❮ Back to blog
Product Spotlights

Obsidian Security announces integration with Claude's Compliance API to strengthen AI security offering

Obsidian Security's new integration with Claude's Compliance API helps security teams find and fix risky configurations before they become a data exposure problem.

8 min read

Users are connecting Claude to sensitive business data sources faster than security teams can track. Sales pipelines, HR records, source code, financial models; all of it is increasingly reachable through a single AI chat interface. That speed is exactly the point of adopting Claude. But it also means just one misconfigured rule or setting can open the door for your most critical data being leaked.

The challenge is knowing which configurations create opportunities for data exfiltration: a shared conversation, an open project, an unmanaged account. Not every user is a security expert. And not every security team has the time or visibility to constantly audit and remediate risky posture settings in Claude. At the speed AI operates, any deviation can result in immediate data loss long before anyone on the security team realizes something is wrong.

Obsidian Security is now integrated with Claude's Compliance API on the Claude Platform, giving security teams a way to instantly find and remediate risky configurations across their Claude rules and settings, so access, data, and sessions always stay secure.

The wrong Claude configuration puts your sensitive data at risk

Claude is designed to make information easy to find and share. That's exactly why its configuration settings deserve close attention. Here are three examples of how a single misconfiguration can turn that convenience into a data exposure risk.

Scenario 1: Claude chat sharing bypasses data access controls

Not every user has the same level of access to data. When sharing files directly, security teams can put controls in place to prevent users without the right access from viewing sensitive information. The same logic applies to Claude: security teams can ensure the agent only sees data the user is provisioned to access.

But that logic breaks down when chat sharing isn't given the same attention. Without the right controls, data access restrictions can be bypassed without anyone noticing. Once confidential data is part of a shared conversation, it can reach employees who were never meant to see it. Without visibility into how sharing is used, sensitive data spreads unchecked.

Scenario 2: Users can broaden access to sensitive information

Claude projects can be kept private or set to public. By default, that keeps sensitive material contained. But the boundary only holds as long as the visibility setting stays put. A single click can expose a project, and from that moment on, everyone in the organization can see what's inside.

If security teams are unaware that users have the ability to share their Claude projects, customer data, financial models, or internal strategy docs may be exposed org-wide. And current data access controls will not fire, since no file was moved and no permissions were granted individually.

Scenario 3: A loose session timeout window leaves the door open for hijacking

Claude sessions are governed by a timeout setting that determines how long a session stays active. Set correctly, that window is short enough to limit how long a compromised session could be used. But if that value is left too permissive, the same session can stay active far longer than it should.

That gap matters if a device is unattended or a bad actor is able to hijack the session. This could enable unauthorized access for weeks without any alerts firing. Knowing what your session lengths are, and aligning them with corporate policy, ensure long standing damage is avoided.

Stay in control of your Claude rules and settings 

Claude is a critical application, but it's just one of many in your stack. Without continuous visibility into these settings, and alerts the moment one changes, these risks can sit unnoticed for hours, days, or longer. 

An automated tool that continuously assesses your Claude posture gives security teams confidence that Claude deployments and the data it touches stay secure.

Obsidian Security eliminates Claude data exposure risks

Anthropic’s built-in tooling isn't designed to continuously surface security misconfigurations, which means overprivileged access can persist quietly in the background. Security teams end up relying on manual spot checks instead of consistent monitoring, making it difficult to catch exposures before they turn into incidents.

Obsidian continuously monitors Claude's settings and configurations, surfacing misconfigurations as soon as they appear. When something falls outside policy, security teams find out immediately, with the context they need to act rather than investigate from scratch.

Flag data retention violations. Obsidian continuously monitors chat and project retention settings, surfacing configurations that may violate corporate data retention requirements before they become an audit finding. Continuous tracking moves audits from a periodic scramble to always-on evidence, compressing prep time from weeks to hours.

Catch unauthorized data sharing. Detect right away if users can make their projects public or share conversations, so security teams can act before sensitive data, confidential discussions, or proprietary information reach an audience beyond the one they were intended for. Closing these misconfigurations can help save hundreds of thousands of dollars in costs if the data exposed is protected under regulations like GDPR or HIPAA. 

Surface excessive session windows. Long session durations increase the risk of unauthorized access from hijacked sessions, compromised credentials, or unattended devices. Obsidian identifies these configurations so security teams can tighten them before they're exploited. By shrinking attack windows from days to hours, businesses can avoid millions in breach costs and accelerate remediation efforts.

Catch shadow accounts. External email domains and unmanaged accounts can retain access to Claude environments, and the sensitive data inside them, long after an employee has left the organization. Obsidian surfaces these accounts so access can be cut off. And because credential-theft-driven insider incidents average $4.8M each, shutting off access is a direct cost saver.

Demonstrate compliance with NIST 800-53. Obsidian's controls are mapped to NIST 800-53, streamlining audits, validating security posture, and accelerating compliance reporting for Claude deployments. Automating reporting for controls like NIST can save 25-50% on total compliance costs and cut audit timelines in half.

How to get started

Obsidian's integration with Claude's Compliance API removes the complexity of securing your organization’s Claude deployment, replacing scattered settings with one continuously monitored view. Security teams get alerted the moment rules or settings drift out of policy, and outcomes mapped to NIST 800-53 help them stay ahead of audits instead of scrambling when one arrives.

To learn more about the integration, visit our website. To see how Obsidian secures AI agents and applications across your organization, check out our AI security page, or get a demo to see it in action.

Frequently Asked Questions (FAQs)