In August I wrote about model training and why, on a business plan, it is not the thing to worry about. This post is about the thing people worry about next: whether to upload the files at all.

The question comes up on almost every kickoff call. Before anyone attaches a spreadsheet, a contract, or a procedures document, they want to know where it goes, who can open it, how long it sits there, and how it could get out.

Anthropic hears the same thing. In the survey of 503 small-business decision-makers it published in September, data security was the most-cited barrier to adopting AI, and one of the three questions owners asked at every stop was what Claude can see once QuickBooks is connected. That is a different question from the upload question, and the two get conflated constantly, so I'll take them in turn.

Where an uploaded file sits

A file you upload lives in one of two places: a conversation or a Project.

A file attached to a conversation is visible to the person who attached it. Anthropic's staff can't read it by default; access is limited to a designated trust and safety team, and only to enforce the usage policy. Delete the chat and it leaves your history immediately and Anthropic's back-end systems within 30 days.

A file in a Project's knowledge base is visible to the project's members. A private project means only invited members; a "public" project means everyone in your organization, and only your organization. The word trips people up, but it never means the internet, and Team/Enterprise Plan Owners can switch public projects off entirely.

The chats inside a shared project stay private to whoever ran them. Members see the documents and the instructions, not each other's conversations. That is the reverse of the mental model most teams arrive with.

Memory is not a third place. It stores topics, not files: your role, the people you work with, how you like things written. Each person's memory is their own, Owners can't read it, and every project keeps a separate memory space, so what Claude learns in one project does not follow you into another.

Connectors are a different question

When someone connects QuickBooks, Google Drive, Microsoft 365, Slack, or any other system, nothing is uploaded. Claude fetches what a given chat asks for, from the source, on the connecting person's own login.

That means Claude inherits that person's permissions. If they can't open a folder in Drive or a report in QuickBooks, Claude can't open it for them. Team/Enterprise Plan Owners decide which connectors are enabled at all, and can hold any connector to read-only so Claude can look but not change anything.

So the answer to the QuickBooks question is: exactly what the person connecting it can already see, and nothing more.

How breaches actually happen

Anthropic encrypts all of this in transit and at rest, which is unremarkable. So does your email provider, your accounting software, and the file server the spreadsheet came from. The documents you're nervous about have been sitting on encrypted systems for years.

Encryption is also not where companies lose data. Colonial Pipeline went down in 2021 because of one compromised password on a legacy VPN account with no second factor, and Change Healthcare was breached in 2024 through stolen credentials on a remote-access portal with no multifactor authentication. Verizon's 2026 breach report has 31 percent of breaches starting with an unpatched vulnerability and 62 percent involving the human element; broken encryption doesn't make the list.

Companies don't lose data because the encryption failed. They lose it because someone got a login.

Judged on access rather than encryption, Claude is stricter than most of the software your team already uses, starting with the fact that there is no Claude password. You sign in with a link sent to your email, with a Google or Apple account, or on Team and Enterprise through your company's identity provider. Everyone complains about fishing another code out of their inbox, and that same design is why a leaked password list is useless against a Claude account.

It does put the weight on your email. The second factor for Claude lives wherever your mail lives, so multifactor authentication on Google or Microsoft, if it isn't already on, is one lever for tightening this further.

The four exits

Knowing where the file sits matters less than knowing how it leaves. There are four exits.

Training is closed by contract on Team, Enterprise, and the API. The one gap is the feedback button: a thumbs up or down sends the entire conversation to Anthropic for up to five years, and that data can be used for training. Team/Enterprise Plan Owners can turn the rating feature off under Data and Privacy.

Export is a feature, not a leak. On Team and Enterprise, only the Primary Owner can export the organization's data, which covers conversations and uploaded files and excludes anything already deleted. That is your company's data staying your company's data.

Legal process is rare and disclosed. Anthropic releases data only under valid legal process, notifies the user unless it is barred from doing so, and for business customers asks the requester to go to the customer first. Its latest transparency report covers the second half of 2025: two content requests worldwide, across eight accounts.

Sharing is the fourth exit, and the one behind the only public exposures of Claude content to date. In September 2025, and again at larger scale in July 2026, chats that people had shared with public links turned up in Google search, some containing health records and internal company documents.

Those were consumer accounts. Team and Enterprise members can only share chats inside their organization; public links don't exist on those plans, and Team/Enterprise Plan Owners can turn chat sharing off or see and revoke what has been shared.

The setup that matters

Every protection above attaches to the business plan, not to Claude in general. The exposure I actually find on engagements is the personal account on a work email: it runs on the consumer terms, where training rides on a toggle, retention is five years if the toggle is on, and public share links exist.

Team plans can verify your domain and block new personal accounts on it; Enterprise can claim the existing ones. Do this before training day, not after.

Once everyone is on the business plan, the structure does the rest. Each person's connectors inherit their own permissions, each person's chats are their own, and an export, or an audit log on Enterprise, resolves to a name. That is more visibility into where a spreadsheet went than any company has over its email.

So when someone asks whether they should feel comfortable uploading the file, my answer is yes, with one condition that has nothing to do with the upload: the account is on a business plan. Get that right and the file in Claude is better protected than the same file in the inbox it came from.