Every field is source-linked and dated.See the rubric behind the grades.

How we grade
Sovereign AI Registry
ExploreBlogGov accessCertsCountries

Footer

Sovereign AI Registry

The compliance registry for AI vendors. Data residency, training defaults, retention, subprocessors and EU AI Act posture — one row per vendor, product and deployment, every claim linked to its source.

Registry

  • Explore vendors
  • Deployment models
  • Categories
  • Countries

Compliance

  • Gov access exposure
  • EU AI Act roles
  • Certifications

Resources

  • FAQ
  • Methodology
Built with ShipMore·Build yours →

© 2026 Sovereign AI Registry. All rights reserved.

  1. Explore
  2. North (secure agent platform)
N(

North (secure agent platform)

Sovereignty grade A (87/100). You control where it runs; no training on your data; on-prem. Cohere, Canada.

Category
foundation-model
Categories
Foundation model
EU AI Act role
General-purpose AI (GPAI)
Certifications
ISO 27001ISO 42001SOC 2 Type II
Government access exposure
No non-EU government access
Deployments
On-premise

Details

Deployment
on-prem
Hq Country
Canada
Hq City
Toronto
Ownership
private
Founded
2019
Trust Center Url
trustcenter.cohere.com
Training Default
never
Residency Options
your-infrastructure (on-prem), VPC, air-gapped, any cloud
Gov Access Exposure
none-eu
Eu Ai Act Role
gpai
Certs
ISO 27001, ISO 42001, SOC 2 Type II, UK Cyber Essentials
DPA available
yes
Zero Retention Available
Yes
Self Host Option
Yes
Retention Default
On-prem/VPC/air-gapped: customer-controlled — Cohere never receives prompts or generations.
Retention Exceptions
Managed SaaS (a different deployment) is opt-OUT (training default in) via dashboard, 30-day retention, ZDR enterprise-only. HIPAA BAA is narrow (custom-model dev only, not SaaS).
Subprocessor Count
0
Transfer Mechanism
intra-eu
Eu Procurement Ready
pass
Eu Procurement Reason
On-prem deployment: no vendor-side data flow, zero subprocessors, customer-controlled retention. Vendor jurisdiction (Canada/US) is not in the data path.
Last Policy Change
2025-06-27T00:00:00.000Z
Change Summary
Cohere achieved ISO 42001 (AI management system) and ISO 27001 certifications; North reached general availability (Aug 2025).
Prior Value
Held SOC 2 Type II only; no AI-management-system certification.
Training Evidence Url
cohere.com/enterprise-data-commitments
Training Claim Basis
stated
Training Confidence
high
Residency Evidence Url
cohere.com/deployment-options
Residency Claim Basis
stated
Residency Confidence
high
Retention Evidence Url
cohere.com/enterprise-data-commitments
Retention Claim Basis
stated
Retention Confidence
high
Subprocessors Evidence Url
trustcenter.cohere.com
Subprocessors Claim Basis
inferred
Subprocessors Confidence
high
Residency Class
customer-controlled
Portability / Exit Path
proprietary-only
Subprocessor Jurisdiction
structurally-none

Change history

  1. Aug 3, 2026Eu Procurement Ready

    conditional → pass

  2. Aug 3, 2026Governance Grade

    B+ → A

  3. Aug 3, 2026Eu Procurement Ready

    pass → conditional

  4. Aug 3, 2026Governance Grade

    A- → B+

At a glance
Governance Grade
A
Governance Score
87
EC SOV-2 Legal & Jurisdictional (0-4)
3
EC SOV-3 Data & AI (0-4)
3
Website

Similar

Fathom · Aug 2026

FAFathom AI notetaker

Sovereignty grade D (35/100). No EU residency. Fathom, United States.

meeting-ai
Governance Grade
D
Granola · Sep 2026

GAGranola AI notepad

Sovereignty grade D (30/100). No EU residency. Granola, United States.

meeting-ai
Governance Grade
D
Fireflies.ai · Sep 2026

FNFireflies.ai notetaker

Sovereignty grade D (40/100). No EU residency; no training on your data. Fireflies.ai, United States.

meeting-ai
Governance Grade
D

More Categories

  • Coding assistant15
  • meeting-ai13
  • Sovereign host13
  • Inference host13
  • SaaS-embedded11
  • Foundation model11
  • Cloud platform7

More EU AI Act role

  • Deployer59
  • General-purpose AI (GPAI)10
  • provider9
  • GPAI with systemic risk5

More Certifications

  • SOC 2 Type II46
  • ISO 2700136
  • ISO 4200113
  • ISO 270177
  • ISO 277017
  • ISO 270186
  • HDS5
  • HIPAA4
  • CSA STAR4
  • C54
  • ISO 90013
  • PCI DSS3
  • FedRAMP High3
  • ISO 27001:20223
  • SOC 2 (type unverified)2
  • ISO 500012
  • BSI C52
  • SOC 32
  • FedRAMP2
  • GDPR2
  • CSA STAR Level 12

More Government access exposure

  • US CLOUD Act44
  • No non-EU government access27
  • Mixed jurisdiction9
  • PRC National Intelligence Law2

More Deployments

  • Hosted API68
  • Self-hosted weights6
  • On-premise6
  • Private VPC2