Registry / xAI API
xAI API
xAI's first-party API for the Grok model family. Publicly claims SOC 2 Type 2 compliance and a no-training-by-default policy for API data, with a 30-day default retention window and enterprise-only zero-data-retention; formal reports sit behind an NDA-gated trust center, and EU AI Act engagement is limited to the Safety and Security chapter of the GPAI Code of Practice.
Watch-outs 8
The cells where this offering is not a clean public yes. This is what to check before you sign.
- SOC 2 Type II: Yes, sales-gated Report requires a signed NDA (access via Trust Center)
- ISO 27001: No public evidence Only SOC 2 is publicly listed; ISO 27001, if any, is behind a gated Trust Center.
- ISO 42001: No public evidence The only public source only references ISO/IEC 42001 but does not claim xAI holds the certification, and no other authoritative page shows certification.
- Trust center: Yes, sales-gated Access to the Trust Center requires a signed NDA
- HIPAA BAA: Yes, sales-gated BAA requires submitting a questionnaire and sales approval; not directly downloadable
- Retention / ZDR: Partial ZDR is self‑serve only where enabled; otherwise requires sales contact
- Residency: Yes, sales-gated Residency is an Enterprise-tier feature obtained through a sales conversation; no self-serve EU region selection is documented.
- GPAI Code: Partial Only signed the Safety and Security chapter, not the full GPAI Code
The provider’s own FAQ confirms SOC 2 Type II compliance but states the report is only available to customers with a signed NDA, fitting the sales‑gated definition.
We are SOC 2 Type 2 compliant. Customers with a signed NDA can refer to our Trust Center for up-to-date information on our certifications and data governance.
The public FAQ mentions only SOC 2 compliance and directs customers to a gated Trust Center for certifications, providing no public ISO 27001 evidence.
We are SOC 2 Type 2 compliant. Customers with a signed NDA can refer to our Trust Center for up-to-date information on our certifications and data governance.
The only public source only references ISO/IEC 42001 but does not claim xAI holds the certification, and no other authoritative page shows certification.
xAI references standards such as NIST's AI Risk Management Framework, ISO/IEC 42001 for AI management systems, and industry best practices.
The provider’s own FAQ explicitly states the Trust Center exists but is gated behind a signed NDA, matching yes_sales_gated.
We are SOC 2 Type 2 compliant. Customers with a signed NDA can refer to our Trust Center (https://trust.x.ai/) for up-to-date information on our certifications and data governance.
The provider offers a BAA request form, indicating the agreement is available but gated behind a sales/approval process.
This form is for customers requesting a Business Associate Agreement (BAA) from xAI to enable HIPAA compliance when using xAI APIs.
The publicly accessible DPA defines SCCs and links to a publicly viewable subprocessor list, meeting the requirement.
"SCCs" means the standard contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021, as may be amended, superseded, or replaced. ... xAI's list of general Subprocessors is available[here](/legal/subprocessor-list)("Subprocessor List").
The provider's own public FAQ page explicitly states that xAI does not train on API inputs or outputs by default, confirming a public, ungated commitment.
xAI never trains on your API inputs or outputs without your explicit permission. By default, all API requests and responses are stored on our servers (encrypted at rest) for 30 days for auditing purposes in the event of suspected abuse or misuse. xAI does not train on this data, and it is automatically deleted after 30 days.
Retention is publicly documented, while zero‑data‑retention is only available via a self‑serve toggle that may not be enabled for all customers, making the overall answer partially satisfied.
By default, all API requests and responses are stored on our servers (encrypted at rest) for 30 days ... automatically deleted after 30 days. ... Self‑serve: Where available, a team admin can turn it on or off directly from the xAI Console. If you do not see the ZDR option, you may not be a team admin, self‑serve ZDR may not be enabled for your environment yet, or your team may be on a negotiated Enterprise Customer Agreement ... contact [email protected]
Verified on x.ai's own pricing page that Data residency is listed under the Enterprise tier alongside "Talk to our sales team," and x.ai/api also lists "Data residency options" under its sales-oriented enterprise section, with no self-serve regional pinning documented in the docs.
Data residency — Control where your data lives.
The EC GPAI Code page lists xAI solely under the Safety and Security chapter, indicating a partial signatory status per registry rules.
In addition, xAI signed up to the Safety and Security Chapter; this means that it will have to demonstrate compliance with the AI Act’s obligations concerning transparency and copyright via alternative adequate means.
xAI's own legal page lists the public training-content summary for Grok 4.5, confirming the developer published the Art. 53 summary on its own domain without a gate.
Public Summary of Training Content for Grok 4.5
Spotted an error? Submit a correction with evidence, corrections with a primary source are folded in and credited in the changelog.