Claude
Anthropic · claude.ai
Claude offers strong in-product controls: item-level memory editing, readable Skills, custom MCP connectors, published base system prompts, a written no-ads commitment and a one-click JSON export. Structurally it remains a hosted, proprietary service: the agent cannot be run outside Anthropic's infrastructure or with another model, there is no tamper-evident audit trail, and model training is a default-on setting.
- Self-service JSON export of chats and memory
- Memory viewable, editable and deletable item by item
- Skills stored as readable SKILL.md files and scripts
- Custom remote and local MCP connectors
- Base system prompts published; written ad-free commitment
- Manual-approval mode for Claude in Chrome
- No runnable export; runtime and models are provider-only
- No tamper-evident or owner-verifiable audit log
- Training toggle defaults to on; flagged data retained up to 2–7 years
- Connector OAuth tokens held by Anthropic
- Some modifications gated by paid tier (e.g. connector limits on Free)
All 34 findings
Consumer Claude apps (claude.ai web, Desktop, mobile, Claude in Chrome) on Free, Pro and Max plans, per public documentation as of 2026-09-27. Team/Enterprise and the API not assessed.
Portable · Can you leave, and take the whole agent with you?
8%- P1Round-trip portability
Incomplete, delayed and not restorable: the account export arrives by email, is not documented as including Skills, connectors or credentials, and Anthropic documents no import of it. Memory and Skills can only be brought back separately by pasting text and uploading .zip files.
Fail - P2Complete export
The export includes conversations, account data and memory, but documentation does not state that custom Skills, connector configurations or credentials are included, so the export does not capture the whole agent.
Partial - P3Independent execution
The agent runtime and Claude models are available only as Anthropic-hosted proprietary services; no open-source runtime can execute the exported agent without contacting Anthropic servers.
Fail - P4Identity continuity
The agent's identity is the Anthropic account, which does not travel with an export, so nobody the agent has dealt with can verify after a move that it is the same agent.
Fail - P5No kill switch
The functioning agent exists only on Anthropic infrastructure, so the provider can restrict or close the account; exported JSON files carry no license check but are not an executable agent.
Fail - P6Capability independence
Memory, search, artifacts, connectors and Chrome automation are delivered by Anthropic's service and work only with Claude models, so moving to another model would remove them. Skills and MCP servers use open formats, which partly mitigates this.
Fail
Transparent · Can you see everything the agent is, with ordinary tools?
50%- T1Open storage format
Exported conversations are JSON and Skills use a documented SKILL.md format, but the live internal storage format is undocumented and only reachable through Anthropic's software.
Partial - T2No hidden instructions
Anthropic publishes the base system prompts for claude.ai and the mobile apps, and user/project instructions are visible. Tool definitions, memory injection, safety interventions and other runtime context are not all shown to the owner.
Partial - T3No shadow memory
Deleted chats persist in back-end storage for up to 30 days; flagged inputs/outputs are kept up to 2 years and trust-and-safety classification scores up to 7 years, outside the owner-inspectable state.
Fail - T4Complete action history
Tool calls and connector actions appear inline in conversation transcripts, which the owner can export. Completeness is not documented, and deleted or incognito chats leave no owner-held record.
Partial - T5Readable logic
Custom Skills are human-readable Markdown plus optional scripts. The platform's own agent logic (orchestration, memory, tool routing) is closed source.
Partial - T6No third-party influence channel
Anthropic states that Claude will remain ad-free, with no sponsored links and no advertiser influence or unrequested product placement in responses. The company reserves the right to revisit this with transparency.
Pass
Auditable · Can you reconstruct exactly what the agent did?
10%- A1No unrecorded actions
Anthropic does not document whether every consequential action is durably recorded, or whether an action is blocked when it cannot be recorded.
Unverified - A2Tamper evidence
The owner-visible record is conversation history, which can be deleted or branched by editing messages without a detectable trace, and no other tamper-evident record is documented.
Fail - A3Separation from the audited
Anthropic does not document whether the agent layer can alter or delete records of its own actions; Claude can edit its memory store, which is separate from history.
Unverified - A4Readable with ordinary tools
Exported conversation JSON, including tool-use content, can be read with ordinary tools, but it is an account export rather than a dedicated audit trail.
Partial - A5Corroborated interactions
The consumer apps document no agent-to-agent exchanges whose records each side could match against the other's.
Unverified
Verifiable · Can you prove the agent runs what it claims?
10%- V1Open, reproducible runtime
The Claude apps and service runtime are proprietary; no OSI-licensed, reproducible runtime is published. Open specifications (MCP, Agent Skills) cover interfaces only.
Fail - V2Active config is inspectable config
Base system prompts and user instructions are inspectable, but server-side configuration, classifiers and injected context cannot be verified to match what is published.
Partial - V3Attributable messages
Messages go out through the owner's connected accounts, so recipients cannot verify that they came from this agent under the owner's authority, and no attribution survives leaving Anthropic.
Fail - V4Independently checkable record
No action record is offered whose integrity can be checked with open tools that do not depend on Anthropic.
Fail - V5Comparable state
Server-side state is not fully exposed and the export is partial, so the owner cannot verify whether the agent's state changed between two points in time.
Fail
Modifiable · Can you change anything, without asking?
42%- M1Instructions
Owners can write profile preferences, project instructions, styles and Skills, but cannot rewrite the platform system prompt or safety layers.
Partial - M2Memory
Settings > Memory lists stored memory topics, each of which can be read, edited or deleted; memory can also be updated from chat, and incognito chats are excluded.
Pass - M3Logic
Owners can create, upload and edit custom Skills (SKILL.md with scripts); the core agent logic of the app cannot be changed.
Partial - M4Tools and permissions
Owners can add any remote MCP server as a custom connector, run local MCP servers in Claude Desktop, and disconnect connectors. Free users are limited to one custom connector, and fine-grained per-tool permission policies are documented mainly for Team/Enterprise admins.
Partial - M5Model choice
Only Anthropic's Claude models can be selected; third-party or local open-weight models are not supported.
Fail - M6No gatekeeping
Some modifications are tier-gated, for example the one-custom-connector limit on Free, and all changes are bounded by Anthropic's terms and product surface.
Fail
Controllable · Is your word final?
50%- C1Communication boundaries
Owners choose which connectors are enabled and can revoke per-site access in Claude in Chrome, but runtime-enforced limits on which recipients, domains or channels the agent may contact are documented only as Team/Enterprise admin controls.
Partial - C2Approval gates
Claude in Chrome offers a Manual mode that pauses for Allow/Deny on each action, and some high-risk actions always require permission. Selecting specific action types to gate is documented mainly as an admin feature, and enforcement cannot be independently verified.
Partial - C3Immediate halt
Responses and Chrome agent tasks can be stopped from the interface at any time, and site permissions can be revoked in extension settings.
Pass - C4Data sovereignty
All content is processed on Anthropic servers by design. Since the 2025 consumer terms update, users choose whether chats are used for training, but the setting is reported to default to on, with 5-year retention for those who allow it.
Fail - C5Credential custody
Local MCP server credentials live in an owner-controlled config file in Claude Desktop, and remote connectors can be disconnected. OAuth tokens for remote connectors are held by Anthropic, are not inspectable and do not travel with an export.
Partial - C6Full deletion
Owners can delete chats and their account; deleted chats are removed from back-end storage within 30 days. Flagged content (up to 2 years), safety scores (up to 7 years), feedback (5 years) and de-identified training data (up to 5 years) may be retained longer.
Partial
Vendors and the public can dispute any finding with evidence. Disputes and their resolutions are published.