Foreign AI Models

Mistral AI Vendor Risk Profile

European AI company developing open-weight and commercial LLMs for enterprise.

Last verified: October 1, 2026Jurisdictional Due Diligence RequiredReview RequiredElevated RiskReview RequiredHIPAA: Review Required

Risk Score

66

/100

AI Trust

66

/100

Compliance Overview

HIPAA Compatible

Review Required

BAA Available

Review Required

BAA Notes

Available for qualifying services

Hosting Model

—

Healthcare Focused

—

Approval Status

Review Required

Risk Level

Elevated Risk

Last Reviewed

2026-07-14

Last Verified

October 1, 2026

Review Frequency

Quarterly

Verification reflects VNDRIQ's latest automated source check. Editorial review is a separate human assessment.

AI & Data Policies

AI Training Policy

Excluded from product improvement training per privacy policy

Data Retention Policy

30-day default for API; user-controlled for Vibe; ZDR for Scale plan

Support Access Risk

—

Deployment & Data Residency

Deployment Type

Open Weight, Hosted API

Model Type

Foundation Model, LLM

Deployment Environment

Cloud, Open Weight

Hosting Regions

Europe, Global

Available Regions

—

Data Residency

—

Customer Data Residency Options

—

Cross-Border Data Transfer

—

Data Residency Controls

—

Executive Summary

Primary Use Cases

European AI company developing open-weight and commercial LLMs for enterprise.

Major Strengths

HIPAA Readiness

Key Procurement Considerations

Product MaturityHealthcare FocusCustomer Support Information

Security Highlights

Encryption at rest

Compliance Highlights

HIPAA claimed

Vendor Trust Score

Limited Trust Data

16

/100

HIPAA Readiness50
BAA Availability17
Security Controls33
Governance Documentation0*
Transparency0*
Product Maturity0*
Healthcare Focus0*
Integration Readiness25
Customer Support Information0*
Compliance Documentation25

Informational framework based on publicly available and registry data. Not a certification or guarantee. Asterisks indicate categories with limited registry data.

Security & Compliance Dashboard

Standardized view of available registry security information. Not Verified indicates the registry has no documented data.

HIPAA StatusClaimed
BAA AvailabilityNot Verified
SOC 2SOC 2 Type II compliant
ISO 27001ISO/IEC 27001:2022 certified
HITRUSTNot Verified
Encryption at RestYes
Encryption in TransitYes
Single Sign-On (SSO)Not Verified
Multi-Factor AuthNot Verified
Audit LoggingNot Verified
Role-Based AccessNot Verified
Data ResidencyNot Verified
Public Security DocsNot Verified
Incident ResponseNot Verified

AI Governance Maturity

Foundational13/100

Minimal governance documentation; early-stage controls.

Foundational
Developing
Established
Advanced
Leading

Assessed Indicators

Governance Documentation
Human Oversight
AI Policies
Compliance Transparency
Risk Management
Security Controls
Operational Governance

Procurement Risk Considerations

Informational considerations for procurement evaluation, not definitive ratings.

Governance Maturity

Foundational

Elevated Consideration

Security Readiness

33/100 security controls

Elevated Consideration

Compliance Readiness

25/100 compliance documentation

Elevated Consideration

Integration Complexity

API available — lower complexity

Low Consideration

Operational Complexity

Not Verified

Vendor Transparency

0/100 transparency

Elevated Consideration

Healthcare Experience

Healthcare focus not verified

Moderate Consideration

Documentation Completeness

0/100 governance docs

Elevated Consideration

Vendor Lifecycle & Change History

Available registry milestones. Detailed change tracking expands as the registry matures.

Profile Updated

2026-10-01

Last Website Review

2026-10-01

Last Verification

2026-10-01

Last Registry Review

2026-07-14

Registry Added

2026-07-14

Sovereign AI Risk

Factual enterprise due diligence information for jurisdictional, procurement, and governance decision-making. Country of origin alone does not determine enterprise suitability.

Headquarters Jurisdiction

France (EU)

Primary Development Country

France

Hosting Country

EU / Global

Jurisdictional Review Status

Jurisdictional Due Diligence Required

Regulated Use Assessment

Healthcare

Additional Due Diligence Required

HIPAA Compatibility

Review Required

BAA Availability

Review Required

Financial Services

Vendor Due Diligence Required

VNDRIQ does not classify vendors as HIPAA Compliant, SEC Compliant, or FINRA Approved unless official evidence exists. Vendor suitability depends on each organization's governance requirements, contractual obligations, deployment model, risk tolerance, and applicable regulations.

Quick Facts

Category

Foreign AI Models

Country

France

Headquarters

Paris, France

Year Founded

2023

Deployment Type

Open Weight, Hosted API

Model Type

Foundation Model, LLM

Website

mistral.ai
Verified

Risk Score

66/100

AI Trust Score

66/100

Last Reviewed

2026-07-14

Last Verified

October 1, 2026

Request Vendor Evaluation

Get a structured risk assessment and governance recommendation for Mistral AI.

Vendor Governance

Approval Tier

Restricted / Review Required

BAA Verification

Not Started

PHI Exposure

High

AI Risk Level

High

Last Review

2026-10-01

Verification Status

Verified

Last Verified

2026-10-01

Review Frequency

Quarterly

Vendor Completeness Score

100/100

Complete

Website Present

+20

Category Assigned

+15

Approval Status Present

+15

BAA Status Present

+15

PHI Exposure Classified

+10

Risk Level Present

+10

Review Date Present

+10

Verification Notes Present

+5

Trust & Transparency

Last Reviewed Date

2026-07-14

Review Frequency

Quarterly

Vendor Verification Process

Every vendor is reviewed against public documentation, trust centers, and contract evidence before classification.

Editorial Independence Statement

VNDRIQ classifications are independent of vendor relationships. Ratings reflect available evidence and governance risk only.

Registry Update Policy

The registry is reviewed on a monthly cycle. All updates are editor-reviewed before publication; no automated public data changes.

Editorial Methodology

Vendors are evaluated across compliance, security, AI governance, and enterprise readiness. Each review follows a standardized 12-point checklist covering website, HIPAA, BAA, security, compliance, AI capabilities, deployment, pricing, product changes, ownership, integrations, and documentation.

Trust Signals

Editorial Review StatusPending Review
Last Reviewed2026-07-14
Last Updated2026-10-01
Verification Date2026-10-01
Registry ConfidenceNot Verified
Governance MaturityFoundational
Trust Score16/100
Compliance SnapshotSOC2, HIPAA
Security SnapshotEncryption

Vendor Benchmarking

Comparison against registry averages where supported. Benchmarks are informational and based on registry data.

Governance Maturity13 ↑ 8 vs avg 5
Security Readiness33 ↑ 20 vs avg 13
Documentation Completeness0 ↑ 0 vs avg 0
Integration Readiness25 ↑ 13 vs avg 12
Healthcare Specialization0 ↑ 0 vs avg 15
Compliance Transparency25 ↑ 16 vs avg 9
Overall Trust Score16 ↑ 6 vs avg 10
This vendorRegistry average

VNDRIQ provides enterprise due diligence information.

Vendor profiles support governance and procurement decision-making. VNDRIQ does not provide legal advice. Vendor approval depends on each organization's governance requirements, contractual obligations, deployment model, risk tolerance, and applicable regulations.

Country of origin alone should never determine enterprise suitability. All foreign AI vendors are listed as "Under Review" with "Jurisdictional Due Diligence Required" until an organization completes its own governance review.

Ask VNDRIQ About This Vendor

Ask questions about Mistral AI using registry data.

Ask VNDRIQ About Healthcare AI Vendors

Explore healthcare AI vendors, compare capabilities, identify documentation gaps, and understand procurement and governance considerations using information from the VNDRIQ registry.

Suggested prompts

VNDRIQ provides vendor intelligence and educational procurement support. Responses do not constitute legal, medical, cybersecurity, compliance, or procurement advice. Vendor information may be incomplete, vendor-reported, under review, or subject to change.

Do not enter patient information, PHI, passwords, or sensitive data.

VNDRIQ vendor ratings are for operational risk screening and governance support. Final approval should include legal, compliance, security, and contract review before any PHI or regulated data is shared. Risk classifications are based on available public information and internal review at time of last verification.