All engagements conducted under NDA·Evidence preserved to technical chain-of-custody standards·Engagements limited to qualified organizations

Free scanThe studyForensic TriageForensic AuditAI VendorsResearch
Free scan · no install

Does Perplexity offer a HIPAA BAA — and what does "HIPAA aligned" actually mean?

Consumer (websites, Comet browser & apps): No BAA published · Data used to improve services including AI models, with no opt-out described · Uploaded files deleted in seven days, but the session containing them is not

Enterprise Pro: No BAA published · Enterprise data never used to train, extended contractually to third-party providers · Admin-configurable session retention

Consumer - websites, Comet browser & appsEnterprise Pro
HIPAA BAANot statedno Perplexity document reviewed offers a HIPAA Business Associate Agreement on any plan. The enterprise security page claims "HIPAA aligned safeguards," which is not a BAANot statedPerplexity claims "GDPR and HIPAA aligned safeguards" but publishes no BAA offer for Enterprise Pro or any other plan
Trains on your dataYesdata is used to "Improve or create services and products, including our AI models," with no training opt-out described in the privacy notice. A carve-out exists only for Email Assistant: "We do not use the content of emails to create, train, improve, or fine-tune AI models"No"Enterprise data is never used to train or fine-tune Perplexity's models, and our agreements with third-party AI providers prohibit them from training on your data"
Survives deletionYesuploaded files follow a seven-day deletion policy but "The session containing those files is not deleted unless you request it." Deletion requests may be refused where data is legally required, and "We may keep historical data in our backup files as permitted by law"Admin-configurableEnterprise administrators set session retention windows in the admin control panel. Uploaded files follow a seven-day deletion policy, but the session containing them is not deleted unless requested
Deployer / admin log accessNot stated for consumer productsaudit logging is documented as an Enterprise admin featureYesaudit logging is available in the Enterprise admin control panel, alongside session retention, Incognito Mode enforcement and AI model/provider settings
Third-party attestationSOC 2 Type 2 stated on the enterprise security page. ISO 27001 is not mentioned. Scope by plan not statedSOC 2 Type 2 stated. ISO 27001 is not mentioned on the enterprise security page
Commonly mistaken for — Consumer - websites, Comet browser & apps

Enterprise Pro, which has the opposite training posture - the consumer privacy notice explicitly does not apply to Enterprise or API offerings. Also "HIPAA aligned safeguards," which is marketing language, not a BAA

Commonly mistaken for — Enterprise Pro

"HIPAA aligned safeguards" being read as HIPAA coverage - no BAA is offered in any reviewed document. Also consumer Perplexity, which trains on user data and is governed by a different notice entirely

Source: https://www.perplexity.ai/enterprise/securityDocument: Perplexity Enterprise - security pageVerified: September 2, 2026Verified by: Adil — Shadow AI Forensics

Vendor terms change without notice. This page reflects what Perplexity published as of September 2, 2026. Re-verified quarterly.

This page states what the vendor published. It does not score them.

If you need a scored Go / Conditional Go / No-Go verdict for a vendor decision — including a vendor not listed here — that's an AI Vendor Risk Assessment: three binary industry gates, nine scored criteria, four provenance fields on every finding. $997, delivered in 48 hours.

See how AVRA works →

Want all 13 tools in one file?

AI Vendor Compliance Quick-Reference

Covers 22 tiers across 13 tools — same sourcing, side by side, printable for a vendor file.