AI Provider Trust Registry evidence verified as of 2026-10-03

Registry / Cohere API

Cohere API

developer: Cohere platform: Cohere (first-party) category: first party

Cohere's first-party SaaS API platform serving the Command model family (plus Embed/Rerank), hosted on Google Cloud in the US. Cohere holds SOC 2 Type II, ISO 27001 and ISO 42001, and signed the EU GPAI Code of Practice; training on API data is opt-out rather than off by default, and the hosted API offers no EU residency or HIPAA BAA coverage.

Watch-outs 8

The cells where this offering is not a clean public yes. This is what to check before you sign.

Vendor trust
SOC 2 Type II Is a SOC 2 Type II report available for this offering?
◐Yes, sales-gated confidence: high · verified 2026-10-01

The provider’s own Trust Center confirms the SOC 2 Type II audit exists but the report must be requested, matching a sales‑gated availability.

Cohere undergoes an annual SOC 2 Type II audit. Request here to see our report.

source

ISO 27001 Is there an ISO/IEC 27001 certification covering this offering?
◐Yes, sales-gated confidence: high · verified 2026-10-02

Cohere’s Trust Center lists the ISO 27001 certification but only offers a request link to obtain the actual certificate, making it sales‑gated

ISO 27001 Certification Official Certificate

source

ISO 42001 Is there an ISO/IEC 42001 (AI management system) certification?
◐Yes, sales-gated confidence: high · verified 2026-10-01

Cohere’s Trust Center lists ISO 42001 certification but provides only a request link to obtain the official certificate, matching the definition of a sales‑gated certification.

### ISO 42001 Artificial Intelligence Management System (AIMS) ### ISO 42001 Certification Official Certificate

source

Trust center Is there a maintained trust center / compliance portal?
●Yes, public confidence: high · verified 2026-09-28

The Cohere Trust Center loads publicly without login and explicitly offers security and compliance resources, confirming a maintained compliance portal.

Get our latest security and compliance resources and reports

source

Data handling
HIPAA BAA Will they sign a HIPAA Business Associate Agreement covering this offering?
✕No, verified confidence: high · verified 2026-10-02

Provider's own trust center states the BAA does not cover the hosted API, confirming they will not sign a HIPAA BAA for this offering.

After a review of the customer's use case and internal HIPAA-related compliance checks, Cohere may execute a Business Associate Agreement (BAA) for custom model development. It does not cover Cohere hosted products and applications such as Cohere's SaaS services.

source

GDPR DPA Is there a public DPA with SCCs and a published subprocessor list?
◔Partial confidence: high · verified 2026-10-03

Cohere provides a public subprocessor list but the Data Processing Addendum is not publicly downloadable, requiring a request, so only partial compliance is met.

Contact [email protected] if you are a SaaS Platform customer and need a Data Processing Addendum.

source

No-training default Is there a public commitment not to train on customer API data by default?
○No public evidence confidence: high · verified 2026-10-03

The provider’s own page states data is used for training by default with an opt‑out toggle, confirming there is no public commitment not to train on customer API data.

You can opt out from your prompts and generations being used to train Cohere models... If you are opted out, prompts and generations will not be used to train Cohere models.

source

Retention / ZDR Is retention documented, and is zero-data-retention available?
◐Yes, sales-gated confidence: high · verified 2026-10-01

The page publicly documents 30‑day retention and states zero‑data‑retention requires approval, making the offering sales‑gated.

We automatically delete logged prompts and generations after 30 days, unless we need it to comply with a legal requirement or ... If you have been approved for zero data retention, Cohere does not log any customer prompts or generations.

source

Residency Can data be pinned to a region (especially the EU)?
◐Yes, sales-gated confidence: high · verified 2026-10-02

Cohere's own compliance page says region selection can meet data‑residency needs but requires contacting them, indicating the capability is gated behind a sales interaction.

Region selection supports data‑residency requirements; contact Cohere to confirm the regions available for your vault.

source

EU AI Act
GPAI Code Is the model developer on the EC's GPAI Code of Practice signatory list?
●Yes, public confidence: high · verified 2026-09-29

The EC’s official GPAI Code of Practice signatory list on its own site includes Cohere, confirming it is a signatory.

- Cohere

source

Art. 53 summary Has the model developer published the Art. 53 training-data summary?
●Yes, public confidence: high · verified 2026-09-29

Cohere provides a publicly accessible PDF titled “Public Summary of Training Content for Command A+ and family” meeting the EU AI Act Article 53 requirement.

Public Summary of Training Content for Command A+ and family Version of the Summary: v1.1 Last update: 10 September 2026

source

Spotted an error? Submit a correction with evidence, corrections with a primary source are folded in and credited in the changelog.