Today, Noma is launching an integration with Claude’s Compliance API, extending our coverage of Claude Enterprise usage, including chats, files, and activity, into the same governance workflows that already cover other agent types like endpoint AI agents, SaaS agents, Homegrown AI, and AI components like MCP servers, skills, and tools.
While Claude is widely used across enterprise departments for tasks like legal drafting and financial modeling, most security teams lack visibility into the specific data being shared. Noma helps organizations adopt the power of the Claude platform by securing every interaction. Acting as a Unified Agent Control Plane, Noma integrates with Claude’s Compliance API to ingest activity logs and conversation content, and runs it through the same AI-DR detection and response engine that already covers Claude Code and Cowork By centralizing this data, Noma allows organizations to discover, govern, and protect AI usage across every Claude product without the silent risk of confidential data exposure through chat prompts.
One Policy Layer, Every Control Point
Integration with the Compliance API does not require rearchitecting how employees work, routing traffic through a proxy, or installing software on end-user machines. It connects at the organizational level on the Claude Platform, running in the background to provide a complete audit trail and runtime governance without impacting the user experience.
The integration with Claude’s Compliance API expands on Noma customers’ ability to define their AI Constitution centrally, and set policies for what agents can access, share, or act on, and enforce it consistently across the places where Claude and other agents actually operate. That enforcement runs through control points organizations already have, whether that’s an AI gateway sitting in front of agent traffic or hooks built into Claude agents themselves. This integration plugs Claude into the same policy layer that already governs homegrown, SaaS and endpoint agents.
What is the Compliance API?
Claude’s Compliance API gives authorized integrations programmatic access to activity logs on the Claude Platform. It exposes chat sessions, messages, users, roles, and organizational structure through a set of endpoints that integrations can poll on a defined schedule.
Noma connects to the Compliance API at the organizational level and polls for new activity, pulling sessions and messages and mapping them to individual user identities within the organization. Security teams get to see activity logs on the Claude Platform: who’s active, what sessions they’re running, and what content is moving through those conversations, without adding any friction to how people already use Claude.
Note: Conversation content access via the Compliance API is available on Claude Enterprise plans only.
What Noma Does With the Data
Every Claude Chat session that comes through the integration is processed by Noma’s AI-DR engine, the same detection engine that already covers Claude Code and Claude Cowork. That means:
- Sensitive data detection: PII, credentials, regulated records, and other confidential information are flagged as they move through chat sessions
- Prompt injection detection: both direct and indirect attempts are surfaced in real time
- Full audit trail: every session is captured for audit regardless of whether a detection fires, so you have an evidence trail of what employees were doing over weeks, months, or quarters
This isn’t just observability. Chat activity is evaluated against the same centrally-defined AI usage policy (your “AI constitution”) that Noma enforces across every other control point in the environment: AI gateways, native hooks inside Claude Code and Cowork, and now Claude Chat via the Compliance API. Detections in Chat feed the same console, the same policies, and the same investigative workflow as the rest of your Claude estate.
If a session contains a policy violation, Noma surfaces it in the console with full context: the prompt, the response, the user identity, the timestamp, and a risk classification. Security teams can investigate the session directly, filter across the environment for similar patterns, and export the data for compliance reporting. If an incident investigation requires reconstructing what data a specific employee shared, that session history is already mapped to their identity.
Part of Full-Ecosystem Coverage
This integration extends Noma’s existing coverage across Claude Enterprise, including Claude Code, Cowork, Dispatch, and Managed Agents, so Claude Chat is no longer a blind spot in a governed AI environment. Discovery and risk assessment, access control and governance, and runtime detection and response now span the Claude product surface for Anthropic-hosted deployments.
What Comes Next
Anthropic is shipping new capabilities faster than most security programs can keep up with. Claude Tag is the most recent example, a genuinely useful feature that also introduces governance questions your existing tools aren’t built to answer. Who initiated the task? What did the agent access? Did any interaction violate policy?
These are answerable questions, but only if you have the instrumentation and enforcement in place before the capability is widely adopted.
Getting Started
Ready to connect it? Get setup instructions on our Claude Enterprise integration page.
Want to see it in action? Reach out for a demo.


