# Is Claude safe for client data? Settings and plans for CPA firms

> Is Claude safe for client data? The Claude Team settings to change, what the October 2026 Cowork change means, and how to give AI copies, not originals.

- **URL**: https://www.nocodetalks.co/blog/is-claude-safe-for-client-data
- **Author**: Ankur Khandelwal, Nocodetalks
- **Updated**: Oct 7, 2026
- **Topic**: Security & compliance
- **Sources checked**: 41

---

_A setup guide for US CPA and bookkeeping firms._ The plan to use, the admin settings to change in Claude, ChatGPT and Copilot, a working-folder setup for client files, and what the October 6 Cowork change means.

## The short answer

Yes, for most firm work, if you set it up first. Put client work on a firm-managed Team or Enterprise plan, where Anthropic doesn't train on your content by default. Change the handful of admin settings below, and give Claude copies of client files in one working folder, never the originals. Since October 6, 2026, new Cowork tasks on Pro and Max run in Anthropic's cloud; on Team, an Owner decides.

> General information, not legal or tax advice. Check the cited rules with your own CPA or attorney before acting.

## Is Claude safe? What firms are asking

Is Claude safe for client data? Under YouTube videos about Claude for accounting firms, that question keeps coming up.

> is it safe to use real client bank statements yet?
> — a commenter on a Jason Staats YouTube video (2026) (https://www.youtube.com/watch?v=PwhvAASCJ1I)

What people report
- A commenter at a firm with one AI user didn't want to pay for five Team seats and asked if turning off model training is enough. (a commenter on YouTube (2026), https://www.youtube.com/watch?v=SAGeq_LTOpg)
- An accountant at a Copilot-only firm said they run work through Claude's Excel add-in anyway. One of the top replies asked whether IT had approved that. (a poster on r/Accounting (April 2026), https://www.reddit.com/r/Accounting/comments/1ssdawn/am_i_crazy_or_is_claudes_own_plugin_in_excel_just/)
- Some don't trust it at all. One said plainly they can't trust Claude with sensitive data. (a commenter on YouTube (2026), https://www.youtube.com/watch?v=9OsKjq_rVXc)

It comes down to three things you control: the plan, the settings and what you hand the agent.

## Which plan: client work needs a business account

| Tool | Plan for client work (Oct 2026) | Trains on your content? |
|---|---|---|
| Claude | Team (2 to 150 seats; $25 a seat monthly, $20 billed annually) or Enterprise. Solo: an API account | No, by default. Feedback you send is the exception |
| ChatGPT | Business or Enterprise | No, by default |
| Copilot | Your Microsoft 365 commercial tenant, with work accounts | No. Prompts and responses don't train foundation models |
| Claude Free, Pro, Max | Not for client data | Only if Help improve our AI models is on |

The five-seat comment is out of date: Team's minimum is two. Working alone? An API account, used through Claude Code, sits under Anthropic's Commercial Terms.

On Team and Enterprise, chats stay until you delete them, then leave Anthropic's back end within 30 days.

## The Claude Team and Enterprise settings to change

An Owner sets these once, under Organization settings, before anyone opens a client file.

| Setting | What I'd set | Why |
|---|---|---|
| Identity and access: SSO | On, via Google Workspace or Microsoft 365 with MFA | Staff sign in with accounts you already protect |
| Data and Privacy: Rate chats | Off | Feedback is kept 5 years and can train models |
| Capabilities: Allow network egress | Off, or package managers only | Limits where code Claude runs can send data |
| Connectors > Tool permissions | Add only what you use. Read tools Always allow; write and delete tools Needs approval or Blocked | Org-wide; members can't override it |
| Cowork > Permissions | Allow "Always allow" for connector tools: off (default). Allow "Automatically approve" mode: off | Every write waits for a person |
| Cowork: built-in browser | Off unless a task needs it | On by default on Team |
| Claude in Chrome | Off, or a short site allowlist | On by default on Team |
| Plugins & skills > Policy | User-created skills off; Publishing set to Requires review | Skills from the internet can carry hidden instructions |

> Note: Network egress doesn't cover web search, web fetch or connectors, including Claude in Chrome. Jason Staats shows several of these toggles [on screen](https://youtu.be/SAGeq_LTOpg?t=1478).

## The October 6 Cowork change: what it means for client files

Since October 6, 2026, new Cowork tasks on Pro and Max run in Anthropic's cloud, and the Only on your computer option is gone. For local-only work, Anthropic points to Claude Code in the desktop app.

A cloud task reaches only folders you've connected, through the open desktop app, and fetches a copy of each file it needs. Deleting the session deletes the copies.

On Team and Enterprise, cloud Cowork is in beta. An Owner controls it at Organization settings > Cowork > Run Cowork in the cloud: on by default for Team, off for Enterprise. Off keeps local Cowork.

|  | Cowork in the cloud | Local Cowork (Team, Enterprise) |
|---|---|---|
| Where it runs | A temporary sandbox on Anthropic's servers, cut off from your network | Your computer, code in a virtual machine |
| Client files | Files a task opens are processed on Anthropic's servers | Stay on disk; what Claude reads still goes to the model |
| History | In the Claude account, under plan retention | On the laptop; admins can't centrally delete it |

My read: cloud Cowork on Team runs under the same commercial terms as chat. The bigger change is scheduled tasks, which now run unwatched; Anthropic says not to schedule tasks that touch sensitive files. Keep client work in tasks you start, and turn off Memory in the + menu for one-off client tasks.

## Give the agent copies, not originals: the folder setup

Anthropic's own advice is to avoid giving Cowork sensitive files, like financial documents, and to use a dedicated folder with backups. If you go ahead, narrow what it reaches:

1. **One working folder per job,** such as `AI-work/C014-close/` with `in/` and `out/`, named by client code, not name.
2. **Copy, don't move,** only the files needed into `in/`.
3. **Strip what Claude doesn't need.** Delete SSN, account and name columns. In Excel, File > Info > Check for Issues > Inspect Document clears comments, hidden sheets and author details.
4. **Connect only that folder,** never Documents or a synced client drive.
5. **Outputs go to `out/` under new names.** Claude asks before deleting a file but can overwrite one; in [Jason Staats's demo](https://youtu.be/SAGeq_LTOpg?t=363), an "improve" request wiped the original.
6. **File it yourself.** Move checked outputs to your workpapers by hand, then delete the session and folder.

Prompt for Claude · Working rules for a client task:

```
You're working on a client task in [AI-WORK/CLIENT-CODE-JOB].
Rules:
1. Read only files in /in. Don't open anything outside this folder.
2. Write only to /out, with new file names. Never edit, rename or delete files in /in.
3. Don't send email, post anywhere or use a connector tool that writes. If a step needs one, stop and describe it.
4. If a file holds an SSN, a full account number or an unexpected name, stop and name the file.
5. Finish by listing files read and created, and anything you're unsure about.
```

To reuse it every month, paste these rules into each client's Cowork project instructions.

## When files must stay on your machine: Claude Code

Claude Code keeps your folders and history on your computer, but the model runs at Anthropic. **If Claude reads it, it's sent:** a file it opens, a CSV it searches, anything a script prints to it.

- Block raw folders with a deny rule such as `Read(./clients/raw/**)` in `.claude/settings.json`. It doesn't stop a script that opens files itself; the sandbox does.
- Transcripts sit in plain text under `~/.claude/projects/` for 30 days by default (`cleanupPeriodDays`). That folder now holds client data.
- Set `DISABLE_FEEDBACK_COMMAND=1`, and sign in only with the firm account.

Prompt for Claude Code · Mask a client export before Claude reads it:

```
Write a Python script, mask.py, that reads a CSV path I pass in and writes a masked copy to [OUTPUT FOLDER].
- Replace SSNs, EINs and ITINs with tokens like ID-001.
- Keep only the last 4 digits of account numbers.
- Replace [NAME COLUMNS] with client codes; save the key to [KEY FOLDER].
Test it only on a small fake CSV you create. Don't open [RAW FOLDER].
Print row counts and masked-value counts per column, never the values.
Tell me which patterns it could miss.
```

That follows [Christine Payton's tip](https://youtu.be/HC7Eq90bR9Y?t=232): build on sample data, then run the script on real files yourself, outside Claude.

## ChatGPT Business and Copilot, briefly

**ChatGPT Business.** OpenAI doesn't train on Business workspace data by default. Plugins and apps start switched on, so an admin should turn off unused ones, limit apps to read-only actions where supported, and set app permissions to ask first.

**Copilot.** Work-account prompts don't train foundation models. In US commercial tenants, Claude models are available in Copilot by default, with Anthropic as a Microsoft subprocessor. A separate option, Anthropic models with Data Retention, is off by default and uses Anthropic's own terms. Check both at Microsoft 365 admin center > Copilot > Settings > AI providers operating as Microsoft subprocessors.

**Claude for Excel.** It isn't in Enterprise audit logs and doesn't inherit custom retention. Anthropic says to use it only with trusted spreadsheets.

## Check the setup before real client files

1. **Run a fake client** through a full task. Confirm Claude stayed in the folder and asked first.
2. **Ask each connector what it can do** (prompt below) and compare with Tool permissions.
3. **Review quarterly.** Claude in Chrome, the built-in browser, cloud Cowork and ChatGPT apps all started on by default for Team or Business.

Prompt for Claude · Connector permissions check:

```
For the [CONNECTOR NAME] connector, list every tool you can call.
Make a table: tool name, what it does, read or write, and whether it can delete or send anything.
Don't call any tool that writes, sends or deletes while you do this.
Then say which tools you'd block for a firm that only needs to [TASK], and flag any tool whose effect you're unsure of.
```

Hector Garcia asks a connector this [on camera](https://youtu.be/aGyhYW0TQmE?t=566). Verify answers on the admin screen.

## Where this setup still fails

> never rely on somebody using a tool correctly to remain compliant
> — Jason Staats, A Claude Cowork Security Guide for your Accounting Firm (YouTube, April 2026) (https://youtu.be/W3PAxJOVqQY?t=500)

- **People route around rules.** Over-restrict, and staff drift to personal accounts. Make the safe path the easy one.
- **Hidden instructions.** A client email, PDF or vendor workbook can carry text aimed at the agent; Anthropic calls the risk non-zero.
- **No undo through connectors.** A QuickBooks or email write is real.
- **No zero data retention** for Cowork, Claude in Chrome or the chat apps; only the API and, on qualified Enterprise accounts, Claude Code.

## Write it down: WISP and Section 7216

The FTC Safeguards Rule (16 CFR Part 314) requires tax preparers to oversee service providers. IRS Pub 4557 says preparers need a written security plan; neither it nor the IRS WISP template mentions AI. IRS OPR guidance (Issue Number 2026-19, June 2026) says to use only secure, enterprise-approved AI for client data and to document AI use. Add to your WISP:

- Each AI vendor as a service provider, with plan, terms and the dated settings above
- Which folders the agent may read, and what gets stripped first
- Laptops holding local Cowork history or Claude Code transcripts
- No client data in personal AI accounts

Tax return information has its own rule under 26 U.S.C. § 7216. Read [7216 consent and AI](https://www.nocodetalks.co/blog/irs-section-7216-ai-client-consent) before return data goes near any AI tool.

> Note: General information, not legal advice. Product details were checked against Anthropic, OpenAI and Microsoft pages on October 7, 2026, and settings change. Have your IT provider and your CPA or attorney review your setup.

## Common questions

**Does Claude train on your data?**

On Free, Pro and Max, only if the Help improve our AI models setting is on, plus feedback you send and chats flagged for safety review. On Team, Enterprise and the API, Anthropic doesn't train on your content by default. Feedback is the exception, which is why Rate chats should be off.

**Did the October 2026 Cowork change affect Team plans?**

The forced move to the cloud applied to Pro and Max. On Team, cloud Cowork is on by default and an Owner can turn it off at Organization settings > Cowork. On Enterprise it stays off until an Owner turns it on.

**Is the Claude Team plan enough for a CPA firm?**

For many small firms, yes: commercial terms, no training by default, SSO and admin controls, from 2 seats. Audit logs, custom retention and the Compliance API come with Enterprise. A solo practitioner can use an API account. Either way, change the settings above first.

**Is Claude safer than ChatGPT or Copilot for client data?**

On business plans, all three say they don't train on your data by default. The differences are in admin controls and defaults, which you have to set yourself. Copilot can also route requests to Anthropic's models.

**Does Claude Code upload my whole folder?**

No. It sends what enters the conversation: your prompts, files Claude reads, search results and command output. Files it never touches stay on disk. It can open any file in the folder you start it in, so deny the folders it shouldn't read.

## Sources

- [Use Claude Cowork on web, desktop, and mobile](https://support.claude.com/en/articles/15520349-use-claude-cowork-on-web-desktop-and-mobile)
- [Use Claude Cowork on Team and Enterprise plans](https://support.claude.com/en/articles/13455879-use-claude-cowork-on-team-and-enterprise-plans)
- [Claude Cowork architecture overview](https://support.claude.com/en/articles/14479288)
- [Use Claude Cowork safely](https://support.claude.com/en/articles/13364135-use-claude-cowork-safely)
- [Claude in Chrome admin controls](https://support.claude.com/en/articles/13065128-claude-in-chrome-admin-controls)
- [Provision and manage skills for your organization](https://support.claude.com/en/articles/13119606)
- [Set up role-based permissions on Enterprise plans](https://support.claude.com/en/articles/13930452)
- [Use connectors to extend Claude's capabilities](https://support.claude.com/en/articles/11176164)
- [Create and edit files with Claude (code execution and file creation)](https://support.claude.com/en/articles/12111783)
- [Is my data used for model training? (consumer)](https://privacy.claude.com/en/articles/10023580-is-my-data-used-for-model-training)
- [How do I change my model improvement privacy settings?](https://privacy.claude.com/en/articles/12109829-how-do-i-change-my-model-improvement-privacy-settings)
- [Commercial Terms of Service](https://www.anthropic.com/legal/commercial-terms)
- [Is my data used for model training? (commercial)](https://privacy.claude.com/en/articles/7996868-is-my-data-used-for-model-training)
- [How long do you store my organization's data?](https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data)
- [What is the Team plan?](https://support.claude.com/en/articles/9266767-what-is-the-team-plan)
- [Plans and pricing](https://claude.com/pricing)
- [Use Claude for Excel](https://claude.com/docs/office-agents/excel)
- [Data usage](https://code.claude.com/docs/en/data-usage)
- [Configure permissions](https://code.claude.com/docs/en/permissions)
- [Zero data retention](https://code.claude.com/docs/en/zero-data-retention)
- [API and data retention](https://platform.claude.com/docs/en/manage-claude/api-and-data-retention)
- [ChatGPT Work cloud security](https://learn.chatgpt.com/docs/enterprise/chatgpt-work-cloud-security)
- [ChatGPT Work overview](https://learn.chatgpt.com/docs/enterprise/chatgpt-work-overview)
- [Plugin controls](https://learn.chatgpt.com/docs/enterprise/apps-and-connectors)
- [Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat](https://learn.microsoft.com/en-us/microsoft-365/copilot/enterprise-data-protection)
- [Anthropic models in Microsoft Online Services](https://learn.microsoft.com/en-us/microsoft-365/copilot/connect-to-ai-subprocessor)
- [Remove hidden data and personal information by inspecting documents, presentations, or workbooks](https://support.microsoft.com/en-us/office/remove-hidden-data-and-personal-information-by-inspecting-documents-presentations-or-workbooks-356b7b5d-77af-44fe-a07f-9aa4d085966f)
- [16 CFR Part 314: Standards for Safeguarding Customer Information](https://www.ecfr.gov/current/title-16/part-314)
- [Publication 4557, Safeguarding Taxpayer Data (Rev. 6-2024)](https://www.irs.gov/pub/irs-pdf/p4557.pdf)
- [Publication 5708, Creating a WISP for your Tax & Accounting Practice (Rev. 8-2024)](https://www.irs.gov/pub/irs-pdf/p5708.pdf)
- [Issue Number 2026-19: Introductory Guidelines for Responsible AI Use in Federal Tax Practice (June 24, 2026)](https://www.irs.gov/pub/opr-taxpros/issue-number-2026-19-introductory-guidelines-for-responsible-ai-use-in-federal-tax-practice.pdf)
- [26 U.S.C. § 7216](https://www.law.cornell.edu/uscode/text/26/7216)
- [A Claude Cowork Guide for Accounting Firms (2026)](https://youtu.be/SAGeq_LTOpg?t=1478)
- [A Claude Cowork SECURITY Guide for your Accounting Firm](https://youtu.be/W3PAxJOVqQY?t=500)
- [Extract from PDFs with Claude (super easy!)](https://youtu.be/HC7Eq90bR9Y?t=232)
- [Work with QuickBooks inside ChatGPT or Claude](https://youtu.be/aGyhYW0TQmE?t=566)
- [Claude Cowork Ran My Accounting Firm's Email Inbox](https://youtu.be/Yv51xj_1DOQ?t=81)
- [Claude Cowork Is REPLACING QuickBooks in Accounting Firms (comments)](https://www.youtube.com/watch?v=PwhvAASCJ1I)
- [How to Use Claude for Excel (comments)](https://www.youtube.com/watch?v=9OsKjq_rVXc)
- [Am I crazy or is Claude's own plug-in in Excel just better than Copilot's Claude model](https://www.reddit.com/r/Accounting/comments/1ssdawn/am_i_crazy_or_is_claudes_own_plugin_in_excel_just/)
- [IRS Office of Professional Responsibility Releases AI Guidelines - Alert 2026-19](https://www.reddit.com/r/taxpros/comments/1w3seof/irs_office_of_professional_responsibility/)
