Cloudflare Now Monitors Claude Enterprise Activity via CASB

Enterprise security teams have a new way to watch what happens inside Claude. Cloudflare has extended its cloud access security broker (CASB) to support the Claude Compliance API, so security and compliance teams can now monitor Claude usage directly in the Cloudflare dashboard, no endpoint agents required.
The move addresses a growing blind spot. AI adoption has outpaced security governance. While IT and security teams raced to enable AI tools for productivity, the controls lagged behind. Most organizations today operate with partial visibility: they may block unauthorized AI tools at the network layer, but they cannot see what happens inside sanctioned ones.
That gap is particularly risky with AI tools. They are conversational, persistent, and deeply integrated into workflows through APIs and agent frameworks. An employee might paste customer data into a prompt. A developer might accidentally share an API key and leave it unrotated for months. These are exactly the kinds of actions that conventional security tools cannot detect.
To address this, Anthropic built the Claude Compliance API to give enterprises programmatic access to security-relevant data about their Claude organizations, workspaces, and usage. Cloudflare CASB now connects to that endpoint and surfaces actionable findings, without requiring inline traffic inspection.
Specifically, the integration scans for security findings across projects, project attachments, chat files, chat messages, and provider-generated artifacts, all items that can violate data loss prevention (DLP) policies. These findings appear in the Cloudflare dashboard alongside posture data from other SaaS applications like Microsoft 365, Google Workspace, and Salesforce.
The integration also supports two Claude tiers. For Claude Enterprise, CASB surfaces compliance data such as organizations, projects, chats, and roles, and retrieves conversation content through dedicated read-only endpoints to prevent data loss. For Claude Platform, CASB surfaces member and workspace changes, API key creation, and file create or download events.
Cloudflare CASB is also built to turn findings into action. A detected security finding in Claude, such as a user uploading files containing sensitive data, can become a Gateway policy in minutes. Security teams can block uploads, restrict access to Claude entirely, or limit functionality until a finding is resolved.
This integration fits into a broader Cloudflare strategy for AI security. Cloudflare AI Gateway sits between applications and AI providers, providing observability into requests, token spend, and model performance. Cloudflare Gateway and Data Loss Prevention inspect AI traffic for sensitive data, blocking prompts containing customer PII or confidential material before they reach the model.
For enterprises ready to connect, the setup requires a Claude Enterprise account, Compliance API access from Anthropic, and an Anthropic integration added in the Cloudflare Zero Trust dashboard. The integration begins scanning immediately and surfaces findings within minutes. New Cloudflare customers can also start with their first two integrations for free.




