ModelCharter

AI Tool Risk Directory

Is that AI tool safe for work?

Before your team uses an AI tool at work, know how it treats your data. We rate 60 popular tools for default at-work use: whether they train on your inputs, how long they keep data, and which certifications they hold. Everything is sourced from the vendor's own policies.

Facts compiled 2026-07-07. Always confirm against the linked source before relying on a fact.

60 of 60 tools

AdaLow risk · 0

Ada · Customer support

Ada is enterprise-only and says it never trains shared models on your data, holds SOC 2 Type II, publishes subprocessors and offers HIPAA documentation and negotiated EU residency. The open questions are ISO 27001 (not listed on its trust center) and confirming a named BAA before regulated deployment.

Adobe FireflyLow risk · 0

Adobe Inc. · Image

The bigger governance question is output provenance and indemnity scope rather than training. Firefly is 'commercially safe' and IP-indemnified mainly for enterprise customers, so individual and free users should not assume the same legal coverage for generated assets.

Airtable AILow risk · 0

Airtable · Productivity

Airtable AI does not train models on customer inputs, and Business and Enterprise Scale plans get no third-party retention beyond compliance metadata versus a 30-day window on lower tiers. HIPAA BAA and EU residency are reserved for Enterprise Scale.

Amazon Q DeveloperMedium risk · 30

Amazon Web Services · Coding

On the Pro tier, Amazon Q Developer is not used for training and stores content in the Region where your profile was created (some features US-only). The Free tier can use your code for model training unless you opt out. Per-service SOC 2 and ISO scope and a BAA for ePHI should be confirmed via AWS Artifact.

Asana AILow risk · 0

Asana · Productivity

Asana states neither it nor its AI partners train on customer data, and partner LLMs must delete inputs and outputs after each query; it holds SOC 2 Type II and ISO 27001 with a HIPAA BAA, DPA, EU residency and SSO reserved for paid plans.

Bland AILow risk · 0

Bland AI · Audio

Bland AI publishes a clearer compliance story than most voice-agent platforms: self-attested SOC 2 Type II, HIPAA with BAA, GDPR with a public DPA and SCCs, plus configurable EU data residency, and calls run through its own models in inference-only mode. ISO 27001 is not listed and SSO is not documented.

Bolt.newLow risk · 20

StackBlitz · Coding

Bolt.new has a real trust center confirming SOC 2 Type 2 and GDPR, and its Enterprise tier adds SSO and dedicated-tenant deployment. ISO 27001, a HIPAA BAA and a locatable subprocessor list are unconfirmed, and training opt-out is only vaguely plan-dependent.

Canva Magic StudioLow risk · 17

Canva Pty Ltd · Design

There is a genuine discrepancy between Canva's stated opt-in default and third-party reports of training toggles being on by default for Free/Pro accounts, so an at-work individual user should explicitly verify and disable both 'usage' and 'content' AI-training toggles in privacy settings.

ChatGPTLow risk · 14

OpenAI · AI assistants

Consumer/free ChatGPT uses your chats for training unless you proactively disable it, so staff pasting work data into personal accounts can leak it into model improvement.

ClaudeLow risk · 16

Anthropic · AI assistants

Even when a consumer opts out of training, conversations flagged for safety review can still be retained up to two years and used to improve models without notifying the user.

Claude CodeLow risk · 16

Anthropic · Coding

Under commercial terms, Claude Code is not trained on, retains data 30 days by default (Zero Data Retention on qualified Enterprise), and rides Anthropic's SOC 2 and ISO 27001 with a BAA available. Consumer accounts are trained on when data-sharing is enabled and can retain data for 5 years.

ClickUp BrainLow risk · 0

ClickUp · Productivity

ClickUp Brain does not train on customer data and enforces zero data retention with its LLM partners, backed by SOC 2 Type II and ISO 27001. HIPAA BAA and EU and APAC data residency are available but Enterprise-tier only.

Coda AIMedium risk · 0

Coda (Grammarly) · Productivity

Coda holds SOC 2 Type II and ISO 27001 and publishes its AI subprocessors, but since Grammarly's acquisition its legal pages redirect to Grammarly documents. Several AI-specific details (no-training claim, retention, EU residency, BAA) could not be independently verified.

ConsensusMedium risk · 0

Consensus · Search

Consensus is unusually clear that it never trains on your queries or content and does not track individual users by default. It just does not publish any SOC 2, ISO 27001, HIPAA or GDPR DPA documentation, so it is not positioned for regulated or enterprise-compliance use as-is.

CursorLow risk · 17

Anysphere · Coding

On the free/Pro tier Privacy Mode is opt-in and OFF by default, so an at-work user who does not enable it has their code, prompts and editor actions stored and used to train Cursor's models.

DecagonMedium risk · 0

Decagon · Customer support

Decagon confirms zero-day retention with its LLM providers and offers SSO with Okta and Entra, but its SOC 2, ISO 27001 and HIPAA claims appear only as badges without a primary source stating type, scope or date, and no subprocessor list or DPA was found publicly.

DeepSeekHigh risk · 81

DeepSeek (Hangzhou DeepSeek Artificial Intelligence) · AI assistants

The hosted DeepSeek app and API store user prompts and personal data on servers in the People's Republic of China (subject to Chinese law) and use inputs to train models by default. This is a major governance risk that has led to government bans and restrictions in Italy, South Korea, Australia, and multiple US federal agencies.

DevinMedium risk · 25

Cognition · Coding

Devin holds SOC 2 Type II and ISO 27001:2022 with a downloadable DPA and dated all-US subprocessor list. But non-Enterprise customers are opted into model training by default and must turn it off, and there is no EU residency or confirmed BAA.

Dropbox DashLow risk · 11

Dropbox · Search

Dash inherits Dropbox's compliance stack (SOC 2 Type II, its own ISO 27001 certificate and a dedicated subprocessor list) and states content is not used to train third-party models, with a 90-day retention window. Dropbox explicitly excludes Dash from HIPAA BAA coverage, so it is not suitable for PHI on any plan.

ElevenLabsLow risk · 15

ElevenLabs Inc. · Audio

On the default consumer tier your submitted audio/voice data is used to improve models unless you flip the opt-out toggle, and voice cloning carries real consent/likeness-misuse exposure if someone uploads a voice they aren't authorized to clone.

Figma AILow risk · 16

Figma · Design

Figma holds SOC 2 Type II and ISO 27001, and content training defaults off on Organization and Enterprise (on for Starter and Professional unless an admin turns it off). The gap is HIPAA: the AUP bars PHI and no BAA is offered.

Fireflies.aiLow risk · 0

Fireflies.ai Corp. · Meetings & notetakers

Fireflies' bot auto-joins calendar meetings to record/transcribe, creating consent exposure, and HIPAA-grade Private Storage plus EU data hosting are gated to Enterprise deals.

Framer AIMedium risk · 32

Framer · Design

Framer holds SOC 2 and ISO 27001, but only Enterprise excludes your site content from AI training; other plans grant a training license by default with no self-serve opt-out. Hosting is US only and Framer states it is not for PHI.

GammaLow risk · 17

Gamma Tech, Inc. · Design

On individual Free/Plus plans your presentation content is fed into AI model improvement by default, so an at-work user must manually opt out (or move to a Team/Business workspace) to keep client material out of training.

Gemini Code AssistLow risk · 19

Google · Coding

On Standard and Enterprise, Gemini Code Assist is not trained on without permission, is stateless, and carries SOC 1/2/3 and ISO 27001 with VPC Service Controls. The free Individual tier is different: code and prompts are collected to improve Google products with human review and up to 18-month retention.

GitHub CopilotLow risk · 17

GitHub (Microsoft) · Coding

On individual (free/Pro) plans, code snippets can be retained and used for model improvement unless opted out, so developers on personal accounts may expose proprietary code.

GleanLow risk · 0

Glean · Search

Glean says it never uses customer data to train models thanks to zero-retention agreements with model providers, offers single-tenant and regional (incl. EU) deployment, and will sign a HIPAA BAA. ISO 27001 status was not independently verifiable from its public pages.

Google GeminiLow risk · 14

Google · AI assistants

Personal Gemini accounts have human reviewers reading a sample of chats (kept up to 3 years even after you delete activity), so confidential work content typed into a personal account can be seen by reviewers.

GrammarlyLow risk · 16

Grammarly, Inc. · Writing

On free/Premium consumer tiers Grammarly uses de-identified content for product improvement/training unless you opt out, and HIPAA coverage requires an Enterprise BAA (not available on Free/Premium/Business).

GuruLow risk · 0

Guru · Productivity

Guru states it does not train on customer content and applies zero-retention handling for data passed to third-party LLMs, backed by SOC 2 Type II with platform-wide SSO, DPA and BAA support. No ISO 27001 certification or EU data-residency option was found.

HeyGenMedium risk · 28

HeyGen · Video

HeyGen holds SOC 2 Type II and stays US only. On consumer plans HeyGen may use your inputs to improve its models unless you email to opt out, and there is no BAA, so keep PHI out of it.

IdeogramLow risk · 20

Ideogram · Image

On the free tier, Ideogram images and prompts are public by default and cannot be deleted, with no stated no-training commitment. Enterprise flips that with SOC 2 controls, a DPA on request, SSO and no shared-model training. No BAA and no verified ISO 27001.

Intercom FinLow risk · 14

Intercom · Customer support

On the top Expert plan with Regional Data Hosting and a signed BAA, Fin holds SOC 2 Type II and ISO 27001, keeps third-party LLMs out of training, and offers EU residency. Lower plans train Intercom's own models on anonymized data unless you opt out.

JasperLow risk · 0

Jasper AI, Inc. · Writing

Jasper relies on third-party LLM providers (e.g., OpenAI/Anthropic) under no-training API agreements, so an at-work user's confidential prompts still transit external model vendors and trust rests on contractual rather than self-hosted controls.

Leonardo AILow risk · 22

Leonardo.Ai (Canva) · Image

Free Leonardo content is public by default and used to improve the service; only paid members can switch on Private Mode. There is a DPA and a SOC 2 commitment, but no verified ISO 27001, no BAA and no enterprise SSO. Fine for creative work, not for regulated data.

LovableLow risk · 16

Lovable · Coding

Lovable has SOC 2 Type I and II and ISO 27001:2022 and EU, US and Australia data-residency options, but its own pages give conflicting signals on training: marketing says no training while the docs describe an opt-out default. Confirm HIPAA directly since no BAA language was found.

Luma AI (Dream Machine)Medium risk · 44

Luma AI · Video

Luma trains on your content on consumer tiers; only Enterprise and API get a contractual no-training guarantee. It is explicitly not HIPAA-ready and has no verified SOC 2 or ISO 27001, so treat it as a creative tool rather than a compliance-grade one.

Microsoft 365 CopilotLow risk · 0

Microsoft · Productivity

Copilot inherits the user's existing permissions, so over-shared SharePoint/OneDrive content becomes far easier for employees to surface. That is an oversharing and governance risk rather than a training one.

MidjourneyHigh risk · 100

Midjourney, Inc. · Image

All prompts and generated images are public by default and licensed for model training, and Stealth Mode (Pro/Mega only) merely hides outputs from the public gallery without exempting them from training, so confidential work-related content should not be used.

monday AILow risk · 0

monday.com · Productivity

monday.com states its AI does not train on customer data and enforces Zero Data Retention with its LLM providers, backed by SOC 2 Type II and ISO 27001. HIPAA BAA, EU data residency and SSO are all Enterprise-tier only.

NotebookLMMedium risk · 51

Google · Search

NotebookLM does not train on your uploads or queries on either tier, a genuinely strong default. But Google is explicit that the product carries no SOC 2, ISO 27001 or HIPAA BAA today; for regulated data you would need the separate NotebookLM Enterprise product.

Notion AILow risk · 0

Notion Labs, Inc. · Productivity

Some AI features can optionally enable data-retaining LLMs via workspace settings, so an admin must confirm the workspace stays on zero/short-retention configurations.

Otter.aiLow risk · 23

Otter.ai, Inc. · Meetings & notetakers

Otter trains its own models on de-identified user content by default and its meeting assistant can auto-join calendar meetings, raising consent and surveillance concerns (it is the subject of a wiretap/consent class action).

PerplexityLow risk · 20

Perplexity AI, Inc. · Search

On consumer plans data is used to improve models unless you turn off the default-on 'AI data retention' toggle, and reporting alleges Perplexity shared conversational data with ad/tracking platforms (incl. in Incognito).

PikaHigh risk · 100

Pika · Video

A consumer creative tool with a thin trust posture: Pika may use your inputs and outputs to train its models by default, with no documented opt-out, no DPA, and no published SOC 2 or BAA. Keep confidential or regulated content out of it.

Read AILow risk · 19

Read AI, Inc. · Meetings & notetakers

The biggest gotcha is the auto-join bot behaviour. Read can be invited by any participant and join meetings automatically, so sensitive conversations may be silently recorded or transcribed unless hosts and participants actively remove it.

ReplitMedium risk · 28

Replit · Coding

On the paid Commercial Agreement, Replit will not train on your code and rides a SOC 2 Type II attestation with a DPA and public subprocessor list. Hosting is US-first with no EU residency and no BAA, so it is not positioned for PHI.

Salesforce Einstein / AgentforceLow risk · 0

Salesforce · Sales & CRM

One of the strongest CRM-AI postures: the Einstein Trust Layer enforces zero data retention with LLM providers, and Salesforce publishes AI-scoped SOC 2 and ISO 27001 reports naming Agentforce and Einstein plus a HIPAA BAA and EU residency via Hyperforce. Some Einstein features are not available in the EU Operating Zone.

SanaLow risk · 0

Sana Labs · Productivity

Sana states it does not train models on customer data, holds SOC 2 and ISO 27001, and publishes a subprocessor list and DPA. HIPAA BAA availability and a firm EU data-residency guarantee are not documented publicly, so confirm both before handling PHI or EU-restricted data.

SierraMedium risk · 0

Sierra · Customer support

Sierra is ISO 27001 and 42001 certified, lists SOC 2 and HIPAA as maintained standards, and publishes a subprocessor list. Much of the granular detail (no-training commitment, retention, BAA, EU residency, SSO) sits behind a gated trust center and per-customer DPA.

Slack AILow risk · 0

Salesforce · Productivity

The 'no training' guarantee covers generative LLMs, but Slack's non-generative machine-learning features have historically processed customer messages on an opt-out (not opt-in) basis, so admins must proactively review AI/ML data settings rather than assume default protection.

Sourcegraph CodyLow risk · 9

Sourcegraph · Coding

A strong disclosure posture: SOC 2 Type II, ISO 27001:2022, a public DPA and subprocessor list, and a contractual no-training and zero-retention policy. The managed offering is US only (EU residency needs self-hosting).

SynthesiaLow risk · 0

Synthesia Limited · Video

The main governance gotcha is consent provenance for AI avatars and voices. Synthesia requires documented consent for any likeness, so an at-work user must ensure they have rights to any face or voice they upload to create a custom avatar.

TabnineLow risk · 0

Tabnine · Coding

Tabnine says it never trains on your code, keeps zero code retention, holds SOC 2 and ISO 27001, and can run on-prem or air-gapped. The open questions are a signed BAA and a formal DPA, both unverified on its own pages, so confirm before regulated use.

v0Low risk · 16

Vercel · Coding

v0 inherits Vercel's platform compliance program (SOC 2 Type 2, ISO 27001:2022, GDPR DPA, HIPAA BAA availability) rather than v0-specific certs. Its training policy is tier-gated: Hobby and, unless opted out, Pro content can be used to train models.

VapiMedium risk · 28

Vapi · Audio

Vapi's default configuration retains call data and can use it to improve the service; you have to explicitly turn on HIPAA mode to disable storage and training use, and even then you choose HIPAA-compliant providers yourself. Treat it as developer infrastructure that requires deliberate configuration.

WindsurfLow risk · 17

Cognition (formerly Codeium) · Coding

Cognition holds SOC 2 Type 2 and ISO 27001, but Windsurf's own terms say customer code may be used for training by default; the opt-out with Zero Data Retention is available only on paid tiers, and free-tier users have no documented opt-out. HIPAA and EU residency are unconfirmed.

You.comLow risk · 21

You.com · Search

You.com says it does not train models on your data and holds a SOC 2 Type 2 report, with a DPA available. It explicitly is not a HIPAA tool, and EU residency is not guaranteed, so keep PHI and EU-locked data out of it.

Zendesk AILow risk · 19

Zendesk · Customer support

Zendesk holds SOC 2 Type II and ISO 27001 and 42001 and will sign a BAA via a paid add-on, but it trains its own AI on Service Data by default; you must contact support to opt out, and EU residency and HIPAA are both paid add-ons.

Zoom AI CompanionLow risk · 0

Zoom Communications, Inc. · Meetings & notetakers

AI Companion must process meeting audio/transcripts to function, and those inputs can be retained up to ~30 days for support/debugging, so disabling or admin-scoping the feature is the only way to keep sensitive conversations out of that processing pipeline.

About the directory

How are the risk ratings calculated?
Each tool is scored on the data exposure an employee creates by using its default or consumer tier at work: whether it trains on your inputs, retention, and whether it holds SOC 2, ISO 27001, a GDPR DPA, EU data residency, SSO and a HIPAA BAA. The score is transparent: every point is explained on the tool's page.
Are these facts official?
Yes. They are compiled from each vendor's privacy policy, DPA and trust centre, with source links on every tool page. Anything we could not verify is shown as Unverified rather than guessed.
Which AI tools are safest for work?
Tools that do not train on your data and hold SOC 2 or a GDPR DPA score lowest. On their business tiers, assistants like ChatGPT Enterprise, Claude for Work and Microsoft 365 Copilot rate well. Image tools that train on all inputs, such as Midjourney, rate highest-risk.