AI Vendor Directory · Foundation model APIs
Does Cohere train on your data?
Yes — trains on your data by default. Vendor-stated default: yes (SaaS Platform default — opt-out toggle in dashboard). On Cohere's SaaS Platform, prompts and generations may be used for model training unless the customer opts out: Dashboard Settings > Data Controls > toggle Off — and 'your change in settings will apply to data created after you make that change' (not retroactively). Logged prompts/generations are auto-deleted after 30 days unless flagged or legally required. Zero data retention is available only to enterprise customers making additional usage commitments (via support@cohere.com); usage metadata is still collected under ZDR. Private/VPC/cloud-marketplace deployments send no prompts or generations to Cohere. Trial-key usage may be used for R&D with de-identification.
By the Shieldra Compliance Team · Last updated 2026-07-29
What is Cohere (SaaS API Platform)?
Cohere's Command, Embed, and Rerank models via SaaS API, cloud marketplaces, or private deployment. SMBs use it mainly for RAG/search (embed + rerank) and enterprise chat.
Key facts
- Vendor: Cohere — https://cohere.com
- Trains on customer data by default: yes (SaaS Platform default — opt-out toggle in dashboard)
- Source for the training answer: https://cohere.com/enterprise-data-commitments
- Last verified: 2026-07-29
What certifications does Cohere hold?
- SOC 2 Type II
- ISO 27001
- ISO 42001
Security, DPA, and subprocessor links
- Security / trust page: https://cohere.com/security
- Subprocessor list: https://trustcenter.cohere.com/
What is your EU AI Act role when you build on Cohere?
Building on Cohere's API typically makes you the provider of your downstream AI system under the EU AI Act with Article 50 transparency duties. Given the training-on-by-default SaaS posture, confirm the Data Controls opt-out (or a ZDR/private deployment) before processing customer personal data.
What to record in your AI registry
- Provider: Cohere
- Model type: third party api
- Data typically flowing to the vendor: prompts, generations, embedding corpus text, rerank documents
Sources
- https://cohere.com/enterprise-data-commitments
- https://cohere.com/security
- https://cohere.com/privacy
- https://cohere.com/blog/iso-42001-and-iso-27001-certifications
- https://trustcenter.cohere.com/
Disclaimer
Curated from vendor-published pages on the date above. Vendor terms change - verify against the cited sources before relying on a profile for a procurement decision. Last verified 2026-07-29.
Frequently asked questions
Does Cohere train AI models on your data?
Yes — trains on your data by default. Vendor-stated default: yes (SaaS Platform default — opt-out toggle in dashboard). On Cohere's SaaS Platform, prompts and generations may be used for model training unless the customer opts out: Dashboard Settings > Data Controls > toggle Off — and 'your change in settings will apply to data created after you make that change' (not retroactively). Logged prompts/generations are auto-deleted after 30 days unless flagged or legally required. Zero data retention is available only to enterprise customers making additional usage commitments (via support@cohere.com); usage metadata is still collected under ZDR. Private/VPC/cloud-marketplace deployments send no prompts or generations to Cohere. Trial-key usage may be used for R&D with de-identification.
What certifications does Cohere hold?
Per the vendor's published pages as of 2026-07-29: SOC 2 Type II; ISO 27001; ISO 42001.
What is your EU AI Act role when you build on Cohere?
Building on Cohere's API typically makes you the provider of your downstream AI system under the EU AI Act with Article 50 transparency duties. Given the training-on-by-default SaaS posture, confirm the Data Controls opt-out (or a ZDR/private deployment) before processing customer personal data.