Registry / Mistral La Plateforme
Mistral La Plateforme
Mistral AI's first-party API platform (La Plateforme / AI Studio) for serving and fine-tuning Mistral models. French provider with EU hosting by default, a public DPA with SCCs and subprocessor list, SOC 2 Type II / ISO 27001 attestations gated behind its trust center, and full GPAI Code of Practice signatory status.
Watch-outs 5
The cells where this offering is not a clean public yes. This is what to check before you sign.
- SOC 2 Type II: Yes, sales-gated Report must be requested via Trust Center (not publicly downloadable)
- ISO 27001: Yes, sales-gated ISO 27001 report must be requested via the Trust Center (no public download)
- ISO 42001: No public evidence The trust center lists ISO 27001 and ISO 27701 but does not mention ISO/IEC 42001, and no other authoritative page shows such a certificate.
- HIPAA BAA: Yes, sales-gated BAA is offered only for "qualifying services" and must be obtained by requesting access through Mistral's Trust Center/sales process; it is not publicly downloadable.
- Retention / ZDR: Yes, sales-gated ZDR must be requested from Mistral support with a legitimate reason and is approved at Mistral's discretion; available only with pay-as-you-go and only for stateless API endpoints.
Mistral lists a SOC 2 Type II Full Report in its Trust Center but requires a request for access, confirming the report is gated rather than public.
Use this Trust Center to learn about our security posture and request access to our security documentation.
Mistral confirms ISO 27001 compliance but the certification report is only available on request, matching the sales‑gated definition.
Yes, Mistral complies with both SOC 2 Type II and ISO 27001/27701 frameworks. ... For more information, and **to request a copy of our Compliance Reports**, please visit our Trust Center.
The trust center lists ISO 27001 and ISO 27701 but does not mention ISO/IEC 42001, and no other authoritative page shows such a certificate.
ISO/IEC 27001:2022 Certificate (Mistral AI) · ISO/IEC 27701:2019 Certificate (Mistral AI)
The provider's own publicly accessible trust.mistral.ai site displays a welcome message and detailed compliance resources, confirming a maintained trust center.
Welcome to Mistral AI's Trust Center!
Mistral's own Trust Center (trust.mistral.ai/resources) publicly confirms a HIPAA BAA exists, but it is only for "qualifying services" and access is requested via the Trust Center/sales rather than publicly available, which is yes_sales_gated rather than unclear.
Mistral AI supports customers that are subject to the U.S. Health Insurance Portability and Accountability Act (HIPAA) by offering a Business Associate Agreement (BAA) for qualifying services.
The DPA is publicly accessible, defines SCCs, and points to a publicly available Trust Center that lists subprocessors, satisfying the requirement.
(i) “SCC” means the clauses annexed to the EU Commission Implementing Decision 2021/914 of June 4, 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to the GDPR… (k) “Trust Center” means the Mistral AI Trust Center available at https://trust.mistral.ai/
The provider’s own Additional Terms publicly state it does not train on customer data, confirming a default commitment not to train on API data.
For clarity, Mistral AI does not use the Third-Party Content provided in Customer's Data or that is displayed in Outputs to train our artificial intelligence models.
ZDR is publicly documented on Mistral's own docs/help center but activating it requires a support request reviewed and approved at Mistral's discretion, so per the gate rules (like HIPAA BAA) it is yes_sales_gated rather than yes_public.
To request ZDR, contact support through the ZDR Help Center article or contact Mistral support. Include enough detail about your legitimate reason for requesting ZDR. We review each request and may approve or deny it.
The provider’s publicly accessible documentation confirms dedicated EU endpoint for inference, allowing data to be pinned to the EU.
Mistral offers regional inference as an optional service through dedicated API endpoints. It supports processing inference requests by systems located within a chosen geography: currently the European Union or the United States.
The EU Commission’s official GPAI Code of Practice signatory list includes Mistral AI, confirming the model developer is a signatory.
- Mistral AI
Mistral AI provides a publicly accessible document titled “Public Summary of Training Content” for Mistral Large 3, fulfilling the Article 53 requirement.
"Public Summary of Training Content applies to the following version of Mistral Large 3: Base and Instruct."
Spotted an error? Submit a correction with evidence, corrections with a primary source are folded in and credited in the changelog.