Mistral first-party API, default zero data retention: terms and exceptions
ZDR 2.0 (f) · B
Short answer
30d rolling abuse logs; EU storage; no training on API traffic in the published ZDR docs. Agents, batch, and files sit outside the ZDR path; Labs models train regardless.
Scope and evidence
| Provider | Mistral |
|---|---|
| Service | first-party API, default |
| Lane | API default |
| Origin | |
| License | open-weight |
| Hosting | Self-host |
| Score | ZDR 2.0 (f) · B Bounded retention. Content retained a defined window (<=90d) for abuse monitoring, possibly human-reviewed, then deleted |
| Evidence | Public documentation reviewed (B: published documentation) |
| Source-review date | 2026-08-25 |
Other lanes for Mistral
Structured breakdown
- Default posture
- 30d rolling abuse logs; EU storage; no training on API traffic in the published ZDR docs.
- Exceptions and carve-outs
- agents, batch, and files sit outside the ZDR path; Labs models train regardless
Approval and setup path
application: paid plans, stated justification, discretionary approval
Flags on this record
- f
- stateful-feature carve-outs (files, batch, threads, caching, grounding)
Practical questions for your agreement
- Does your signed agreement cover this exact service, model set, and feature path?
- Which retention, logging, and human-review exceptions still apply after any ZDR election?
- What configuration evidence (flags, project settings, store defaults) confirms the posture you expect?
- Do your customer commitments match what the reviewed evidence supports?
Does your agreement cover this deployment?
We can review the relevant terms, feature choices, and customer commitments, then help your team identify what to clarify or negotiate.
Sources
Trust and security
- Trust Center trust.mistral.ai
Posture ledger
seeded
ZDR 2.0 (f) · B
Seeded from published documentation.
Full key on the scale. Method notes on methodology. Notation is always ZDR 1.0 (s,f,r) · A.