Compliance frameworks, security audits, and quality certifications this company maintains.
Cohere maintains SOC 2 Type II certification for its cloud API platform, providing enterprise customers in regulated industries with independent assurance that Cohere's security and availability controls protect sensitive data processed through its LLM infrastructure.
Cohere holds ISO 27001 certification for its information security management system, covering the cloud infrastructure that trains, serves, and monitors its Command, Embed, and Rerank models for enterprise customers globally.
Cohere is GDPR compliant with data processing agreements, EU data residency options through private cloud deployment, and zero-training-data retention commitments for enterprise customers, ensuring European enterprises can use Cohere models without violating data protection regulations.
Cohere supports CCPA compliance for California-based enterprise customers by providing data processing agreements that prohibit Cohere from using enterprise prompts and outputs for model training without explicit consent.
Cohere supports HIPAA-eligible deployments through its private cloud deployment model, allowing healthcare enterprises to process protected health information through Command R without data leaving the enterprise's own cloud tenancy.
Cohere is pursuing FedRAMP Moderate authorization for its enterprise AI platform to serve U.S. federal government agencies and defense contractors that require FedRAMP-compliant LLM infrastructure for sensitive government workloads.
Regulatory
AI Ethics & Safety (NIST AI RMF)
CompliantCohere aligns its enterprise AI platform with the NIST AI Risk Management Framework, providing transparency documentation, model cards, and evaluation frameworks that help enterprise customers meet emerging AI governance requirements.
Cohere is pursuing ISO 42001 AI Management System certification, positioning its enterprise platform as the first enterprise LLM provider to achieve the new international standard for responsible AI development and deployment management.
Cohere maintains CSA STAR Level 1 self-assessment for its cloud AI platform, demonstrating transparency in cloud security controls for the infrastructure that hosts its model training and inference systems.
Cohere is compliant with Canada's PIPEDA privacy law, maintaining appropriate data handling practices for Canadian enterprises and government customers who use Cohere's AI platform under Canadian data sovereignty requirements.