"Mistral" refers to the AI models; "Mistral AI" is the company that developed them. The Mistral models are software (large language models) that generate responses to your prompts. Mistral AI is based in Paris, France.
Bells Up AI runs the Mistral models on Amazon's servers in the United States. Mistral AI itself never receives your prompts, your documents, or the models' responses.
Your data never leaves Amazon's infrastructure. Mistral AI has zero access to your prompts or responses.
| Question | Answer |
|---|---|
| Can Mistral AI access your prompts or documents? | No — Mistral AI never receives them |
| Can Mistral AI train its models on your prompts or documents? | No — Mistral AI has zero access |
| Can Mistral AI employees or contractors review your data? | No — Mistral AI has zero access |
| How long does Mistral AI retain your data? | N/A — Mistral AI never receives your data |
| Does Amazon Bedrock store your prompts or documents? | No — Amazon Bedrock applies zero data retention by default (not stored) |
| Does Amazon train AI on your data? | No — prohibited by contract |
| Does Amazon scan your data for abuse? | Yes — but automated; AWS states no operators of the service can access your inputs or outputs (details) |
| Can Amazon employees or contractors review your prompts or responses? | No — AWS states Amazon Bedrock uses a zero operator access model, so no operators can access your inputs or outputs; content flagged as apparent CSAM may be reviewed for confirmation and reporting. Access to data stored on Amazon's infrastructure is separately limited (details) |
Your data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Amazon Web Services — the cloud provider that runs the model and where your prompts are processed — holds SOC 2 and ISO 27001 certifications.
When you use the Mistral family of AI models through Bells Up AI, three parties are involved in processing your request:
Each party operates under contractual obligations that protect your data. Below, we explain what each party can and cannot do with your data, with citations to the governing contracts.
What Mistral AI Does: Mistral AI develops and trains the Mistral family of AI models. Mistral AI provides the trained model to Amazon for deployment on Amazon's infrastructure.
About Mistral AI: Mistral AI is headquartered in Paris, France. As a European company, Mistral AI is subject to the EU General Data Protection Regulation (GDPR) and French data protection law. Mistral AI states that it complies with both the SOC 2 Type II and ISO 27001/27701 frameworks, and is a signatory to the EU AI Act's General-Purpose AI Code of Practice; the Code's obligations become enforceable by the European Commission on August 2, 2026.
Mistral AI cannot access your prompts, documents, or Mistral's responses. This is a technical restriction. Mistral AI has no access to the Amazon infrastructure where Mistral models are deployed.
Amazon does not provide Mistral AI with access to your prompts, documents, or responses. In order to run AI models like the Mistral models you access through Bells Up AI, Amazon maintains "Model Deployment Accounts", which model developers like Mistral AI do not have access to:
"Model providers don't have any access to those accounts. After delivery of a model from a model provider to [Amazon], Amazon Bedrock will perform a deep copy of a model provider's inference and training software into those accounts for deployment. Because the model providers don't have access to those accounts, they don't have access to Amazon Bedrock logs or to customer prompts and completions."
What this means:
Under Mistral's Partner-Served Deployment Terms (effective May 28, 2026), data processed through partner infrastructure (such as AWS Bedrock) is not used by Mistral for model training. Mistral does not have access to the infrastructure or customer data in partner-served deployments. Attorneys who wish to verify the full terms may review them directly at Mistral's legal page linked above.
Two independent prohibitions prevent training on your data:
While Mistral AI never receives the content of your prompts or responses, Amazon may share non-content usage information with third-party model providers:
"We may share information, that does not include Your Content, about your use of a third-party model with the provider of that third-party model."
This metadata may include:
This metadata is used for billing between Amazon and Mistral AI. It contains no content from your prompts, documents, or responses.
Mistral AI also operates its own direct API service called "La Plateforme." Bells Up AI does not use La Plateforme. However, for transparency, you should know that La Plateforme operates under different, less protective terms than the Bedrock deployment used by Bells Up AI:
| Aspect | Via Bedrock (Bells Up AI) | Via La Plateforme (Direct) |
|---|---|---|
| Data reaches Mistral? | No | Yes |
| Default retention | None (not stored) | 30 days for abuse monitoring |
| Training on your data | No | Opt-in for free/standard tiers; opt-out default for Scale tier |
| Data jurisdiction | AWS region (US) | EU (France) |
None of these La Plateforme terms apply when you use Mistral models through Bells Up AI, because your data never reaches Mistral AI's own infrastructure.
Amazon provides two distinct services relevant to how your data is handled:
What Amazon Bedrock Does: Amazon Bedrock is the service that hosts and runs the Mistral AI models. When you submit a prompt, Bells Up AI sends it to Amazon Bedrock, which processes it through the Mistral model and returns the response.
Amazon Bedrock's Core Commitments:
Zero Operator Access and Zero Data Retention:
"Amazon Bedrock uses a zero operator access (ZOA) data security model. This means no operators of the service can access model input or output. Also, Amazon Bedrock uses a zero data retention (ZDR) data security model. This means that by default, Amazon Bedrock does not store model inputs or outputs."
No Training on Your Data:
Amazon does not use your prompts and responses to train its own models, and does not share them with the model provider. AWS states that retained inputs and outputs (for the limited set of models that require retention) are "stored and processed by AWS and are not shared with third-party model providers."
Data Stays in Region: Your data remains in the Amazon data center region where the request is processed. Bells Up AI uses the us-east-1 (Northern Virginia) region.
The optional “Improve my prompt” tool sends the draft prompt to Amazon Bedrock’s prompt-optimization service. The tool sends your draft prompt to Amazon Bedrock regardless of the model you select. Conversations, documents, and workflow runs are processed by the model you selected.
Amazon Bedrock runs automated content scanning on data processed through the service. If that scanning flags apparent child sexual abuse material, the AWS Service Terms provide:
"If we detect apparent child sexual abuse material ("CSAM"), you agree and instruct that we may: (a) review the flagged input or output to determine if it is CSAM, and (b) report the incident to the National Center for Missing and Exploited Children or other authority."
The Service Terms also provide that, for certain models identified on Amazon's Bedrock abuse-detection documentation, Amazon Bedrock stores inputs and outputs for up to 30 days to detect terms-of-service violations and may review them if a potential violation is detected. None of the models available through Bells Up AI are identified on that list as of this review.
Apart from these provisions, Amazon's abuse-detection documentation states that Amazon Bedrock uses a zero operator access model:
"Amazon Bedrock uses a zero operator access (ZOA) data security model. This means no operators of the service can access model input or output."
What this means:
This automated scanning is narrower in scope than the abuse monitoring systems used by direct API providers like OpenAI or Google, which retain data for up to 30 or 55 days and may involve human review of flagged content. Amazon Bedrock's abuse detection operates at the infrastructure level and does not involve the model provider (Mistral AI).
What This Means: Separately from Amazon Bedrock, the Bells Up AI application itself runs on Amazon's cloud infrastructure. This includes:
Can Amazon Access This Data?
Amazon operates the physical servers and storage infrastructure we use. Amazon's access to data stored on its infrastructure is governed by contract and verified by independent audits, which test whether Amazon's actual practices match its contractual commitments:
Amazon "will not access or use ... Customer Data, except ... as necessary to maintain or provide the Services, or as necessary to comply with the law or a valid and binding order of a governmental body ..."
This prohibits Amazon from using your data to develop Amazon's own AI or other products, or from providing your data to others for such purposes.
Amazon's SOC 2 Type II certification provides independent verification that Amazon maintains and follows these access controls.
Technical Protections:
| Protection | Implementation |
|---|---|
| Encryption in transit | TLS 1.2+ for all communications |
| Encryption at rest | AES-256 for all stored data |
| Server storage | Encrypted at the hardware level |
| Access controls | Credentials managed through Amazon's identity system; no hardcoded passwords |
Bells Up AI's use of Amazon services is governed by:
Under the Data Processing Addendum, Amazon acts as a "data processor" — meaning Amazon processes data on our behalf according to our instructions, rather than controlling or owning the data.
Amazon Bedrock and the underlying infrastructure maintain the following certifications:
We encourage you to review the source documents:
| Document | What It Covers | Link |
|---|---|---|
| Mistral AI Partner-Served Deployment Terms (effective May 28, 2026) | No data access, no training in partner deployments | View |
| Mistral AI Trust Center | Certifications (SOC 2, ISO 27001, ISO 27701) | View |
| Amazon Bedrock Data Protection | No-storage, no-training, no-access commitments | View |
| Amazon Web Services Service Terms | Bedrock-specific terms (Section 50.12), abuse detection, metadata sharing | View |
| Amazon Web Services Data Processing Addendum | Amazon's role as processor, access limitations | View |
| Amazon Bedrock Security & Compliance | Certifications (SOC, ISO, HIPAA) | View |
If you have questions about how your data is protected when using Mistral models through Bells Up AI, contact us at info@bellsup.ai.
This document describes data handling for Mistral models accessed via Amazon Bedrock. Other models available through Bells Up AI have different data flows — see the privacy information page for each model family.
This disclosure is provided for informational purposes. Bells Up AI does not provide legal advice to our customers, and attorneys selecting AI models should exercise their independent professional judgment regarding model selection. We believe prudent AI risk management practices include considering the risks of using particular models and assessing the applicability of specific regulatory and contracting requirements.