Replicate
medium riskAI Infrastructure & Model Hostingreplicate.com, replicate.deliveryverified 2026-03-04
Data-handling profile
- Trains on input
- No — does not train on customer inputs
- Retention
- Predictions (inputs and outputs) are stored indefinitely unless explicitly deleted by the user via the API or dashboard; standard system and execution logs are retained for 30 days.
- Data region
- United States (AWS)
- Certifications
- SOC 2 Type II
- DPA available
- Yes
- Breach history
- In April 2024, Replicate resolved a container-escape vulnerability that could have allowed unauthorized access to other customers' private model inputs and API tokens. No evidence of active exploitation by malicious actors was found.
- EU AI Act
- As an AI model hosting and infrastructure provider, Replicate acts as a hosting platform. Compliance obligations under the EU AI Act largely fall on the developers and deployers who build and configure the specific models hosted on the platform.
Sources
- https://replicate.com/privacy
- https://replicate.com/privacy
- https://replicate.com/terms
- https://replicate.com/blog/container-escape-vulnerability-patched
Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes.
Change history
No material changes recorded since monitoring began.