Mosaic AI
databricks.com
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
- No clear commitment that your data will not train their models
- Data retention window not stated
See Before you sign, with what to ask for ↓
Scanned Sep 1, 2026 · Public evidence · Point-in-time
Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.
Before you sign
Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.
What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.
Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.
What to ask for: Get retention windows, in days, in writing.
“In accordance with OpenAI's public safety retention policy , for gpt-5.5 , gpt-5.5-pro and future models, OpenAI may retain certain coding and routing customers' customer content that OpenAI's classifiers detect as potentially violating OpenAI's usage policies when using these models. Otherwise retention will not be affected.”
“For Anthropic's Fable 5 and future Mythos-class models, all customers are subject to data retention for safety purposes, as described in Anthropic's data retention practices .”
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
!Will they train on your data?Ask the vendor
Not found in the public sources scanned — ask the vendor directly.
!How long do they keep your data?Ask the vendor
Databricks documents OpenAI's safety retention policy in its own product documentation: for gpt-5.5, gpt-5.5-pro and future models, OpenAI may retain content its classifiers flag as potentially violating usage policies for customers doing software engineering or acting as model-access intermediaries.
Requires written confirmation — see Before you sign ↓
“In accordance with OpenAI's public safety retention policy , for gpt-5.5 , gpt-5.5-pro and future models, OpenAI may retain certain coding and routing customers' customer content that OpenAI's classifiers detect as potentially violating OpenAI's usage policies when using these models. Otherwise retention will not be affected.”
“For Anthropic's Fable 5 and future Mythos-class models, all customers are subject to data retention for safety purposes, as described in Anthropic's data retention practices .”
✓Who else can access your data?Clear
Anthropic, PBC and OpenAI, L.L.C. are both registered as subprocessors for AI-backed services in the United States, each marked "Customer Selected" - so their engagement follows a customer decision rather than being a platform default.
“Anthropic, PBC AI-backed services United States Customer Selected Anthropic Resources OpenAI, L.L.C. AI-backed services United States Customer Selected OpenAI resources”
✓Where is your data processed?Clear
Databricks publishes a Data Processing Addendum incorporating the Standard Contractual Clauses, forming part of the Master Cloud Services Agreement governing use of the Databricks Services.
“This Data Processing Addendum, including its Annexes and the Standard Contractual Clauses (“DPA”), forms an integral part of the Databricks Master Cloud Services Agreement, or any other written agreement that governs Customer's use of the Databricks Services (as defined below) entered into between the entity identified as the “Customer””
!What happens in a security incident?Ask the vendor
Databricks publishes an RFC 9116 security.txt naming a security contact, a PGP key, its trust page as policy and a HackerOne bug bounty programme.
Confirm in writing: Ask the vendor to state this in writing before signing.
“Policy: https://www.databricks.com/trust Contact: [email protected] Encryption: https://www.databricks.com/.well-known/pgp-key.txt Preferred-Languages: en Canonical: https://www.databricks.com/.well-known/security.txt Hiring: https://www.databricks.com/company/careers/open-positions?department=security&location=all Bug Bounty: https://hackerone.com/databricks”
Key findingsclick a row for the evidence
✓Third-party model retention is disclosed in the product documentationStrong
Databricks documents, in its own model serving pages, that OpenAI may retain flagged content for coding and model-intermediary customers on newer models, and that Anthropic retains data for safety purposes on Fable 5 and future Mythos-class models for all customers.
Almost no platform vendor publishes the retention behaviour of the models it resells - it is normally left for the buyer to find in the provider's own terms, if at all. Disclosing it inside the product documentation, where an engineer configuring an endpoint will actually see it, is materially better practice than a link in a subprocessor list.
Question for vendor: Which of our workloads fall inside OpenAI's "coding and routing customers" definition, and can we route around models with mandatory safety retention?
“In accordance with OpenAI's public safety retention policy , for gpt-5.5 , gpt-5.5-pro and future models, OpenAI may retain certain coding and routing customers' customer content that OpenAI's classifiers detect as potentially violating OpenAI's usage policies when using these models. Otherwise retention will not be affected.”
“For Anthropic's Fable 5 and future Mythos-class models, all customers are subject to data retention for safety purposes, as described in Anthropic's data retention practices .”
✓Model providers are named and customer-selectedStrong
Anthropic and OpenAI are both registered subprocessors for AI-backed services, each marked "Customer Selected", and externally hosted model endpoints are centrally governed from within Databricks.
The "Customer Selected" marking is the useful part: no customer content reaches a third-party model until someone in the organisation configures an endpoint that sends it there. That supports a staged rollout and makes the AI supply chain a matter of configuration a buyer controls rather than a platform default they inherit.
“Anthropic, PBC AI-backed services United States Customer Selected Anthropic Resources OpenAI, L.L.C. AI-backed services United States Customer Selected OpenAI resources”
“The endpoints that serve these models can be centrally governed from Databricks , so you can streamline the use and management of various LLM providers, such as OpenAI and Anthropic, within your organization.”
!Two model paths with different data boundaries behind one interfaceGap
Databricks-hosted foundation models such as Meta Llama run through Foundation Model APIs, while externally hosted models such as OpenAI GPT-4 are reached through External models. Both are served through the same Model Serving interface.
The interface being uniform is the point of the product and also the risk. A prompt served by a Databricks-hosted model stays inside the platform boundary; the same prompt routed to an external model leaves it, and the retention disclosures above then apply. A governance position has to distinguish the two, and the interface does not force that distinction on the person configuring it.
Question for vendor: How do we detect or restrict which endpoints route to external providers, and is that visible in audit logs?
“Databricks-hosted foundation models like Meta Llama. These models are available using Foundation Model APIs . These models are curated foundation model architectures that support optimized inference. Base models, like Meta-Llama-3.3-70B-Instruct, GTE-Large, and Mistral-7B are available for immediate use with pay-per-token pricing, and workloads that require performance guarantees and fine-tuned model variants can be deployed with provisioned throughput”
“In accordance with OpenAI's public safety retention policy , for gpt-5.5 , gpt-5.5-pro and future models, OpenAI may retain certain coding and routing customers' customer content that OpenAI's classifiers detect as potentially violating OpenAI's usage policies when using these models. Otherwise retention will not be affected.”
“For Anthropic's Fable 5 and future Mythos-class models, all customers are subject to data retention for safety purposes, as described in Anthropic's data retention practices .”
✓Governance controls are described but not evidenced in operationStrong
AI Gateway is documented as the control point for guardrails, rate limits and quality monitoring, alongside Unity Catalog model registration, automated access controls and data lineage across the agent workflow.
This is a genuinely strong control surface for an AI platform, and it is the reason a regulated buyer would choose a platform over assembling the parts. The material collected is product documentation rather than assurance evidence, so it establishes the controls exist and are documented - not that they are independently tested.
Question for vendor: Are AI Gateway guardrails and Unity Catalog access controls in scope of your SOC 2 Type II?
“The endpoints that serve these models can be centrally governed from Databricks , so you can streamline the use and management of various LLM providers, such as OpenAI and Anthropic, within your organization.”
“set usage limits and monitor the quality of all types of models using AI Gateway . This enables you to democratize access to SaaS and open LLMs within your organization while ensuring appropriate guardrails are in place.”
“Maintain data security with end-to-end governance for agents . Enforce guardrails for all of your models, automate access controls, set rate limits and track data lineage across your entire workflow.”
“Custom models . These are Python models packaged in the MLflow format. They can be registered either in Unity Catalog or in the workspace model registry. Examples include scikit-learn, XGBoost, PyTorch, and Hugging Face transformer models. Agent serving is supported as a custom model. See Deploy an agent for AI applications”
!Certifications are asserted but no certificate or scope reached this collectionGap
Databricks refers to ISO certifications, an annual penetration test confirmation letter, an Enterprise Security Guide and a SOC 2 Type II report, all available through a due diligence package or the account team rather than published.
Nothing here suggests the certifications are absent - a platform at this scale in regulated industries would not survive without them. But scope is what decides whether they reach Mosaic AI, and scope cannot be read from a sentence saying documents are available on request. This is the single largest gap on the record and the one worth closing first.
Question for vendor: Please provide the ISO/IEC 27001 certificate and SOC 2 Type II report, and confirm whether Mosaic AI and Model Serving are named in their scope.
“For self-service security reviews, you can download our due diligence package. It includes common compliance documents such as our ISO certifications and our annual pen test confirmation letter. You can also reach out to your Databricks account team for copies of our Enterprise Security Guide and SOC 2 Type II report.”
!No AI-specific incident or change notification practice was foundGap
Databricks publishes a coordinated vulnerability disclosure route through HackerOne and a security contact, but nothing collected covers breach notification timeframes or how customers are told when a hosted foundation model is changed, deprecated or replaced.
Model deprecation is the live one for this product. An agent tuned against a specific hosted model behaves differently when that model is retired, and the notice period governs whether an organisation can re-validate before the change lands. It is an ordinary contract schedule item and should be requested directly.
Question for vendor: What notice do you give before deprecating or replacing a hosted foundation model, and what are your breach notification timeframes?
“Policy: https://www.databricks.com/trust Contact: [email protected] Encryption: https://www.databricks.com/.well-known/pgp-key.txt Preferred-Languages: en Canonical: https://www.databricks.com/.well-known/security.txt Hiring: https://www.databricks.com/company/careers/open-positions?department=security&location=all Bug Bounty: https://hackerone.com/databricks”
“This Data Processing Addendum, including its Annexes and the Standard Contractual Clauses (“DPA”), forms an integral part of the Databricks Master Cloud Services Agreement, or any other written agreement that governs Customer's use of the Databricks Services (as defined below) entered into between the entity identified as the “Customer””
?Technical dependency observed: AtlassianObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Anthropic, PBC AI-backed services United States Customer Selected Anthropic Resources OpenAI, L.L.C. AI-backed services United States Customer Selected OpenAI resources”
?Technical dependency observed: GoogleObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Google as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Anthropic, PBC AI-backed services United States Customer Selected Anthropic Resources OpenAI, L.L.C. AI-backed services United States Customer Selected OpenAI resources”
?Technical dependency observed: AWSObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on AWS as a platform provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — AWS appears to be involved as a platform provider: confirm whether this dependency exists, and whether it processes customer data.
“Anthropic, PBC AI-backed services United States Customer Selected Anthropic Resources OpenAI, L.L.C. AI-backed services United States Customer Selected OpenAI resources”
Assurance dimensionsweighted components of one score — not eight separate ratings
Organisation & AI governance15% of the score60
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
“The endpoints that serve these models can be centrally governed from Databricks , so you can streamline the use and management of various LLM providers, such as OpenAI and Anthropic, within your organization.”
“set usage limits and monitor the quality of all types of models using AI Gateway . This enables you to democratize access to SaaS and open LLMs within your organization while ensuring appropriate guardrails are in place.”
“Maintain data security with end-to-end governance for agents . Enforce guardrails for all of your models, automate access controls, set rate limits and track data lineage across your entire workflow.”
Governance & accountability: vendor-evidenced, not yet independently corroborated.
AI system15% of the score33
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
“Databricks-hosted foundation models like Meta Llama. These models are available using Foundation Model APIs . These models are curated foundation model architectures that support optimized inference. Base models, like Meta-Llama-3.3-70B-Instruct, GTE-Large, and Mistral-7B are available for immediate use with pay-per-token pricing, and workloads that require performance guarantees and fine-tuned model variants can be deployed with provisioned throughput”
“Custom models . These are Python models packaged in the MLflow format. They can be registered either in Unity Catalog or in the workspace model registry. Examples include scikit-learn, XGBoost, PyTorch, and Hugging Face transformer models. Agent serving is supported as a custom model. See Deploy an agent for AI applications”
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
“Databricks offers built-in evaluation for agents, supporting any AI model. Measure agent output quality with AI judges, evaluate fixes and redeploy quickly. Across ML and GenAI apps, you can identify production issues, analyze root causes and take corrective actions.”
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
AI system description: vendor-evidenced, not yet independently corroborated.
Change management: not publicly evidenced.
Model10% of the score60
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
“Anthropic, PBC AI-backed services United States Customer Selected Anthropic Resources OpenAI, L.L.C. AI-backed services United States Customer Selected OpenAI resources”
Model provider transparency: vendor-evidenced, not yet independently corroborated.
Customer data15% of the score72
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
“In accordance with OpenAI's public safety retention policy , for gpt-5.5 , gpt-5.5-pro and future models, OpenAI may retain certain coding and routing customers' customer content that OpenAI's classifiers detect as potentially violating OpenAI's usage policies when using these models. Otherwise retention will not be affected.”
“For Anthropic's Fable 5 and future Mythos-class models, all customers are subject to data retention for safety purposes, as described in Anthropic's data retention practices .”
“We provide comprehensive security to protect your data and workloads, such as encryption, network controls, data governance and auditing. Customer-Managed Keys Gain greater control over”
Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
AI supply chain10% of the score60
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
“Anthropic, PBC AI-backed services United States Customer Selected Anthropic Resources OpenAI, L.L.C. AI-backed services United States Customer Selected OpenAI resources”
Subprocessors & supply chain: vendor-evidenced, not yet independently corroborated.
Security foundation15% of the scoreorganisation-level evidence62
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
“Policy: https://www.databricks.com/trust Contact: [email protected] Encryption: https://www.databricks.com/.well-known/pgp-key.txt Preferred-Languages: en Canonical: https://www.databricks.com/.well-known/security.txt Hiring: https://www.databricks.com/company/careers/open-positions?department=security&location=all Bug Bounty: https://hackerone.com/databricks”
Independent assurance evidence10% of the scoreorganisation-level evidence59
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
“For self-service security reviews, you can download our due diligence package. It includes common compliance documents such as our ISO certifications and our annual pen test confirmation letter. You can also reach out to your Databricks account team for copies of our Enterprise Security Guide and SOC 2 Type II report.”
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.
Legal & contractual10% of the scoreorganisation-level evidence40
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
“This Data Processing Addendum, including its Annexes and the Standard Contractual Clauses (“DPA”), forms an integral part of the Databricks Master Cloud Services Agreement, or any other written agreement that governs Customer's use of the Databricks Services (as defined below) entered into between the entity identified as the “Customer””
Not graded: Agent — not applicable to this scan.
What would strengthen assuranceeach figure is from today's score — resolving one changes the others
Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 56 → up to 81 with every identified gap resolved.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
View as list
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.
Map your inherited responsibilitiesAssurance evidence: certifications 5 — registry checks and verification ladders, click to view
Referred to as part of a due diligence package available for download; no certificate or scope statement was collected.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Available from the Databricks account team rather than published. No report or scope statement was collected.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.
Checked against Data Privacy Framework (dataprivacyframework.gov), Sep 1, 2026: Verified on the registry
Checked against FedRAMP Marketplace (fedramp.gov), Sep 1, 2026: Verified on the registry
Sources 18 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
