Cloudflare CASB Now Sees Inside Claude Enterprise!
Hey everyone, it's Shiichan! Today's news takes that uneasy feeling of "I can't see what's happening inside our AI tools" at work and makes it a whole lot clearer. So exciting!
Cloudflare Blog
What was announced?
The Cloudflare Blog announced that its CASB (Cloud Access Security Broker) now supports Anthropic's Claude Compliance API! That means you can monitor how your company uses Claude Enterprise directly from the Cloudflare dashboard. And the best part is you don't need to install any endpoint agents on devices.
The story so far
Until now, security teams had a hard time seeing how employees actually used AI apps. Unlike regular SaaS tools, AI platforms let people upload files, write freeform prompts, and have the AI generate brand-new content. Sensitive data can slip into any of that, but even though you could block unapproved tools at the network layer, you couldn't peek inside the apps you had approved. That left a real gap in compliance.
What changes
CASB connects through the Compliance API and surfaces security findings without inspecting traffic inline. The findings show up in the Cloudflare dashboard grouped by category and ordered by severity, so your team can triage, assign, and remediate using the same workflows they already know.
Even better, a finding can become a Gateway policy in minutes. For example, you can block uploads to Claude for specific users, restrict access to the app entirely, or limit its functionality until the issue is resolved. You're not stuck just spotting problems; you can act on them right away.
Dive Deep
CASB watches over five kinds of assets:
- Projects: detects ones shared across the whole org or specific groups
- Project attachments: files that violate DLP (data loss prevention) policies
- Chat files: ones uploaded by users or generated by the AI
- Chat messages: prompts and the AI's responses
- Artifacts: documents and files the AI generated
For Claude Enterprise, CASB surfaces compliance data like organizations, projects, chats, and roles, and pulls conversation content through dedicated read-only endpoints. For Claude Platform, it tracks member and workspace changes, API key creation, and file events, with Activity Feed support coming soon.
To get started, you need a Claude Enterprise account and you first request Compliance API access from Claude. After that, head to the Cloudflare dashboard under Zero Trust, go to Integrations and then Cloud & SaaS, add Anthropic, enter your Compliance API key, and configure your DLP profiles to start scanning. Findings appear within minutes.
On pricing, new Cloudflare customers can use their first two integrations for free. Existing customers can enable it right from the dashboard.
Wrap-up
- Cloudflare's CASB now supports the Claude Compliance API, so you can monitor Claude Enterprise usage from the dashboard
- No endpoint agents and no inline inspection, and it detects five kinds of issues across projects, chats, artifacts, and more
- Findings can become Gateway policies in minutes to restrict uploads or access
- New customers get their first two integrations free; existing customers enable it from the dashboard
If you're on a security or compliance team that rolled out AI company-wide but feels nervous because "we can't see what's happening inside," this one is for you!