Modal AI Vendor Risk Profile
Serverless compute platform for AI and data workloads offering Python-first GPU orchestration. Developers deploy inference endpoints, batch jobs, and training pipelines without managing infrastructure. Backed by Redpoint and Amplify.
Risk overview
Risk score: 35/100
Risk tier: Moderate
Safety rating: 65/100 (higher is better)
Lower risk scores indicate lower assessed risk.
Last verified: Apr 19, 2026 Aging
Risk dimensions
| Dimension | Risk score |
|---|---|
| Data Handling | 28/100 |
| IP Exposure | 26/100 |
| Jurisdiction | 13/100 |
| Security | 40/100 |
| Regulatory Compliance | 60/100 |
| Transparency | 75/100 |
| Business Stability | 55/100 |
| Dependency Chain | 32/100 |
| Agent Governance | Not assessed |
Analyst summary
Rating: Acceptable
Modal is a serverless GPU compute platform with modern developer UX, clean no-training terms, SOC 2 Type II, and HIPAA-eligible enterprise tier. Good for teams wanting AWS Lambda-style ergonomics for GPU workloads.
Bottom line: Acceptable for engineering-led adoption; match enterprise needs carefully for regulated workloads.
Strengths
- No training on customer code or workloads; customer retains full ownership
- SOC 2 Type II and GDPR DPA available; HIPAA BAA on enterprise tier
- Developer experience well-rated among ML engineers (Python-native, fast cold starts)
- Clear per-second billing with no long-term GPU commitments
Concerns
- Smaller company profile than hyperscalers; narrower compliance footprint
- Relies on upstream GPU cloud providers; customers inherit provider risk indirectly
- No FedRAMP authorization
- Smaller community and ecosystem than AWS/GCP serverless alternatives
Best for
- Python-first engineering teams building ML inference and batch workloads
- Teams wanting serverless GPU without managing clusters or cold-start complexity
- Workloads where developer velocity outweighs enterprise feature depth
Avoid if
- You need FedRAMP-authorized serverless compute
- Your enterprise procurement requires extensive third-party audit reports beyond SOC 2
- You want tight integration with a specific hyperscaler's surrounding services
Citations
- Data Handling — Hipaa Baa Available
Modal offers HIPAA Business Associate Agreements for Enterprise customers processing protected health information.
- Data Handling — Trains On User Data
Modal Labs does not use customer code, data, or workloads executed on Modal compute for model training or internal product improvement.
- Governance — Strategic Investors
Modal Labs raised $80 million in Series B funding led by Lux Capital, bringing total funding to $104 million.
- Ip Profiles — User Owns Outputs
Customers retain full ownership of all code, data, models, and outputs executed on Modal infrastructure.
- Jurisdiction Profiles — Incorporation Country
Modal Labs, Inc. is a Delaware corporation headquartered in New York City.
- Security Compliance — Gdpr Compliant
Modal offers a Data Processing Addendum for customers processing personal data under GDPR.
- Security Compliance — Soc2 Type2
Modal is SOC 2 Type II certified covering its serverless compute platform.