AI Tool Risk Directory
Is that AI tool safe for work?
Before your team uses an AI tool at work, know how it treats your data. We rate 60 popular tools for default at-work use: whether they train on your inputs, how long they keep data, and which certifications they hold. Everything is sourced from the vendor's own policies.
Facts compiled 2026-07-07. Always confirm against the linked source before relying on a fact.
60 of 60 tools
Ada · Customer support
Ada is enterprise-only and says it never trains shared models on your data, holds SOC 2 Type II, publishes subprocessors and offers HIPAA documentation and negotiated EU residency. The open questions are ISO 27001 (not listed on its trust center) and confirming a named BAA before regulated deployment.
Adobe Inc. · Image
The bigger governance question is output provenance and indemnity scope rather than training. Firefly is 'commercially safe' and IP-indemnified mainly for enterprise customers, so individual and free users should not assume the same legal coverage for generated assets.
Airtable · Productivity
Airtable AI does not train models on customer inputs, and Business and Enterprise Scale plans get no third-party retention beyond compliance metadata versus a 30-day window on lower tiers. HIPAA BAA and EU residency are reserved for Enterprise Scale.
Amazon Web Services · Coding
On the Pro tier, Amazon Q Developer is not used for training and stores content in the Region where your profile was created (some features US-only). The Free tier can use your code for model training unless you opt out. Per-service SOC 2 and ISO scope and a BAA for ePHI should be confirmed via AWS Artifact.
Asana · Productivity
Asana states neither it nor its AI partners train on customer data, and partner LLMs must delete inputs and outputs after each query; it holds SOC 2 Type II and ISO 27001 with a HIPAA BAA, DPA, EU residency and SSO reserved for paid plans.
Bland AI · Audio
Bland AI publishes a clearer compliance story than most voice-agent platforms: self-attested SOC 2 Type II, HIPAA with BAA, GDPR with a public DPA and SCCs, plus configurable EU data residency, and calls run through its own models in inference-only mode. ISO 27001 is not listed and SSO is not documented.
StackBlitz · Coding
Bolt.new has a real trust center confirming SOC 2 Type 2 and GDPR, and its Enterprise tier adds SSO and dedicated-tenant deployment. ISO 27001, a HIPAA BAA and a locatable subprocessor list are unconfirmed, and training opt-out is only vaguely plan-dependent.
Canva Pty Ltd · Design
There is a genuine discrepancy between Canva's stated opt-in default and third-party reports of training toggles being on by default for Free/Pro accounts, so an at-work individual user should explicitly verify and disable both 'usage' and 'content' AI-training toggles in privacy settings.
OpenAI · AI assistants
Consumer/free ChatGPT uses your chats for training unless you proactively disable it, so staff pasting work data into personal accounts can leak it into model improvement.
Anthropic · AI assistants
Even when a consumer opts out of training, conversations flagged for safety review can still be retained up to two years and used to improve models without notifying the user.
Anthropic · Coding
Under commercial terms, Claude Code is not trained on, retains data 30 days by default (Zero Data Retention on qualified Enterprise), and rides Anthropic's SOC 2 and ISO 27001 with a BAA available. Consumer accounts are trained on when data-sharing is enabled and can retain data for 5 years.
ClickUp · Productivity
ClickUp Brain does not train on customer data and enforces zero data retention with its LLM partners, backed by SOC 2 Type II and ISO 27001. HIPAA BAA and EU and APAC data residency are available but Enterprise-tier only.
Coda (Grammarly) · Productivity
Coda holds SOC 2 Type II and ISO 27001 and publishes its AI subprocessors, but since Grammarly's acquisition its legal pages redirect to Grammarly documents. Several AI-specific details (no-training claim, retention, EU residency, BAA) could not be independently verified.
Consensus · Search
Consensus is unusually clear that it never trains on your queries or content and does not track individual users by default. It just does not publish any SOC 2, ISO 27001, HIPAA or GDPR DPA documentation, so it is not positioned for regulated or enterprise-compliance use as-is.
Anysphere · Coding
On the free/Pro tier Privacy Mode is opt-in and OFF by default, so an at-work user who does not enable it has their code, prompts and editor actions stored and used to train Cursor's models.
Decagon · Customer support
Decagon confirms zero-day retention with its LLM providers and offers SSO with Okta and Entra, but its SOC 2, ISO 27001 and HIPAA claims appear only as badges without a primary source stating type, scope or date, and no subprocessor list or DPA was found publicly.
DeepSeek (Hangzhou DeepSeek Artificial Intelligence) · AI assistants
The hosted DeepSeek app and API store user prompts and personal data on servers in the People's Republic of China (subject to Chinese law) and use inputs to train models by default. This is a major governance risk that has led to government bans and restrictions in Italy, South Korea, Australia, and multiple US federal agencies.
Cognition · Coding
Devin holds SOC 2 Type II and ISO 27001:2022 with a downloadable DPA and dated all-US subprocessor list. But non-Enterprise customers are opted into model training by default and must turn it off, and there is no EU residency or confirmed BAA.
Dropbox · Search
Dash inherits Dropbox's compliance stack (SOC 2 Type II, its own ISO 27001 certificate and a dedicated subprocessor list) and states content is not used to train third-party models, with a 90-day retention window. Dropbox explicitly excludes Dash from HIPAA BAA coverage, so it is not suitable for PHI on any plan.
ElevenLabs Inc. · Audio
On the default consumer tier your submitted audio/voice data is used to improve models unless you flip the opt-out toggle, and voice cloning carries real consent/likeness-misuse exposure if someone uploads a voice they aren't authorized to clone.
Figma · Design
Figma holds SOC 2 Type II and ISO 27001, and content training defaults off on Organization and Enterprise (on for Starter and Professional unless an admin turns it off). The gap is HIPAA: the AUP bars PHI and no BAA is offered.
Fireflies.ai Corp. · Meetings & notetakers
Fireflies' bot auto-joins calendar meetings to record/transcribe, creating consent exposure, and HIPAA-grade Private Storage plus EU data hosting are gated to Enterprise deals.
Framer · Design
Framer holds SOC 2 and ISO 27001, but only Enterprise excludes your site content from AI training; other plans grant a training license by default with no self-serve opt-out. Hosting is US only and Framer states it is not for PHI.
Gamma Tech, Inc. · Design
On individual Free/Plus plans your presentation content is fed into AI model improvement by default, so an at-work user must manually opt out (or move to a Team/Business workspace) to keep client material out of training.
Google · Coding
On Standard and Enterprise, Gemini Code Assist is not trained on without permission, is stateless, and carries SOC 1/2/3 and ISO 27001 with VPC Service Controls. The free Individual tier is different: code and prompts are collected to improve Google products with human review and up to 18-month retention.
GitHub (Microsoft) · Coding
On individual (free/Pro) plans, code snippets can be retained and used for model improvement unless opted out, so developers on personal accounts may expose proprietary code.
Glean · Search
Glean says it never uses customer data to train models thanks to zero-retention agreements with model providers, offers single-tenant and regional (incl. EU) deployment, and will sign a HIPAA BAA. ISO 27001 status was not independently verifiable from its public pages.
Google · AI assistants
Personal Gemini accounts have human reviewers reading a sample of chats (kept up to 3 years even after you delete activity), so confidential work content typed into a personal account can be seen by reviewers.
Grammarly, Inc. · Writing
On free/Premium consumer tiers Grammarly uses de-identified content for product improvement/training unless you opt out, and HIPAA coverage requires an Enterprise BAA (not available on Free/Premium/Business).
Guru · Productivity
Guru states it does not train on customer content and applies zero-retention handling for data passed to third-party LLMs, backed by SOC 2 Type II with platform-wide SSO, DPA and BAA support. No ISO 27001 certification or EU data-residency option was found.
HeyGen · Video
HeyGen holds SOC 2 Type II and stays US only. On consumer plans HeyGen may use your inputs to improve its models unless you email to opt out, and there is no BAA, so keep PHI out of it.
Ideogram · Image
On the free tier, Ideogram images and prompts are public by default and cannot be deleted, with no stated no-training commitment. Enterprise flips that with SOC 2 controls, a DPA on request, SSO and no shared-model training. No BAA and no verified ISO 27001.
Intercom · Customer support
On the top Expert plan with Regional Data Hosting and a signed BAA, Fin holds SOC 2 Type II and ISO 27001, keeps third-party LLMs out of training, and offers EU residency. Lower plans train Intercom's own models on anonymized data unless you opt out.
Jasper AI, Inc. · Writing
Jasper relies on third-party LLM providers (e.g., OpenAI/Anthropic) under no-training API agreements, so an at-work user's confidential prompts still transit external model vendors and trust rests on contractual rather than self-hosted controls.
Leonardo.Ai (Canva) · Image
Free Leonardo content is public by default and used to improve the service; only paid members can switch on Private Mode. There is a DPA and a SOC 2 commitment, but no verified ISO 27001, no BAA and no enterprise SSO. Fine for creative work, not for regulated data.
Lovable · Coding
Lovable has SOC 2 Type I and II and ISO 27001:2022 and EU, US and Australia data-residency options, but its own pages give conflicting signals on training: marketing says no training while the docs describe an opt-out default. Confirm HIPAA directly since no BAA language was found.
Luma AI · Video
Luma trains on your content on consumer tiers; only Enterprise and API get a contractual no-training guarantee. It is explicitly not HIPAA-ready and has no verified SOC 2 or ISO 27001, so treat it as a creative tool rather than a compliance-grade one.
Microsoft · Productivity
Copilot inherits the user's existing permissions, so over-shared SharePoint/OneDrive content becomes far easier for employees to surface. That is an oversharing and governance risk rather than a training one.
Midjourney, Inc. · Image
All prompts and generated images are public by default and licensed for model training, and Stealth Mode (Pro/Mega only) merely hides outputs from the public gallery without exempting them from training, so confidential work-related content should not be used.
monday.com · Productivity
monday.com states its AI does not train on customer data and enforces Zero Data Retention with its LLM providers, backed by SOC 2 Type II and ISO 27001. HIPAA BAA, EU data residency and SSO are all Enterprise-tier only.
Google · Search
NotebookLM does not train on your uploads or queries on either tier, a genuinely strong default. But Google is explicit that the product carries no SOC 2, ISO 27001 or HIPAA BAA today; for regulated data you would need the separate NotebookLM Enterprise product.
Notion Labs, Inc. · Productivity
Some AI features can optionally enable data-retaining LLMs via workspace settings, so an admin must confirm the workspace stays on zero/short-retention configurations.
Otter.ai, Inc. · Meetings & notetakers
Otter trains its own models on de-identified user content by default and its meeting assistant can auto-join calendar meetings, raising consent and surveillance concerns (it is the subject of a wiretap/consent class action).
Perplexity AI, Inc. · Search
On consumer plans data is used to improve models unless you turn off the default-on 'AI data retention' toggle, and reporting alleges Perplexity shared conversational data with ad/tracking platforms (incl. in Incognito).
Pika · Video
A consumer creative tool with a thin trust posture: Pika may use your inputs and outputs to train its models by default, with no documented opt-out, no DPA, and no published SOC 2 or BAA. Keep confidential or regulated content out of it.
Read AI, Inc. · Meetings & notetakers
The biggest gotcha is the auto-join bot behaviour. Read can be invited by any participant and join meetings automatically, so sensitive conversations may be silently recorded or transcribed unless hosts and participants actively remove it.
Replit · Coding
On the paid Commercial Agreement, Replit will not train on your code and rides a SOC 2 Type II attestation with a DPA and public subprocessor list. Hosting is US-first with no EU residency and no BAA, so it is not positioned for PHI.
Salesforce · Sales & CRM
One of the strongest CRM-AI postures: the Einstein Trust Layer enforces zero data retention with LLM providers, and Salesforce publishes AI-scoped SOC 2 and ISO 27001 reports naming Agentforce and Einstein plus a HIPAA BAA and EU residency via Hyperforce. Some Einstein features are not available in the EU Operating Zone.
Sana Labs · Productivity
Sana states it does not train models on customer data, holds SOC 2 and ISO 27001, and publishes a subprocessor list and DPA. HIPAA BAA availability and a firm EU data-residency guarantee are not documented publicly, so confirm both before handling PHI or EU-restricted data.
Sierra · Customer support
Sierra is ISO 27001 and 42001 certified, lists SOC 2 and HIPAA as maintained standards, and publishes a subprocessor list. Much of the granular detail (no-training commitment, retention, BAA, EU residency, SSO) sits behind a gated trust center and per-customer DPA.
Salesforce · Productivity
The 'no training' guarantee covers generative LLMs, but Slack's non-generative machine-learning features have historically processed customer messages on an opt-out (not opt-in) basis, so admins must proactively review AI/ML data settings rather than assume default protection.
Sourcegraph · Coding
A strong disclosure posture: SOC 2 Type II, ISO 27001:2022, a public DPA and subprocessor list, and a contractual no-training and zero-retention policy. The managed offering is US only (EU residency needs self-hosting).
Synthesia Limited · Video
The main governance gotcha is consent provenance for AI avatars and voices. Synthesia requires documented consent for any likeness, so an at-work user must ensure they have rights to any face or voice they upload to create a custom avatar.
Tabnine · Coding
Tabnine says it never trains on your code, keeps zero code retention, holds SOC 2 and ISO 27001, and can run on-prem or air-gapped. The open questions are a signed BAA and a formal DPA, both unverified on its own pages, so confirm before regulated use.
Vercel · Coding
v0 inherits Vercel's platform compliance program (SOC 2 Type 2, ISO 27001:2022, GDPR DPA, HIPAA BAA availability) rather than v0-specific certs. Its training policy is tier-gated: Hobby and, unless opted out, Pro content can be used to train models.
Vapi · Audio
Vapi's default configuration retains call data and can use it to improve the service; you have to explicitly turn on HIPAA mode to disable storage and training use, and even then you choose HIPAA-compliant providers yourself. Treat it as developer infrastructure that requires deliberate configuration.
Cognition (formerly Codeium) · Coding
Cognition holds SOC 2 Type 2 and ISO 27001, but Windsurf's own terms say customer code may be used for training by default; the opt-out with Zero Data Retention is available only on paid tiers, and free-tier users have no documented opt-out. HIPAA and EU residency are unconfirmed.
You.com · Search
You.com says it does not train models on your data and holds a SOC 2 Type 2 report, with a DPA available. It explicitly is not a HIPAA tool, and EU residency is not guaranteed, so keep PHI and EU-locked data out of it.
Zendesk · Customer support
Zendesk holds SOC 2 Type II and ISO 27001 and 42001 and will sign a BAA via a paid add-on, but it trains its own AI on Service Data by default; you must contact support to opt out, and EU residency and HIPAA are both paid add-ons.
Zoom Communications, Inc. · Meetings & notetakers
AI Companion must process meeting audio/transcripts to function, and those inputs can be retained up to ~30 days for support/debugging, so disabling or admin-scoping the feature is the only way to keep sensitive conversations out of that processing pipeline.
About the directory
- How are the risk ratings calculated?
- Each tool is scored on the data exposure an employee creates by using its default or consumer tier at work: whether it trains on your inputs, retention, and whether it holds SOC 2, ISO 27001, a GDPR DPA, EU data residency, SSO and a HIPAA BAA. The score is transparent: every point is explained on the tool's page.
- Are these facts official?
- Yes. They are compiled from each vendor's privacy policy, DPA and trust centre, with source links on every tool page. Anything we could not verify is shown as Unverified rather than guessed.
- Which AI tools are safest for work?
- Tools that do not train on your data and hold SOC 2 or a GDPR DPA score lowest. On their business tiers, assistants like ChatGPT Enterprise, Claude for Work and Microsoft 365 Copilot rate well. Image tools that train on all inputs, such as Midjourney, rate highest-risk.