Mistral AI is a French provider. Canvas uses the EU endpoint exclusively, under a zero-data-retention setup: inputs and outputs are not stored.
| Question | Answer |
|---|---|
| Model | Mistral Large, current generation (vision-capable) |
| Use on Canvas | Image recognition during development (e.g. screenshots) and as a selectable build model per repository |
| Provider & legal entity | Mistral AI, Paris, France (RCS Paris 952 418 325): an EU company under EU law |
| Route | La Plateforme, EU endpoint; Canvas does not use Mistral's separately offered US endpoint |
| Data residency | EU |
| Training on your data | No. Mistral does not use paying customers' API data for training |
| Retention by the provider | Zero data retention on the stateless endpoints Canvas uses: inputs and outputs are not stored |
| Human review by the provider | Not applicable; without storage there is nothing to review |
| Encryption | AES-256 at rest, TLS 1.2+ in transit |
| Certifications | SOC 2 Type II, ISO 27001, ISO 27701; evidence via the Mistral Trust Center |
| Transfer mechanism | Public data processing agreement (DPA) with EU Standard Contractual Clauses; on the EU path Canvas uses, no third-country transfer takes place |
Transparency: for certain add-on features, Mistral reserves the right to transfer data to subprocessors outside the EU, protected by safeguards under Art. 46 GDPR. Canvas does not use those features; it uses stateless endpoints under zero data retention only. Mistral publishes its current subprocessor list in its Trust Center.
How model selection works in the product: Documentation, AI models.
Questions about privacy and security: support@canvas.software. Responsible entity: Canvas AILabs GmbH, Knorrpromenade 8, 10245 Berlin, HRB 289368 (Amtsgericht Charlottenburg).