Vendor audit · Evidence report

Anthropic / Claude

Extended-thinking block telemetry and TLS interception on container egress — documented with evidence-state labels, alongside credit where credit is due.

ObservedInferredUnder review

Framing — credit and scrutiny

Anthropic deserves credit for drawing specific military-use boundaries, and that stance had real costs. We do not claim otherwise. But a principled position in one domain does not provide a privacy exemption in another. Consumer telemetry, consent behavior, and traffic-interception architecture remain fair subjects for independent audit — including ours, including this one.

What we observed

Fact — decompiled & counted

Extended-thinking blocks in Claude API responses contain 56 cross-references to KAIROS/autoDream telemetry markers embedded in block metadata.

Fact — captured

TLS-intercept CA certificates were present on container egress paths in the environments we tested, enabling inspection of traffic that would otherwise be end-to-end encrypted.

Inference — most likely interpretation

Extended-thinking blocks function, among other things, as a delivery channel for runtime telemetry/instruction patterns that are not surfaced to the API consumer.

Opinion — our judgment

A vendor that asks for trust on safety grounds should expect — and welcome — measurement on privacy grounds. We hold ourselves to the same standard.

Open questions — under review

Provenance & methodology

Report status

Status
Documented
KAIROS cross-refs
56
Last updated
2026-09-13

Thinking-block decompilation, the KAIROS cross-reference map, and CA certificate chain analysis are being finalized for open publication.

Correction & changelog

We do not silently rewrite findings. If a claim changes, the change stays visible.

Get protected — free All vendor audits Counter-evidence? Talk to us