Is Midjourney SOC 2 compliant?
UnverifiedMidjourney, Inc. · Image
Not verified. Midjourney, Inc. has not published a SOC 2 report we could confirm for Midjourney.
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- SOC 2 report
- Not verified
- No public SOC 2 report was confirmed. Ask Midjourney, Inc. for current assurance evidence before approving sensitive use.
- ISO 27001
- Not verified
- No ISO/IEC 27001 certification was confirmed in the sources reviewed for this profile.
- Default data training
- Yes by default
- Midjourney's Terms of Service grant it a broad license to reproduce and prepare derivative works of submitted text/image prompts and generated assets, which it uses to train and improve its models by default.
- Business-tier training
- Yes by default
- Paid Pro/Mega users are also subject to model training; Stealth Mode only keeps generations out of the public gallery and Midjourney still retains the license to use them for service improvement.
Practical risk: All prompts and generated images are public by default and licensed for model training, and Stealth Mode (Pro/Mega only) merely hides outputs from the public gallery without exempting them from training, so confidential work-related content should not be used.
How to make a decision
Check the precise account tier, written contract and intended data before approving Midjourney. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on Midjourney
Is Midjourney HIPAA compliant?Is Midjourney GDPR compliant?Is Midjourney ISO 27001 certified?Does Midjourney train on your data?
See the full Midjourney risk profile, with every data-handling fact and its source, or browse all rated AI tools.