Registry / Mistral La Plateforme
Mistral La Plateforme
Mistral AI's first-party API platform (La Plateforme / AI Studio) for serving and fine-tuning Mistral models. French provider with EU hosting by default, a public DPA with SCCs and subprocessor list, SOC 2 Type II / ISO 27001 attestations gated behind its trust center, and full GPAI Code of Practice signatory status.
Watch-outs 7
The cells where this offering is not a clean public yes. This is what to check before you sign.
- SOC 2 Type II: Yes, sales-gated SOC 2 report must be requested via Trust Center (access gated)
- ISO 27001: Yes, sales-gated Report copies require a request via the Trust Center (gated).
- ISO 42001: No public evidence ISO/IEC 42001 is not listed on any public compliance page; certification, if any, appears gated or absent.
- HIPAA BAA: Yes, sales-gated BAA is offered only "for qualifying services" and access to trust-center documentation requires a request ([email protected]), so an enterprise/qualification process applies.
- No-training default: Partial Default opt-out applies only to pay-as-you-go customers; Free-mode API users are trained by default unless they manually opt out.
- Retention / ZDR: Yes, sales-gated Only for stateless API calls; requires pay-as-you-go plan and a request to enable.
- Art. 53 summary: No public evidence Mistral's own help page says they do not disclose training datasets and no Art. 53 summary is found on their site, so no public summary exists.
Mistral states the SOC 2 report is available only on request through its Trust Center, confirming the report is not publicly downloadable.
If you are a client, you may request access to our SOC 2 report, which outlines the security measures we have in place.
Mistral's own help page confirms ISO 27001/27701 compliance; obtaining the actual Compliance Reports requires a request through the Trust Center, matching the sales-gated definition.
Yes, Mistral complies with both SOC 2 Type II and ISO 27001/27701 frameworks. 🔎 For more information, and to request a copy of our Compliance Reports, please visit our Trust Center.
The provider's public compliance page lists SOC 2 and ISO 27001 but makes no mention of ISO/IEC 42001, and no authoritative public document was found.
Yes, Mistral complies with both SOC 2 Type II and ISO 27001/27701 frameworks. 🔎 For more information, and to request a copy of our Compliance Reports, please visit our Trust Center.
The publicly accessible trust.mistral.ai site loads without login and displays a Trust Center page, confirming a maintained compliance portal.
Welcome to Mistral AI's Trust Center!
Mistral's own trust center publicly lists a "HIPAA Compliance with Mistral AI" document stating it offers a BAA for qualifying services, so there is public evidence the BAA exists but it is gated behind a qualification/access-request process (yes_sales_gated), not no_public_evidence.
Mistral AI supports customers that are subject to the U.S. Health Insurance Portability and Accountability Act (HIPAA) by offering a Business Associate Agreement (BAA) for qualifying services.
The DPA publicly defines and incorporates the EU SCCs and links to the Trust Center where the subprocessor list is openly listed.
"(i) “SCC” means the clauses annexed to the EU Commission Implementing Decision 2021/914 ..." and "(k) “Trust Center” means the Mistral AI Trust Center available at https://trust.mistral.ai/"
Mistral's own help page confirms the quote verbatim and shows the no-training-by-default commitment is conditional on the pay-as-you-go plan, making "partial" the accurate fit.
Customers with pay-as-you-go enabled are opted out of training by default. Users in Free mode may opt out of data training for Mistral Studio and related API services by following the steps below.
The page publicly documents retention control and states ZDR is only available via a gated pay‑as‑you‑go plan and request, matching yes_sales_gated.
Zero Data Retention (ZDR) is available only with pay-as-you-go and only for stateless API calls. ... ZDR does not apply to stateful APIs ... How to request ZDR Submit your request directly within our Help Center or by contacting our support team.
Mistral's own docs provide self-serve EU regional endpoints; the recorded quote is verbatim and the value is accurate.
Mistral offers **regional inference** as an optional service through [dedicated API endpoints](#supported-regions). It supports processing inference requests by systems located within a chosen geography: currently the European Union or the United States.
The EU GPAI Code of Practice signatories list on the European Commission site explicitly includes Mistral AI, confirming the model developer is a signatory.
Mistral AI
Mistral's own help page says they do not disclose training datasets and no Art. 53 summary is found on their site, so no public summary exists.
We **do not** disclose the datasets used to train our models.
Spotted an error? Submit a correction with evidence, corrections with a primary source are folded in and credited in the changelog.