Registry / Cohere API
Cohere API
Cohere's first-party SaaS API platform serving the Command model family (plus Embed/Rerank), hosted on Google Cloud in the US. Cohere holds SOC 2 Type II, ISO 27001 and ISO 42001, and signed the EU GPAI Code of Practice; training on API data is opt-out rather than off by default, and the hosted API offers no EU residency or HIPAA BAA coverage.
Watch-outs 8
The cells where this offering is not a clean public yes. This is what to check before you sign.
- SOC 2 Type II: Yes, sales-gated Report is only available after a request (sales‑gated)
- ISO 27001: Yes, sales-gated certificate must be requested via a form (no public download)
- ISO 42001: Yes, sales-gated certificate must be requested via sales/contact, not publicly downloadable
- HIPAA BAA: No, verified BAA limited to custom model development; API not covered
- GDPR DPA: Partial DPA must be requested; subprocessor list is publicly viewable
- No-training default: No public evidence Cohere defaults to using prompts and generations for training unless customers opt out.
- Retention / ZDR: Yes, sales-gated Zero-data-retention is only available to approved (sales‑gated) customers
- Residency: Yes, sales-gated Regions must be confirmed via sales contact; no public list of available regions.
The provider’s own Trust Center confirms the SOC 2 Type II audit exists but the report must be requested, matching a sales‑gated availability.
Cohere undergoes an annual SOC 2 Type II audit. Request here to see our report.
Cohere’s Trust Center lists the ISO 27001 certification but only offers a request link to obtain the actual certificate, making it sales‑gated
ISO 27001 Certification Official Certificate
Cohere’s Trust Center lists ISO 42001 certification but provides only a request link to obtain the official certificate, matching the definition of a sales‑gated certification.
### ISO 42001 Artificial Intelligence Management System (AIMS) ### ISO 42001 Certification Official Certificate
The Cohere Trust Center loads publicly without login and explicitly offers security and compliance resources, confirming a maintained compliance portal.
Get our latest security and compliance resources and reports
Provider's own trust center states the BAA does not cover the hosted API, confirming they will not sign a HIPAA BAA for this offering.
After a review of the customer's use case and internal HIPAA-related compliance checks, Cohere may execute a Business Associate Agreement (BAA) for custom model development. It does not cover Cohere hosted products and applications such as Cohere's SaaS services.
Cohere provides a public subprocessor list but the Data Processing Addendum is not publicly downloadable, requiring a request, so only partial compliance is met.
Contact [email protected] if you are a SaaS Platform customer and need a Data Processing Addendum.
The provider’s own page states data is used for training by default with an opt‑out toggle, confirming there is no public commitment not to train on customer API data.
You can opt out from your prompts and generations being used to train Cohere models... If you are opted out, prompts and generations will not be used to train Cohere models.
The page publicly documents 30‑day retention and states zero‑data‑retention requires approval, making the offering sales‑gated.
We automatically delete logged prompts and generations after 30 days, unless we need it to comply with a legal requirement or ... If you have been approved for zero data retention, Cohere does not log any customer prompts or generations.
Cohere's own compliance page says region selection can meet data‑residency needs but requires contacting them, indicating the capability is gated behind a sales interaction.
Region selection supports data‑residency requirements; contact Cohere to confirm the regions available for your vault.
The EC’s official GPAI Code of Practice signatory list on its own site includes Cohere, confirming it is a signatory.
- Cohere
Cohere provides a publicly accessible PDF titled “Public Summary of Training Content for Command A+ and family” meeting the EU AI Act Article 53 requirement.
Public Summary of Training Content for Command A+ and family Version of the Summary: v1.1 Last update: 10 September 2026
Spotted an error? Submit a correction with evidence, corrections with a primary source are folded in and credited in the changelog.