AI Provider Trust Registry evidence verified as of 2026-08-19

Registry / Cohere API

Cohere API

developer: Cohere platform: Cohere (first-party) category: first party

Cohere's first-party SaaS API platform serving the Command model family (plus Embed/Rerank), hosted on Google Cloud in the US. Cohere holds SOC 2 Type II, ISO 27001 and ISO 42001, and signed the EU GPAI Code of Practice; training on API data is opt-out rather than off by default, and the hosted API offers no EU residency or HIPAA BAA coverage.

Watch-outs 8

The cells where this offering is not a clean public yes. This is what to check before you sign.

Vendor trust
SOC 2 Type II Is a SOC 2 Type II report available for this offering?
Yes, sales-gated confidence: high · verified 2026-08-19

Cohere’s trust center confirms the SOC 2 Type II report exists but is only available after a request, matching a sales‑gated scenario.

Cohere undergoes an annual SOC 2 Type II audit. Request here to see our report.

source

ISO 27001 Is there an ISO/IEC 27001 certification covering this offering?
Yes, sales-gated confidence: high · verified 2026-08-18

Cohere's own trust center lists ISO 27001 (ISMS) and offers the official certificate only via a request, so the certification exists but the artifact is sales/request-gated, matching yes_sales_gated.

ISO 27001 Certification / Official Certificate

source

ISO 42001 Is there an ISO/IEC 42001 (AI management system) certification?
Yes, sales-gated confidence: high · verified 2026-08-18

Cohere's Trust Center lists the ISO 42001 certification but provides it only through a request form, indicating a gated access

ISO 42001 Certification Official Certificate Request

source

Trust center Is there a maintained trust center / compliance portal?
Yes, public confidence: high · verified 2026-08-17

The Cohere Trust Center page is publicly accessible and contains a resources section confirming a maintained compliance portal.

Get our latest security and compliance resources and reports

source

Data handling
HIPAA BAA Will they sign a HIPAA Business Associate Agreement covering this offering?
Yes, sales-gated confidence: high · verified 2026-08-17

Verified verbatim on Cohere's own security page that a standard BAA can be executed, but qualification requires contacting a sales representative, matching yes_sales_gated.

Cohere is HIPAA compliant, and is prepared and able to execute a standard Business Associate Agreement ("BAA"). To see if you qualify for a BAA, please contact a sales representative.

source

GDPR DPA Is there a public DPA with SCCs and a published subprocessor list?
Partial confidence: high · verified 2026-08-19

The enterprise commitments page states the DPA must be requested, so not publicly available, but also directs users to a public Trust Center where the subprocessor list is shown, satisfying only part of the claim.

Contact [email protected] if you are a SaaS Platform customer and need a Data Processing Addendum. You can view a list of sub-processors by visiting Cohere’s Trust Center.

source

No-training default Is there a public commitment not to train on customer API data by default?
No public evidence confidence: high · verified 2026-08-14

Cohere's own enterprise-data-commitments page confirms an opt-out model — prompts/generations may be used for training unless the customer opts out ("If you are opted out, prompts and generations will not be used to train Cohere models") — so no public commitment not to train by default exists, matc

You can opt out from your prompts and generations being used to train Cohere models in your dashboard settings at any time.

source

Retention / ZDR Is retention documented, and is zero-data-retention available?
Yes, sales-gated confidence: high · verified 2026-08-19

Cohere publicly documents a 30‑day retention policy and states zero‑data‑retention is available only after approval, matching a yes_sales_gated classification.

We automatically delete logged prompts and generations after 30 days, unless we need it to comply with a legal requirement or customer contract, or unless your usage is flagged as potentially violating our terms... If you have been approved for zero data retention, Cohere does not log any customer prompts or generations.

source

Residency Can data be pinned to a region (especially the EU)?
?Unclear confidence: medium · verified 2026-08-14

Verified the verbatim quote on Cohere's own docs page; the value "unclear" is a defensible judgment since the page indicates region pinning exists but leaves available regions (and EU availability in particular) to a sales contact rather than settling it publicly.

Region selection supports data-residency requirements; contact Cohere to confirm the regions available for your vault.

source

EU AI Act
GPAI Code Is the model developer on the EC's GPAI Code of Practice signatory list?
Yes, public confidence: high · verified 2026-08-18

The EU Commission’s GPAI Code of Practice signatory list publicly includes Cohere, confirming it as a signatory.

Cohere

source

Art. 53 summary Has the model developer published the Art. 53 training-data summary?
Yes, public confidence: high · verified 2026-08-16

Audit confirmed the recorded value: the PDF, authored by Cohere Germany GmbH and linked from docs.cohere.com/docs/command-a-plus as "EU AI Act Article 53(1)(d): Public Summary of Training Content", contains the verbatim title and is Cohere's own publicly available Art. 53 training-content summary wi

Public Summary of Training Content for Command A+

source

Spotted an error? Submit a correction with evidence, corrections with a primary source are folded in and credited in the changelog.