IBM watsonx
low riskEnterprise AI Platformibm.comverified 2024-05-22
Data-handling profile
- Trains on input
- No — does not train on customer inputs
- Retention
- Customer data is retained only for the duration of the service agreement; IBM does not retain customer input data for model training purposes for enterprise customers.
- Data region
- Multi-region (Global availability with data residency options in US, EU, and others depending on deployment)
- Certifications
- ISO 27001ISO 27017ISO 27018SOC 2 Type IIHIPAA compliant (select offerings)FedRAMP Authorized
- DPA available
- Yes
- Breach history
- IBM has experienced historical data incidents typical of a global tech firm, but no specific systemic breach involving the watsonx platform's underlying proprietary enterprise data infrastructure has been reported.
- EU AI Act
- IBM actively tracks and incorporates EU AI Act requirements into their AI governance framework, emphasizing transparency and risk management for high-risk AI systems.
Sources
- https://www.ibm.com/trust/privacy
- https://www.ibm.com/legal/privacy
- https://www.ibm.com/docs/en/watsonx/saas?topic=security-data-protection-watsonx
- https://www.ibm.com/products/watsonx-ai
Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes.
Change history
No material changes recorded since monitoring began.