Is Framer AI HIPAA compliant?
NoFramer · Design
No documented BAA. Framer does not appear to offer one for Framer AI, so treat it as unsuitable for PHI until confirmed otherwise.
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- Business Associate Agreement
- Not offered
- No BAA was found in Framer's published materials for this service.
- Enterprise route
- Enterprise (excluded from AI training, SOC 2 and ISO 27001 report access, SSO and SCIM, workspace AI-disable)
- For regulated use, validate the BAA, configured service and users under the Enterprise (excluded from AI training, SOC 2 and ISO 27001 report access, SSO and SCIM, workspace AI-disable) contract.
- Default data training
- Opt-out required
- Non-Enterprise customers grant Framer a license to use de-identified inputs and outputs to train Framer AI models; there is no self-serve opt-out on non-Enterprise plans other than the Enterprise contract.
- Business-tier training
- No by default
- Enterprise customer data is not used for training, and third-party model providers are contractually barred from training on it.
Practical risk: Framer holds SOC 2 and ISO 27001, but only Enterprise excludes your site content from AI training; other plans grant a training license by default with no self-serve opt-out. Hosting is US only and Framer states it is not for PHI.
How to make a decision
Check the precise account tier, written contract and intended data before approving Framer AI. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on Framer AI
Is Framer AI GDPR compliant?Is Framer AI SOC 2 compliant?Is Framer AI ISO 27001 certified?Does Framer AI train on your data?
See the full Framer AI risk profile, with every data-handling fact and its source, or browse all rated AI tools.