Loading the catalogue…
Loading the catalogue…
Compliance posture
Sovereignty ladder · how the level was reached
Stav's assessment · serving-side
Mistral AI is a France-incorporated, EU-jurisdiction operator whose core inference infrastructure is self-operated in France, giving it a stronger default sovereignty posture than providers routed wholesale through US hyperscalers. The composite lands in conditional territory because the strongest dimension, security posture, is offset by legal exposure: the EEA-scoped inference subprocessor CoreWeave is itself a US-incorporated company, and a US Google API endpoint option exists for some Studio/API traffic, so CLOUD Act insulation is not absolute despite EU data-residency framing. Serving retention is solid but not maximal — no-training and Zero Data Retention defaults apply only to the Scale plan and stateless endpoints, with feedback and 'Labs models' features able to override opt-outs. Contractual posture is comparatively strong, with a published DPA, transparent subprocessor listing, and GDPR-aligned transfer terms. On balance, Stav assesses Mistral as suitable for sovereign-leaning routed serving with EEA data residency, but not as a fully CLOUD-Act-insulated option; workloads requiring absolute US-jurisdiction exclusion should request the ZDR/Scale-plan configuration and confirm CoreWeave's EEA-only routing contractually.
Core inference runs on Mistral's self-operated France-based compute and an EEA-scoped CoreWeave subprocessor for SaaS products, but a documented US Google API endpoint option exists for Studio/API traffic.
Certifications & legal documents
Endpoints served · 40
Mistral AI is an EEA-incorporated operator, but its EEA inference capacity is delivered via CoreWeave Inc., a US-incorporated subprocessor, plus several US ancillary subprocessors, meaning CLOUD Act reach is not eliminated even for EEA-hosted workloads.
No-training-by-default and Zero Data Retention are available but scoped only to the Scale plan and stateless endpoints, while standard calls retain up to 30 days and 'Labs models'/feedback features can override opt-out settings.
Mistral holds current, sourced SOC 2 Type II, ISO 27001, and ISO 27701 certifications with a public Trust Center, though a May 2026 supply-chain compromise of engineering tooling (contained, no customer data affected) shows residual risk.
A published DPA incorporates GDPR/SCC-style transfer obligations by reference and subprocessors are transparently listed, though explicit audit-rights language is not confirmed.
Risk assessment
Mistral's inference-capacity subprocessor for 'All SaaS' products is CoreWeave Inc., a US-incorporated company, even though the listed processing region is EEA — meaning the operator of the underlying compute is subject to US jurisdiction/CLOUD Act reach independent of where the servers physically sit. source ↗
SUBPROCESSINGGoogle LLC is listed as a cloud infrastructure subprocessor with a 'United States (US API endpoint)' option for Studio/API, meaning some Mistral product traffic can be processed on US soil rather than the EU, despite the EU-hosted sovereignty framing. source ↗
DATA_RESIDENCYSeveral ancillary subprocessors (Stripe, Blackforest Labs, Brave Software, Twilio) are US-based, covering billing, image generation, web search and phone verification features across Vibe/Studio/API products. source ↗
SUBPROCESSINGA third-party software supply-chain attack ('Mini Shai-Hulud') temporarily compromised one of Mistral's codebase management systems in May 2026; Mistral states hosted services and customer data were not affected, but it shows exposure to supply-chain risk in engineering tooling. source ↗
GOVERNANCEStandard (non-ZDR) API calls retain input/output content for up to 30 rolling days for abuse-monitoring purposes before deletion, and stateful products (Agents API, Fine-Tuning API, Libraries, Le Chat) retain data for longer, until account/data deletion — enterprises needing strict zero-retention must explicitly enable Zero Data Retention, which is scoped only to the Scale plan and stateless endpoints. source ↗
SERVING_RETENTIONSafeguards
Core inference/model-serving infrastructure ('Mistral Compute') is self-operated in France, and the EEA-region inference subprocessor (CoreWeave) is scoped to EEA for all SaaS products. source ↗
Mistral holds SOC 2 Type II, ISO/IEC 27001:2022, and ISO/IEC 27701:2019 certifications, with official certificates and attestation letters published on its Trust Center. source ↗
API-sent data is not used for model training by default (Scale plan customers are opted out by default), and Zero Data Retention is available for stateless API endpoints (chat completions, embeddings, moderation, OCR, audio) on the Scale plan. source ↗
A published Data Processing Addendum incorporates GDPR (and CCPA) obligations by reference into the customer Agreement, with defined terms for International Data Transfer and Applicable Data Protection Law. source ↗
Mistral maintains a public Trust Center listing all subprocessors (24 entities) with product scope and country/region, plus a subscription mechanism to be notified of subprocessor changes. source ↗
Mistral publishes incident reports on its Trust Center, including a detailed account of the May 2026 'Mini Shai-Hulud' supply-chain incident and its resolution. source ↗
Privacy-policy issues
Feedback/thumbs-up-down data used for training regardless of opt-out source ↗
The DPA states that if a customer provides in-app 'thumbs up/down' Feedback, Mistral will use that Feedback plus the associated Input and Output, as Controller, to train its models — a carve-out from the general no-training default.
Labs models override opt-out settings source ↗
Enabling 'Labs models' allows data to be used for training regardless of subscription plan or existing opt-out settings, creating a configuration trap for enterprise admins relying on the no-training default.
Zero Data Retention is plan- and endpoint-scoped, not universal source ↗
ZDR is only available on the Scale plan and only for stateless endpoints; stateful products (Agents, batch, conversations, Libraries, Le Chat) retain data until account/data deletion rather than a short fixed window.