integration is an ungated beta for Claude Enterprise.
How is Speakeasy different from traditional DLP?
Traditional DLP matches patterns in email, file shares, and web traffic. Pointed at the Claude hook, it returns a verdict per prompt with no view of the session around it, no access controls, and a match log that lives apart from the conversation. Speakeasy judges the whole prompt with the risk policies and the personal information and prompt-injection classifiers you already run on the AI Control Plane, applies access to each Claude surface and connector by team and role, and records every turn in Agent Sessions with the verdict attached. Compliance enriches that same record later, and an auditor reads one conversation with the decision on it.
How is this different from hooks in the Claude Agent SDK?
Agent SDK hooks are callbacks a developer registers inside their own agent process. They fire on events such as PreToolUse and UserPromptSubmit and protect the one agent that developer built, wherever it runs. Inference hooks sit on Anthropic's side of the wire. A Claude Enterprise admin names one AI security server for the whole organization, and Anthropic calls it over HTTPS for every prompt in Claude Chat, Claude Design, and Claude Code Web.
What does Speakeasy not block?
Speakeasy does not block tool responses or assistant responses, and it does not rewrite prompts. Image-only attachments are not inspected, since Anthropic sends metadata and extracted text rather than raw image bytes. Personal and Max plans, Bedrock, Vertex, the Claude Platform API, and voice are out of scope. This path does not distribute MCP servers or plugins and does not discover shadow AI on the endpoint; those remain separate capabilities on the AI Control Plane.
Does this change how employees use Claude?
No. Nothing is installed on the device and the Claude client is unchanged. Employees keep using Claude Chat, Claude Design, and Claude Code Web the way they already do. A denied prompt is stopped before the model runs; everything else proceeds as before.
What is the platform's own security posture?
SOC 2 Type II and ISO 27001 certified, GDPR and CCPA compliant, with a BAA and a self-hosted deployment option for regulated environments. Audit reports and certifications are in the trust center.

Go deeper


AI everywhere.

Control here.