Registry / Cohere via AWS Bedrock
Cohere via AWS Bedrock
Cohere's Command and Embed model families served as third-party foundation models on Amazon Bedrock. Vendor-trust and data-handling dimensions reflect AWS Bedrock (the serving platform); EU AI Act dimensions reflect Cohere as the GPAI model developer.
Watch-outs 4
The cells where this offering is not a clean public yes. This is what to check before you sign.
- SOC 2 Type II: Yes, sales-gated Report must be requested via a gated process (no direct public download).
- ISO 27001: Yes, sales-gated The certificate itself must be requested (request link on Cohere's trust center), though the ISO 27001 listing and seal are displayed publicly.
- ISO 42001: Yes, sales-gated Cohere publicly lists the ISO 42001 certification, but the official certificate is only provided via a request form on the trust center.
- HIPAA BAA: Yes, sales-gated requires entering into an AWS BAA via sales process
Cohere’s Trust Center confirms the SOC 2 Type II audit exists but the report is only obtainable by request, matching the sales‑gated classification.
Cohere undergoes an annual SOC 2 Type II audit. Request here to see our report.
Cohere's own trust center lists ISO 27001 Certification - Official Certificate with a request action, so the certification exists covering the model developer, but the certificate artifact is gated behind a request, making it yes_sales_gated.
ISO 27001 Certification / Official Certificate
Cohere's own trust center (https://trustcenter.cohere.com/) lists "### ISO 42001 Certification — Official Certificate" with a Request action and no public download, so the certificate artifact is gated; per the registry's certifications rule a certificate obtainable only through a request/sales proc
### ISO 42001 Certification Official Certificate
Cohere's publicly accessible Trust Center page lists SOC 2, ISO 27001, ISO 42001, GDPR, CCPA and HIPAA, confirming a maintained compliance portal.
### SOC 2 Type 2 ... ### ISO 27001 ... ### ISO 42001 ... ### GDPR ... ### CCPA ... ### HIPAA
AWS lists Bedrock as HIPAA‑eligible and states a BAA with AWS is required, which covers the Cohere model accessed through Bedrock.
Amazon Bedrock ... is eligible ... NOTE: If you are a Covered Entity or Business Associate ... you agree not to use these HIPAA Eligible Services ... without first entering into an AWS business associate agreement.
AWS provides a publicly accessible GDPR DPA that includes SCC language and links to a publicly viewable sub‑processor list, satisfying the DPA requirement for Cohere via Bedrock.
Customer agrees that it is unlikely that AWS would become aware that Customer Data transferred under the Standard Contractual Clauses is inaccurate or outdated... 6.1 Authorized Sub‑processors. ... The AWS website (currently posted at https://aws.amazon.com/compliance/sub‑processors/) lists Sub‑processors that are currently engaged by AWS.
The AWS Bedrock FAQ publicly states that customer content is not used to improve base models, which applies to Cohere models accessed via Bedrock.
With Amazon Bedrock, your content is not used to improve the base models and is not shared with any model providers.
The abuse detection page documents default zero-data-retention and lists only OpenAI and Anthropic models as exceptions, confirming Cohere retains no data and ZDR is available.
Amazon Bedrock uses a zero data retention (ZDR) data security model. This means that by default, Amazon Bedrock does not store model inputs or outputs. However, for specific abuse detection purposes related to the following models, we may be required to store inputs and outputs: - For OpenAI ... - For Anthropic Claude Fable 5 and Claude Fable 5.1 ...
The model card explicitly lists In-Region inference support for EU regions, confirming data can be pinned to a specific EU region.
Amazon Bedrock offers three inference options: **In-Region** keeps requests within a single Region for strict compliance...\n\nRegion | In-Region | ...\n`eu-central-1` (Frankfurt) | ✅ ... `eu-west-1` (Ireland) | ✅
The EC's official GPAI Code of Practice signatory list includes Cohere, confirming the model developer is a public signatory.
Cohere
Cohere’s public model documentation page links directly to a publicly accessible PDF summarizing the training data, fulfilling the Article 53 publishing requirement without a gate.
EU AI Act Article 53(1)(d): [Public Summary of Training Content](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/cohere.docs.buildwithfern.com/465ad10da2a73b55ca4291e34e665bf843f8f918fd8a0c4e8f0092a8d60f93ef/assets/documents/eu-ai-public-summary_command-a-plus-family_20260910.pdf)
Spotted an error? Submit a correction with evidence, corrections with a primary source are folded in and credited in the changelog.