Databricks AI Vendor Risk Profile

Unified data analytics and AI platform combining data lakehouse, ML ops, and generative AI capabilities. Offers Foundation Model APIs that integrate frontier models alongside open-source and custom-trained models on customer data.

Visit Databricks website

HQ: United States · Integrator

Risk overview

Risk score: 25/100

Risk tier: Moderate

Safety rating: 75/100 (higher is better)

Lower risk scores indicate lower assessed risk.

Last verified: Apr 19, 2026 (106 days ago) Aging · 8 cited sources

Risk dimensions

DimensionRisk score
Data Handling28/100
IP Exposure26/100
Jurisdiction13/100
Security22/100
Regulatory Compliance20/100
Transparency50/100
Business Stability31/100
Dependency Chain26/100
Agent GovernanceNot assessed

Analyst summary

Rating: Recommended

Databricks combines the Data Intelligence Platform with Mosaic AI and the open-weights DBRX model, giving enterprises a unified data-plus-AI platform with strong compliance posture (SOC 2, ISO 27001, FedRAMP Moderate/High, HIPAA BAA). For data-heavy enterprises, it is among the strongest AI platform choices available.

Bottom line: One of the strongest AI platform choices for data-heavy enterprises; overkill for simpler API-consumer use cases.

Strengths

Concerns

Best for

Avoid if

Citations

  1. Data Handling — Hipaa Baa Available (primary · high confidence)
    https://www.databricks.com/trust/compliance
    Verified 2026-04-19
    Databricks offers HIPAA Business Associate Agreements covering the Databricks Data Intelligence Platform including Mosaic AI.
  2. Data Handling — Trains On User Data (primary · high confidence)
    https://www.databricks.com/trust/privacy
    Verified 2026-04-19
    Databricks does not use customer data to train DBRX or any Databricks foundation models, and Mosaic AI model serving does not share data with third-party model providers.
  3. Ip Profiles — Training Data Provenance (primary · high confidence)
    https://www.databricks.com/blog/introducing-dbrx-new-state-art-open-llm
    Verified 2026-04-19
    Databricks published a technical report and model card for DBRX, a 132B parameter mixture-of-experts model trained on 12 trillion tokens of curated data.
  4. Ip Profiles — User Owns Outputs (primary · high confidence)
    https://www.databricks.com/legal/mcsa
    Verified 2026-04-19
    Customer retains ownership of Customer Content and outputs generated through the Databricks Data Intelligence Platform.
  5. Jurisdiction Profiles — Incorporation Country (primary · high confidence)
    https://www.databricks.com/company/about-us
    Verified 2026-04-19
    Databricks, Inc. is a Delaware corporation headquartered in San Francisco, California.
  6. Security Compliance — Fedramp Authorized (primary · high confidence)
    https://www.databricks.com/trust/compliance/fedramp
    Verified 2026-04-19
    Databricks on AWS GovCloud holds FedRAMP Moderate authorization, with Databricks on Azure Government holding FedRAMP High.
  7. Security Compliance — Iso 27001 (primary · high confidence)
    https://www.databricks.com/trust/compliance
    Verified 2026-04-19
    Databricks holds ISO/IEC 27001, 27017, 27018, and 27701 certifications.
  8. Security Compliance — Soc2 Type2 (primary · high confidence)
    https://www.databricks.com/trust/compliance
    Verified 2026-04-19
    Databricks maintains SOC 2 Type II compliance with reports available through the Trust Center.