Registry / Mistral via Azure AI
Mistral via Azure AI
Mistral AI models served on Microsoft Azure via Azure AI Foundry (Microsoft Foundry) Models. Some Mistral models (e.g. Mistral Large 3, Mistral Document AI) are "sold directly by Azure", hosted and operated by Azure under Azure SLAs, while others are offered as serverless Models-as-a-Service from the partners-and-community collection, where the model is a Non-Microsoft Product but Microsoft manages the hosting and acts as data processor.
Watch-outs 6
The cells where this offering is not a clean public yes. This is what to check before you sign.
- SOC 2 Type II: Yes, sales-gated Report is behind a request‑access (sales‑gated) gate.
- ISO 27001: Yes, sales-gated the compliance report is only available on request via the Trust Center
- ISO 42001: Partial Microsoft's ISO 42001 scope covers Microsoft's own AI services only; Mistral models are not listed in scope, and Mistral AI itself shows no ISO 42001 (only SOC 2 Type II / ISO 27001) on its Trust Center.
- HIPAA BAA: Partial HIPAA BAA coverage for Azure AI Foundry (Mistral) not publicly confirmed
- Retention / ZDR: Yes, sales-gated Microsoft documentation confirms retention policy is public and zero‑data‑retention can be enabled only after a gated approval process.
- Residency: Yes, sales-gated requires sign‑in to view Microsoft Foundry documentation
Mistral’s own trust center lists a SOC 2 Type II report that must be requested, confirming the report exists but is not publicly downloadable.
Yes, Mistral complies with both SOC 2 Type II ... For more information, and **to request a copy of our Compliance Reports**, please visit our Trust Center.
Mistral publicly states ISO 27001 compliance but the actual certification report must be requested, matching the yes_sales_gated definition.
Yes, Mistral complies with both SOC 2 Type II and ISO 27001/27701 frameworks. … For more information, and **to request a copy of our Compliance Reports**, please visit our Trust Center.
Verified on Microsoft's own compliance page that its ISO/IEC 42001 certification scope lists only Microsoft's own AI services (Copilot family, Foundry, Security Copilot) and not Mistral, and Mistral's Trust Center/Help Center shows no ISO 42001 for the model developer, so partial (platform certified
Microsoft AI services in scope for ISO 42001 certification: GitHub Copilot, Microsoft Copilot, Microsoft Copilot Chat, Microsoft Copilot Health, Microsoft Copilot Studio, ... Microsoft Foundry, Microsoft Security Copilot
Microsoft's Service Trust Portal provides a publicly visible AI Resources page, confirming a maintained trust center/compliance portal for Azure AI services.
Artificial Intelligence Resources ... Resources describing the approach to Compliance, Security and Privacy in the Artificial Intelligence (AI) solutions such as Copilot and Azure Open AI
Microsoft provides a HIPAA BAA for Azure services, but no explicit public confirmation that Azure AI Foundry, which serves Mistral, is in scope, so only part of the requirement is satisfied.
Azure AI Foundry: No explicit confirmation is provided in the context.
Corrected from no_public_evidence: Microsoft's own domain publishes the DPA with no gate (microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA: "The current and archived editions of the DPA are available for download"), learn.microsoft.com/en-us/compliance/r
When you subscribe to a Product under the terms of the Product Terms site, the data processing and security terms are defined in Microsoft Online Services Data Protection Addendum (DPA)... The current and archived editions of the DPA are available for download.
The official Azure Foundry FAQ publicly states that customer data is not used to retrain models, confirming the commitment for the Mistral offering.
Foundry Models don't use customer data to retrain models, and customer data is never shared with model providers.
Microsoft documentation confirms retention policy is public and zero‑data‑retention can be enabled only after a gated approval process.
ZDR requires explicit approval and is not enabled by default. As Zero Data Retention is not a self‑service portal setting, it requires ... a formal support request and business justification ... Once approved, the platform flags the resource so that customer content is not retained and human review is disabled.
The authoritative Microsoft Foundry page confirming region‑pinned processing is behind an authentication gate, so the evidence is sales‑gated rather than publicly accessible.
Standard/Regional types: Processed in the region associated with your deployment (not available for batch deployments). For all deployment types, data stored at rest remains in the designated Azure geography (Americas, Europe, Asia Pacific, and Middle East and Africa).
The EC's GPAI Code of Practice signatory list on its official site includes Mistral AI, confirming the model developer is a signatory.
Mistral AI
Mistral AI provides a publicly accessible PDF titled “Public Summary of Training Content” for Mistral Large 3 on its own legal site, fulfilling the Art. 53 training-data summary requirement.
Public Summary of Training Content
Spotted an error? Submit a correction with evidence, corrections with a primary source are folded in and credited in the changelog.