ModelCharter

Is Framer AI HIPAA compliant?

No

Framer · Design

No documented BAA. Framer does not appear to offer one for Framer AI, so treat it as unsuitable for PHI until confirmed otherwise.

What we checked

This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.

Business Associate Agreement
Not offered
No BAA was found in Framer's published materials for this service.
Enterprise route
Enterprise (excluded from AI training, SOC 2 and ISO 27001 report access, SSO and SCIM, workspace AI-disable)
For regulated use, validate the BAA, configured service and users under the Enterprise (excluded from AI training, SOC 2 and ISO 27001 report access, SSO and SCIM, workspace AI-disable) contract.
Default data training
Opt-out required
Non-Enterprise customers grant Framer a license to use de-identified inputs and outputs to train Framer AI models; there is no self-serve opt-out on non-Enterprise plans other than the Enterprise contract.
Business-tier training
No by default
Enterprise customer data is not used for training, and third-party model providers are contractually barred from training on it.
Practical risk: Framer holds SOC 2 and ISO 27001, but only Enterprise excludes your site content from AI training; other plans grant a training license by default with no self-serve opt-out. Hosting is US only and Framer states it is not for PHI.

How to make a decision

Check the precise account tier, written contract and intended data before approving Framer AI. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.

More on Framer AI

See the full Framer AI risk profile, with every data-handling fact and its source, or browse all rated AI tools.