Microsoft Teams, ChatGPT and Claude. What each vendor's own documentation states about retention, training defaults, deployer log access and third-party attestation, sourced line by line. No scoring, no verdict, no vendor rankings. What the documents say, and where they say nothing.
Verified September 2026 · Facts only — no scoring, no verdict
| Microsoft Teams | |
|---|---|
| What survives deletion, and can you shorten it? | Recordings and transcripts carry a 120-day default expiration, stored in OneDrive and SharePoint. The part that matters for a supervised firm: Microsoft states that changing the expiration setting applies only to newly created recordings and transcripts. You cannot shorten retention on anything already captured. |
| Is transcription on by default? | Yesfor newly created meeting policies — so transcripts may exist for meetings no one decided to transcribe. |
| Can the deployer export and supervise? | YesTranscripts and recordings live in OneDrive and SharePoint, inside existing retention and eDiscovery tooling. This is the strongest supervisory position of the three. |
| Does it train on your data? | Not stated in the transcription documentation |
| Third-party attestation and its scope | Office 365 is on Microsoft's SOC 2 Type 2 in-scope services list. |
"Microsoft is SOC 2 certified" is true, and it does not cover the thing most buyers read it as covering. Microsoft Copilot is not named on that in-scope list — only Office 365 and Copilot Studios are.
| ChatGPT (all tiers) | |
|---|---|
| Can the deployer export usage logs? | Not on consumer tiersFree, Go, Plus and Pro accounts are individual, not workspace-managed, so there is no admin log, audit trail or supervisory path. Whatever an employee does in a personal account is not visible to the firm. Business and Enterprise have admin retention and workspace controls. |
| Does it train on your data? | Consumer tiers: yes, by default. The opt-out lives in the privacy portal and applies only to new conversations, so it is forward-only. Business and Enterprise: no, not by default. |
| What survives deletion? | The data-usage help article does not state what happens to content already used in training. |
| Third-party attestation and its scope | SOC 2 Type 2 is stated for the business products. It is not stated for consumer tiers on the enterprise privacy page. |
There is no longer any "Team" or "Teams" tier. Current tiers are Free, Go, Plus and Pro (individual) and Business and Enterprise (organization). Any policy written against a "Teams" tier is working from a retired product map.
| Claude | |
|---|---|
| Does it train on your data? | It depends entirely on which tier the seat was bought on, and price is not the guide. Consumer tiers (Free, Pro, Max): train on user data by default per Anthropic's privacy policy. Commercial tiers (Team, Enterprise, API): Anthropic's Commercial Terms, Section B, state that Anthropic may not train models on Customer Content from the Services. So a $100/month Max seat trains by default, and a $20/month Team seat does not. Expensed individual seats rarely reach procurement, which is where this usually goes wrong. |
| Third-party attestation and its scope | Anthropic's certifications article describes its SOC 2 and ISO position. The consumer tiers sit outside that scope. |
| What survives deletion? | Organisation data retention is described in Anthropic's privacy-centre retention article. For the consumer tiers, no admin log, audit or eDiscovery path is documented in the privacy policy or the privacy-centre articles. |
It reports what vendors publish. It does not score them, rank them, or tell you whether to use one.
It also cannot tell you whether your firm has a problem. That depends on your tier, your executed contract, and what your people are actually putting into these tools, and none of that is in a vendor's public documentation.
Running something other than these three?
Email the tool name to adil@shadowaiforensics.com and I'll tell you what its documentation says. No charge.
Adil Ali, Shadow AI Forensics · shadowaiforensics.com
Verified September 2026
This brief reports what vendors publish. It deliberately doesn't score them or give a verdict. The AI Vendor Risk Assessment does: one vendor, your regulatory context, three industry gates and nine scored criteria, a Go / Conditional Go / No-Go in 48 hours, plus the exact question to put to the vendor in writing.
$997. No call, no access to your systems.
See what's in it →Want the full picture?
This covers 3 tools. The full AI Vendor Compliance Quick-Reference covers all 13, side by side, same sourcing standard.
See all 13 tools, 22 tiers →