Command: Cohere Sub-processors (Trust Center)
Full side-by-side comparison of both captured documents.
Both captured versions of this document, in full. Deleted text is struck through on the left; inserted text is underlined on the right.
direct captureBefore
Captured 2026-07-29 04:20:49 UTCMethod directHash 503794ee1c8a00c5direct captureAfter
Captured 2026-07-30 04:22:30 UTCMethod directHash c626e749c4736eefraw before · raw after · provider’s live document
| Before | After |
|---|---|
Cohere Trust Center Cohere prioritizes your data's confidentiality, integrity, and availability. Our Trust Center offers insights into our data management, security measures, and compliance. See Certifications Compliance SOC 2 Type 2 Service Organization Controls (SOC 2) (Type II) Trust Services Principles Request ISO 27001 Information Security Management System (ISMS) Request ISO 42001 Artificial Intelligence Management System (AIMS) Request U.K. Cyber Essentials U.K. Gov't-backed Cybersecurity Standard Request GDPR Protect the personal data and privacy of EU citizens for transactions that occur within EU member states CCPA California Consumer Privacy Act HIPAA Health Insurance Portability and Accountability Act (please see FAQ). Resources Get our latest security and compliance resources and reports Request all documents SOC 2 Type II Cohere undergoes an annual SOC 2 Type II audit. Request here to see our report. Request ISO 27001 Certification Official Certificate Request ISO 42001 Certification Official Certificate Request U.K. Cyber Essentials Certificate for Cohere Inc. Request U.K. Cyber Essentials Certificate for Cohere UK, LTD Request Latest Penetration Test Report API Penetration Test Results Request Latest Penetration Test Report Web Application test results Request Responsible Disclosure Policy Rules of engagement for conducting and performing security research (i.e. vulnerability discovery) activities for participating in our Bug Bounty Program. Download Cohere Enterprise Data Commitments Overview of how Cohere handles and protects our Enterprise Customers' Data Visit Cohere Secure AI Frontier Model Framework This document outlines Cohere's risk management methodology for managing risks to our models. Download View all Subprocessors Google Cloud Infrastructure Service Provider Location: USA Fullstory Software Delivery Platform Location: USA LaunchDarkly Feature Flagging Location: USA New Relic Platform Monitoring Location: USA Retool Software Delivery Platform Location: USA Sentry IO Software Delivery Platform Location: USA Segment Event and Error Handling Location: USA Sendgrid Email Communications Location: USA Vercel Web Application Hosting Location: USA View all FAQs Can I request a copy of your SOC 2? Yes, you can request a copy above. Prior to receiving a copy of our SOC 2 Type 2 report, we will need a signed mNDA. How do we manage risk and compliance? Cohere maintains robust security practices to ensure that our customers' data are maintained to the highest degree. Is the company GDPR compliant? What steps have you taken to ensure this? As a service provider that operates in multiple jurisdictions, including Canada, the EU and the US, Cohere has designed its services with Privacy-by-Design in mind, and we have processes in place to assist our customers to comply with their obligations under applicable privacy laws, including the GDPR. In particular, we have a robust Information Security program designed to safeguard the information that our customers share with us, which, in certain circumstances, may contain personal information. In addition, we have implemented GDPR-specific compliance training through Secureframe and have prepared a multi-jurisdictional Data Processing Addendum designed to give our customers contractual assurances regarding Cohere’s handling of customer data on their behalf in compliance with applicable privacy laws, including the GPDR. Further, we rely on appropriate mechanisms for international data transfers as required by the GDPR. We also monitor guidance around GDPR compliance from privacy-related regulatory bodies and will update our product features and contractual commitments accordingly. Do you have a Data Processing Agreement? Yes, Cohere has a DPA. If you would like to receive a copy, we will need a signed NDA. Please contact [email protected] for more information. Where are your hosting centers located and do you have options to use centers outside of the US? Are there options to not send data to the US at all? Our hosting centers are on Google Cloud Platform servers located in US-Central. We do not use servers outside of the US; however, we can, in certain circumstances, configure our offering to ensure that no customer data is stored on Cohere’s systems. When the Cohere offering is configured in this way, the customer data is considered “ephemeral”, as it transits through Cohere’s systems only briefly for the purposes of providing the services and is purged immediately after processing. There are drawbacks to this approach as it limits some features and Cohere’s ability to improve the user experience and/or address certain issues efficiently by reviewing customer data. What has been your response to the Schrems II ruling and have you conducted a transfer impact assessment? Following the Schrems II ruling, companies transferring EU personal data to non-EU countries that have not been deemed adequate by the relevant governmental body, such as the US, must conduct assessments to identify any necessary supplemental measures to protect the personal data being transferred. Cohere has conducted, with the assistance of EU counsel, a Transfer Impact Assessment (TIA) that assesses the impact and security considerations in connection with transfers of customer data originating in the EU (and that is subject to the GDPR) to the US for processing. The TIA details the “relevant contractual, technical or organisational safeguards” Cohere has in place to supplement protections under the Standard Contractual Clauses where necessary. These safeguards include encryption at rest and in transit, administrative access control, system monitoring, logging and alerting and more. Based on the Transfer Impact Assessment, Cohere considers that the transfer of customer data to the US is, taking account of all the circumstances of the transfer, compatible with the GDPR read in light of the Charter of Fundamental Rights of the EU. In addition, our multi-jurisdictional Data Processing Addendum (DPA) contains the following commitments, among others: 1. Standard Contractual Clauses: The DPA incorporates the Standard Contractual Clauses, approved by the European Commission on 4 June 2021, allowing customers to apply the protections in the Standard Contractual Clauses to personal data originating in the EU (and that is subject to the GDPR) to the US for processing. 2. Security: Cohere commits to implementing appropriate technical and organisational measures to protect customer data. A description of Cohere’s security measures are included in Annex B to the DPA. 3. Government Requests and Orders: Unless legally prohibited, Cohere commits to promptly notify customers of any communications received from a governmental agency requesting or purporting to compel the production of customer data that contains personal information so that the customer can work with the governmental agency directly to respond. Will Cohere sign a Business Associate Agreement under HIPAA (i.e. HIPAA Compliance)? After a review of the customers use case and internal HIPAA-related compliance checks, Cohere may execute a Business Associate Agreement (BAA) for custom model development engagements. Cohere's BAA only covers engagements where Cohere develops a custom model on behalf of a customer. It does not cover Cohere hosted products and applications such as Cohere's SaaS services. Enterprise customers should not submit Personal Health Information through the Cohere SaaS services. For more information, please contact your Account Executive or [email protected] . Monitoring Continuously monitored by Secureframe Change Management | |
Production Data Use is Restricted Change Management Policy Configuration and Asset Management Policy | Production Data Use is Restricted Change Management Policy Configuration and Asset Management Policy |
View | View 3 more controls |
Availability Backup Restoration Testing Automated Backup Process | Availability Backup Restoration Testing Automated Backup Process |
Uptime and Availability Monitoring View 2 more controls Organizational Management Acceptable Use Policy Performance Review Policy Internal Control Policy View 10 more controls Confidentiality Data Classification Policy Data Retention and Disposal Policy Disposal of Customer Data Vulnerability Management Vulnerability and Patch Management Policy Third-Party Penetration Test Incident Response Incident Response Plan Testing Tracking a Security Incident Lessons Learned View 1 more control Risk Assessment Vendor Risk Assessment Risk Assessment Vendor Risk Management Policy View 2 more controls Network Security Automated Alerting for Security Events Network Security Policy Access Security Unique Access IDs Access Control and Termination Policy Encryption-in-Transit View 3 more controls Physical Security Visitor Control Physical Access Restrictions Physical Security Policy View 1 more control View all | |