SOC2C

Is this your company? Buyers are checking Mistral AI here. Claim mistral.ai free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Mistral AI logo

Mistral AI

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Mistral AI is SOC 2 Type II compliant. Mistral AI also holds ISO 27001, ISO 27701, and GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Mistral AI is the European leader in generative artificial intelligence models, providing open and portable generative AI for developers and businesses.

Compliance & infrastructure

Subprocessors

14
  • M
    Microsoft Inc. · Cloud Infrastructure
    Sweden, Norway
  • G
    Google LLC · Cloud Infrastructure
    Netherlands, United States
  • S
    Stripe Inc. · Payment and Billing
    United States
  • G
    Get Lago Corp. · Billing
    Ireland
  • B
    Blackforest Labs Inc. · Image Generation
    United States
  • B
    Brave Software, Inc. · Web Search
    United States
  • F
    Foundrylabs, Inc. · Code Interpreter (E2B.dev)
    France, Belgium, Netherlands
  • I
    Intercom Inc. · User support
    Ireland
  • K
    Kong Inc. · Security (API)
    EEA
  • O
    Ory Corp. · User Authentication
    Belgium, Germany
  • M
    Merge API Inc. · Connectors on Le Chat - Transfer ACL and data from the third-party service to le
    United States
  • P
    Plus Five Five, Inc. (Resend) · Email communications
    Ireland
Show all 14 subprocessors
  • T
    Twilio Inc. · Phone number verification
    United States
  • C
    CoreWeave · Inference provider
    EEA

Compliance leadership

The person who leads Mistral AI's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Mistral AI's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Mistral AI’s response to Mini Shai-Hulud security incidentMay 2026

A group of attackers temporarily compromised one of our codebase management systems on Tuesday, 26/05/12, through a third-party software supply chain attack described as Mini Shai-Hulud. Go to https://docs.mistral.ai/resources/security-advisories for more information. We rapidly neutralized the attack and mitigated its effects. We took the necessary actions to fully secure our infrastructure and support our customers with guidelines. The investigation is now closed. The attackers were not able to access anything other than certain non-core code repositories. Neither our hosted services, managed user data, nor any of our research and testing environments were compromised.

Addition of a new subprocessor for Le ChatMay 2025

We are writing to inform you of a recent addition to Mistral AI's subprocessor list for Le Chat, effective as of May 7th 2025: Merge. We use Merge to provide our new "Connector" feature on Le Chat. Merge allows us to retrieve the ACL (Access Control List) from the third-party service you connect to our Mistral AI Products, as applicable. The data retrieved by Merge is transferred to the United States. Merge will not process your personal data unless you activate this new feature in your workspace. If you would like to receive email notifications of changes to our subprocessors list, you can subscribe by clicking on the bell icon and adding your email address.

Addition of a subscription buttonApr 2025

Welcome to Mistral AI's Trust Center! With this platform, we provide you with the latest updates related to our Trust Center. Starting today, you can subscribe to receive notifications by clicking the subscription button (bell icon at the top right) and registering your email address. We will only send you notifications about important updates, such as: - Changes to our list of subprocessors (additions or removals), - The release of new security reports.

This listing is partial

5/11 details · 45%

SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Hosting
    Add where you host (AWS, GCP, Azure) and data residency.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Mistral AI SOC 2 compliant?
Mistral AI is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Mistral AI ISO 27001 certified?
According to Mistral AI's public trust center, Mistral AI is ISO 27001 certified. On SOC2C this listing is Listed.
Is Mistral AI ISO 27701 certified?
According to Mistral AI's public trust center, Mistral AI is ISO 27701 certified. On SOC2C this listing is Listed.
Is Mistral AI GDPR compliant?
According to Mistral AI's public trust center, Mistral AI is GDPR compliant. On SOC2C this listing is Listed.
Is Mistral AI SOC 2 Type I or Type II?
Mistral AI is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.