Vendor comparison

What other vendors leave out of the table.

Five dimensions that matter for every Canadian business in 2026, applied across seven vendors.

DimensionSovereignHybridFrontierChatGPT EnterpriseM365 CopilotAzure OpenAIGemini WorkspaceMistral CloudCohere
No outbound callsYesOpt-in onlyAll queriesNoNoNoNoNoNo
Out of CLOUD Act reachYesLocal yes, Frontier noFrontier only — United StatesUnited StatesUnited StatesUnited StatesUnited StatesOutside United StatesOutside United States
Simplified PIA (≤ 3 pages)1 page3 pages3 pages≥ 12 pages≥ 12 pages≥ 12 pages≥ 12 pages5–7 pages5–7 pages
Audit log under your controlLocal audit logLocal audit logtonia proxyOpenAI logsMicrosoft logsMicrosoft logsGoogle logsMistral logsCohere logs
Terms modifiable on noticeNo (firm purchase)Local no, Frontier yesYes (30 days)Yes (30 days)Yes (Microsoft)Yes (Microsoft)Yes (Google)GDPR-constrainedCanadian-constrained
Default retention window0 days0 days (local) / opt-in (Frontier)24 h contractual pause30 daysM365 retention policyMicrosoft policyGoogle policy90 daysCohere policy
Canadian French consoleYesYesYesFR (France)FR (France)FR (France)FR (France)FR (France)EN-first
Canadian grants applicableCDAEIA, RS&DE, PSPIIACDAEIA, RS&DE, PSPIIACDAEIA, RS&DE, PSPIIANoNoNoNoNoRS&DE only
Open / auditable modelLlama-3 70BLlama-3 70B + FrontierFrontier only (black box)Black boxBlack boxBlack boxBlack boxOpen weightsOpen weights
Contractual SLA99.5–99.9 %99.5–99.9 %99.9 % cloud99.9 % cloud99.9 % cloud99.9 % cloud99.9 % cloud99.5 %99.5 %
  • Bill 25 posture met
  • Partial — needs documenting
  • Not met

Per-vendor notes.

Footnotes capture three details that matter most for a Canadian buyer: jurisdiction, whether the terms can change on notice, and who owns the audit log.

ChatGPT Enterprise / Team

OpenAI retains conversation logs for up to 30 days for abuse monitoring — accessible to OpenAI staff and to US legal process. Zero data retention is available only by separate written agreement, and only on certain models. This is not your default. United States company — CLOUD Act applies.

Microsoft 365 Copilot

Uses your Microsoft Graph as context — it reads your SharePoint, Exchange, OneDrive, and Teams. Retention follows the M365 commitments, not Canadian commitments. United States company — CLOUD Act applies.

Azure OpenAI

The Canadian region addresses the physics of the data, not the jurisdiction. Microsoft Corp. remains subject to the CLOUD Act. See the trust-hub section on Azure for details.

Google Gemini for Workspace

Content is not used for advertising, but it is processed by Google's global infrastructure under the control of the US parent. United States company — CLOUD Act applies.

Mistral Cloud

Out of CLOUD Act reach. However, any transfer from Canada is still cross-border (GDPR ≠ Bill 25). A PIA is required. The posture is better than US vendors, but still weaker than an on-site tonia.

Cohere

Out of CLOUD Act reach for workloads processed on Canadian infrastructure. This is the closest cloud posture to tonia. But: not on-premises, no on-site tonia audit log you control.