Registry / Cohere API
Cohere API
Cohere's first-party SaaS API platform serving the Command model family (plus Embed/Rerank), hosted on Google Cloud in the US. Cohere holds SOC 2 Type II, ISO 27001 and ISO 42001, and signed the EU GPAI Code of Practice; training on API data is opt-out rather than off by default, and the hosted API offers no EU residency or HIPAA BAA coverage.
Watch-outs 8
The cells where this offering is not a clean public yes. This is what to check before you sign.
- SOC 2 Type II: Yes, sales-gated Report must be requested; not publicly downloadable.
- ISO 27001: Yes, sales-gated Certificate document is obtainable only by request from Cohere's trust center.
- ISO 42001: Yes, sales-gated certificate must be requested via a sales/enterprise process
- HIPAA BAA: Yes, sales-gated The BAA is available only after contacting a sales representative to determine qualification.
- GDPR DPA: Partial DPA requires request (sales‑gated) while subprocessor list is publicly displayed
- No-training default: No public evidence Cohere's own enterprise-data-commitments page confirms an opt-out model — prompts/generations may be used for training unless the customer opts out ("If you are opted out, prompts and generations will
- Retention / ZDR: Yes, sales-gated zero‑data‑retention requires prior approval
- Residency: Unclear Cohere's page says region selection supports data residency but you must contact them to confirm which regions (incl. EU) are available, so the specifics are not publicly documented.
Cohere’s trust center confirms the SOC 2 Type II report exists but is only available after a request, matching a sales‑gated scenario.
Cohere undergoes an annual SOC 2 Type II audit. Request here to see our report.
Cohere's own trust center lists ISO 27001 (ISMS) and offers the official certificate only via a request, so the certification exists but the artifact is sales/request-gated, matching yes_sales_gated.
ISO 27001 Certification / Official Certificate
Cohere's Trust Center lists the ISO 42001 certification but provides it only through a request form, indicating a gated access
ISO 42001 Certification Official Certificate Request
The Cohere Trust Center page is publicly accessible and contains a resources section confirming a maintained compliance portal.
Get our latest security and compliance resources and reports
Verified verbatim on Cohere's own security page that a standard BAA can be executed, but qualification requires contacting a sales representative, matching yes_sales_gated.
Cohere is HIPAA compliant, and is prepared and able to execute a standard Business Associate Agreement ("BAA"). To see if you qualify for a BAA, please contact a sales representative.
The enterprise commitments page states the DPA must be requested, so not publicly available, but also directs users to a public Trust Center where the subprocessor list is shown, satisfying only part of the claim.
Contact [email protected] if you are a SaaS Platform customer and need a Data Processing Addendum. You can view a list of sub-processors by visiting Cohere’s Trust Center.
Cohere's own enterprise-data-commitments page confirms an opt-out model — prompts/generations may be used for training unless the customer opts out ("If you are opted out, prompts and generations will not be used to train Cohere models") — so no public commitment not to train by default exists, matc
You can opt out from your prompts and generations being used to train Cohere models in your dashboard settings at any time.
Cohere publicly documents a 30‑day retention policy and states zero‑data‑retention is available only after approval, matching a yes_sales_gated classification.
We automatically delete logged prompts and generations after 30 days, unless we need it to comply with a legal requirement or customer contract, or unless your usage is flagged as potentially violating our terms... If you have been approved for zero data retention, Cohere does not log any customer prompts or generations.
Verified the verbatim quote on Cohere's own docs page; the value "unclear" is a defensible judgment since the page indicates region pinning exists but leaves available regions (and EU availability in particular) to a sales contact rather than settling it publicly.
Region selection supports data-residency requirements; contact Cohere to confirm the regions available for your vault.
The EU Commission’s GPAI Code of Practice signatory list publicly includes Cohere, confirming it as a signatory.
Cohere
Audit confirmed the recorded value: the PDF, authored by Cohere Germany GmbH and linked from docs.cohere.com/docs/command-a-plus as "EU AI Act Article 53(1)(d): Public Summary of Training Content", contains the verbatim title and is Cohere's own publicly available Art. 53 training-content summary wi
Public Summary of Training Content for Command A+
Spotted an error? Submit a correction with evidence, corrections with a primary source are folded in and credited in the changelog.