AI Provider Trust Registry evidence verified as of 2026-08-19

Registry / xAI API

xAI API

developer: xAI platform: xAI (first-party) category: first party

xAI's first-party API for the Grok model family. Publicly claims SOC 2 Type 2 compliance and a no-training-by-default policy for API data, with a 30-day default retention window and enterprise-only zero-data-retention; formal reports sit behind an NDA-gated trust center, and EU AI Act engagement is limited to the Safety and Security chapter of the GPAI Code of Practice.

Watch-outs 8

The cells where this offering is not a clean public yes. This is what to check before you sign.

Vendor trust
SOC 2 Type II Is a SOC 2 Type II report available for this offering?
Yes, sales-gated confidence: high · verified 2026-08-15

The provider’s own FAQ confirms SOC 2 Type II compliance but states the report is only available to customers with a signed NDA, fitting the sales‑gated definition.

We are SOC 2 Type 2 compliant. Customers with a signed NDA can refer to our Trust Center for up-to-date information on our certifications and data governance.

source

ISO 27001 Is there an ISO/IEC 27001 certification covering this offering?
No public evidence confidence: high · verified 2026-08-18

The public FAQ mentions only SOC 2 compliance and directs customers to a gated Trust Center for certifications, providing no public ISO 27001 evidence.

We are SOC 2 Type 2 compliant. Customers with a signed NDA can refer to our Trust Center for up-to-date information on our certifications and data governance.

source

ISO 42001 Is there an ISO/IEC 42001 (AI management system) certification?
No public evidence confidence: high · verified 2026-08-17

The only public source only references ISO/IEC 42001 but does not claim xAI holds the certification, and no other authoritative page shows certification.

xAI references standards such as NIST's AI Risk Management Framework, ISO/IEC 42001 for AI management systems, and industry best practices.

source

Trust center Is there a maintained trust center / compliance portal?
Yes, sales-gated confidence: high · verified 2026-08-16

The provider’s own FAQ explicitly states the Trust Center exists but is gated behind a signed NDA, matching yes_sales_gated.

We are SOC 2 Type 2 compliant. Customers with a signed NDA can refer to our Trust Center (https://trust.x.ai/) for up-to-date information on our certifications and data governance.

source

Data handling
HIPAA BAA Will they sign a HIPAA Business Associate Agreement covering this offering?
Yes, sales-gated confidence: high · verified 2026-08-18

The provider offers a BAA request form, indicating the agreement is available but gated behind a sales/approval process.

This form is for customers requesting a Business Associate Agreement (BAA) from xAI to enable HIPAA compliance when using xAI APIs.

source

GDPR DPA Is there a public DPA with SCCs and a published subprocessor list?
Yes, public confidence: high · verified 2026-08-19

The publicly accessible DPA defines SCCs and links to a publicly viewable subprocessor list, meeting the requirement.

"SCCs" means the standard contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021, as may be amended, superseded, or replaced. ... xAI's list of general Subprocessors is available[here](/legal/subprocessor-list)("Subprocessor List").

source

No-training default Is there a public commitment not to train on customer API data by default?
Yes, public confidence: high · verified 2026-08-14

The provider's own public FAQ page explicitly states that xAI does not train on API inputs or outputs by default, confirming a public, ungated commitment.

xAI never trains on your API inputs or outputs without your explicit permission. By default, all API requests and responses are stored on our servers (encrypted at rest) for 30 days for auditing purposes in the event of suspected abuse or misuse. xAI does not train on this data, and it is automatically deleted after 30 days.

source

Retention / ZDR Is retention documented, and is zero-data-retention available?
Partial confidence: high · verified 2026-08-14

Retention is publicly documented, while zero‑data‑retention is only available via a self‑serve toggle that may not be enabled for all customers, making the overall answer partially satisfied.

By default, all API requests and responses are stored on our servers (encrypted at rest) for 30 days ... automatically deleted after 30 days. ... Self‑serve: Where available, a team admin can turn it on or off directly from the xAI Console. If you do not see the ZDR option, you may not be a team admin, self‑serve ZDR may not be enabled for your environment yet, or your team may be on a negotiated Enterprise Customer Agreement ... contact [email protected]

source

Residency Can data be pinned to a region (especially the EU)?
Yes, sales-gated confidence: high · verified 2026-08-16

Verified on x.ai's own pricing page that Data residency is listed under the Enterprise tier alongside "Talk to our sales team," and x.ai/api also lists "Data residency options" under its sales-oriented enterprise section, with no self-serve regional pinning documented in the docs.

Data residency — Control where your data lives.

source

EU AI Act
GPAI Code Is the model developer on the EC's GPAI Code of Practice signatory list?
Partial confidence: high · verified 2026-08-19

The EC GPAI Code page lists xAI solely under the Safety and Security chapter, indicating a partial signatory status per registry rules.

In addition, xAI signed up to the Safety and Security Chapter; this means that it will have to demonstrate compliance with the AI Act’s obligations concerning transparency and copyright via alternative adequate means.

source

Art. 53 summary Has the model developer published the Art. 53 training-data summary?
Yes, public confidence: high · verified 2026-08-13

xAI's own legal page lists the public training-content summary for Grok 4.5, confirming the developer published the Art. 53 summary on its own domain without a gate.

Public Summary of Training Content for Grok 4.5

source

Spotted an error? Submit a correction with evidence, corrections with a primary source are folded in and credited in the changelog.