30 Days Gen AI Risk Trial -Start Now
Skip to main content
Foundation Model ProvidersAPI pay-per-token; enterprise / on-prem pricing custom

Cohere

Enterprise LLM platform — Command, Embed, and Rerank models with single-tenant deployment options.

Risk score

4/10Medium

Assessment across data handling, compliance, security and transparency.

Overview

Cohere offers enterprise LLM APIs and on-premise / VPC deployments. By default Cohere does not train its production models on customer data submitted via the API; opt-in is required. SOC 2 Type II attested. HIPAA support is available on enterprise contracts but not standard. Notable for offering single-tenant deployments inside the customer's own cloud.

Risk factors

2
  • API access via personal accounts on the free / trial tier lacks enterprise contractual controls
  • No HIPAA BAA on standard plans — requires enterprise contract

Recommendations

3
  • Enforce SSO via the enterprise plan; prohibit personal API keys for business workloads
  • Use VPC / on-prem deployment for regulated data (PHI, classified, export-controlled)
  • Confirm Cohere's zero-retention setting is enabled before production workloads

Data handling

Storage
Cohere's cloud (AWS) by default; VPC / on-prem available on enterprise
Retention
Configurable per tenant; zero-retention available
Training on inputs
Off by default — customer prompts and completions are not used to train production models

See the AI tools in use across your organisation.

Connect your tool research to the employee AI activity and data security questions that matter to your team.