AI Provider Trust Registry evidence verified as of 2026-10-03

Registry / xAI API

xAI API

developer: xAI platform: xAI (first-party) category: first party

xAI's first-party API for the Grok model family. Publicly claims SOC 2 Type 2 compliance and a no-training-by-default policy for API data, with a 30-day default retention window and enterprise-only zero-data-retention; formal reports sit behind an NDA-gated trust center, and EU AI Act engagement is limited to the Safety and Security chapter of the GPAI Code of Practice.

Watch-outs 7

The cells where this offering is not a clean public yes. This is what to check before you sign.

  • SOC 2 Type II: Yes, sales-gated report gated behind signed NDA (Trust Center)
  • ISO 27001: No public evidence Audit confirmed: quote is verbatim on xAI's own docs FAQ, which only states SOC 2 Type 2 and points to an NDA-gated Trust Center (trust.x.ai) that does not load, and x.ai/security lists no ISO 27001;
  • ISO 42001: No public evidence The recorded ISO 42001 certificate is held by Anysphere (Cursor's parent) and covers the Grok Bot product, not xAI or the xAI API; xAI's trust center (trust.x.ai) is gated with no public ISO 42001 evidence.
  • Trust center: Yes, sales-gated Access to the Trust Center requires a signed NDA (sales‑gated).
  • HIPAA BAA: Yes, sales-gated The provider offers a BAA request form but does not publish the agreement publicly, indicating the BAA is available only behind a sales gate.
  • Residency: Yes, sales-gated EU region pinning requires enterprise sales contact
  • GPAI Code: Partial xAI is only a Safety and Security Chapter signatory, not a full signatory
Vendor trust
SOC 2 Type II Is a SOC 2 Type II report available for this offering?
◐Yes, sales-gated confidence: high · verified 2026-10-03

xAI confirms SOC 2 Type II compliance but states the report is only accessible to customers with a signed NDA, fitting the yes_sales_gated category.

We are SOC 2 Type 2 compliant. Customers with a signed NDA can refer to our Trust Center for up-to-date information on our certifications and data governance.

source

ISO 27001 Is there an ISO/IEC 27001 certification covering this offering?
○No public evidence confidence: high · verified 2026-09-27

Audit confirmed: quote is verbatim on xAI's own docs FAQ, which only states SOC 2 Type 2 and points to an NDA-gated Trust Center (trust.x.ai) that does not load, and x.ai/security lists no ISO 27001; no public source confirms an ISO/IEC 27001 certification, so no_public_evidence stands.

We are SOC 2 Type 2 compliant. Customers with a signed NDA can refer to our Trust Center for up-to-date information on our certifications and data governance.

source

ISO 42001 Is there an ISO/IEC 42001 (AI management system) certification?
○No public evidence confidence: high · verified 2026-10-01

The recorded quote itself attributes the ISO/IEC 42001 certificate to Anysphere for Grok Bot (https://docs.x.ai/grok-bot/security-faq: "Anysphere holds ISO/IEC 27001 and ISO/IEC 42001 certifications, issued by Schellman, and Grok Bot is included in the current ISO scope."; trust.cursor.com: "Cursor

Compliance with relevant data privacy regulations and adherence to industry best practices.

source

Trust center Is there a maintained trust center / compliance portal?
◐Yes, sales-gated confidence: high · verified 2026-09-29

The provider’s own FAQ confirms a Trust Center exists but is only available to NDA‑signed customers, matching the definition of a sales‑gated compliance portal.

We are SOC 2 Type 2 compliant. Customers with a signed NDA can refer to our Trust Center (https://trust.x.ai/) for up-to-date information on our certifications and data governance.

source

Data handling
HIPAA BAA Will they sign a HIPAA Business Associate Agreement covering this offering?
◐Yes, sales-gated confidence: high · verified 2026-09-30

The provider offers a BAA request form but does not publish the agreement publicly, indicating the BAA is available only behind a sales gate.

This form is for customers requesting a Business Associate Agreement (BAA) from SpaceXAI to enable HIPAA compliance when using SpaceXAI APIs.

source

GDPR DPA Is there a public DPA with SCCs and a published subprocessor list?
●Yes, public confidence: high · verified 2026-10-01

The public DPA page defines SCCs and links to a publicly accessible subprocessor list, satisfying the requirement.

"**SCCs**" means the standard contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021, as may be amended, superseded, or replaced. ... SpaceXAI's list of general Subprocessors is available at https://x.ai/legal/subprocessor-list ("**Subprocessor List**").

source

No-training default Is there a public commitment not to train on customer API data by default?
●Yes, public confidence: high · verified 2026-10-02

Verbatim quote found on xAI's own docs.x.ai security FAQ, an ungated public commitment not to train on API inputs/outputs without explicit permission, so the recorded yes_public stands.

SpaceXAI never trains on your API inputs or outputs without your explicit permission.

source

Retention / ZDR Is retention documented, and is zero-data-retention available?
●Yes, public confidence: high · verified 2026-10-03

The provider's own FAQ page publicly states the default 30‑day retention and describes a self‑serve Zero Data Retention option, satisfying both parts without a sales or NDA gate.

By default, all API requests and responses are stored on our servers (encrypted at rest) for 30 days ... For teams that require stricter data handling, see Zero Data Retention (ZDR) below. ... Self‑serve: Where available, a team admin can turn it on or off directly from the xAI Console.

source

Residency Can data be pinned to a region (especially the EU)?
◐Yes, sales-gated confidence: high · verified 2026-09-28

The provider’s public pages state data residency options are an enterprise feature and mention regional processing options, indicating pinning to EU is available but gated behind a sales process.

Enterprise ... Data residency options. Regional processing options for teams that need them.

source

EU AI Act
GPAI Code Is the model developer on the EC's GPAI Code of Practice signatory list?
◔Partial confidence: high · verified 2026-10-01

The EC GPAI signatory page lists xAI solely under the Safety and Security Chapter, confirming a partial signatory status.

In addition, xAI signed up to the Safety and Security Chapter; this means that it will have to demonstrate compliance with the AI Act’s obligations concerning transparency and copyright via alternative adequate means.

source

Art. 53 summary Has the model developer published the Art. 53 training-data summary?
●Yes, public confidence: high · verified 2026-10-02

The xAI site provides a direct, unrestricted PDF titled 'Public Summary of Training Content for Grok 4.5', satisfying the Article 53 publishing requirement.

Public Summary of Training Content for Grok 4.5

source

Spotted an error? Submit a correction with evidence, corrections with a primary source are folded in and credited in the changelog.