Alpha
All entriesContact
Inference provider

Fireworks AI

HQ
United States
Serves
9 open model families
Pricing
mixed
API
OpenAI-compatible

You partially own inference here: independently readable docs confirm Zero Data Retention (bar the Response API's 30-day exception) and that training only happens with your explicit opt-in - a decent baseline. But the two documents that would actually settle this - the Terms of Service and the DPA - are page-level noindexed and unreachable to a real browser, so the exact ZDR clause, the confidentiality-clause direction, and the sub-processor list (including a prior, now-unconfirmed claim that Anthropic is named) cannot be independently verified. This is a downgrade from an earlier draft that treated an automated agent's PDF read as equivalent grounding; it was not. Obtain a rendered PDF or authenticated Trust Center access before relying on the stronger claims, and set store=false on the Response API if you need genuine zero-retention there.

Do you really own it?
Partial
none·limited·partial·substantial·full
Analytical input: AOI C · 64.8/100
The four ownership factors

Floor-weighted, not averaged. Nothing is weak, but data control is only moderate, so it misses the bar for substantial - strong on both use & modify and data control - and lands at partial.

1

Use and modify freelyCan you use it freely and leave without lock-in?

Strong

An OpenAI-compatible API (independently browser-confirmed) over a predominantly open-weight catalogue keeps workloads portable - the same checkpoints run elsewhere or self-hosted, independent of Fireworks' own contract terms.

How this scores (AOI sub-dimensions)
Transparency & lock-in3/5how portable it is and how easily you can leaveCORRECTED 2026-09-20: an OpenAI-compatible API over a predominantly open-weight catalogue keeps workloads portable - the base URL and chat/completions support are independently browser-confirmed.
Cost4/5how the pricing model compares and how predictable it isPer-token serverless pricing (with a discounted cached-input rate and a 50% batch discount) and per-GPU-second dedicated pricing are both public and documented in detail, read directly from Fireworks' own pricing docs, and are broadly competitive for the class (e.g.
2

TransparencyAre the binding terms published, legible and independently checkable?

Moderate

The Privacy Policy and several docs pages are legible and were independently browser-read - they state retention and training-opt-in terms clearly - but the Terms of Service and DPA, the two most contractually load-bearing documents, are page-level noindexed and could not be independently read, and the Trust Center's SOC 2/ISO/HIPAA certifications are corroborated only via company blog posts.

How this scores
Not a scored AOI dimension. For a hosted provider, transparency is whether the binding terms are published, legible and were actually read - the read/unverified evidence below, not a certification. A strong rating here must trace to a retrieved binding document.
3

ReliabilityDoes it stay up and stay secure?

Moderate

A public status page (independently browser-confirmed) shows a strong recent uptime record (~99.67-100% across 28 tracked endpoints), but no contractual SLA or service-credit clause was found, and no long multi-year track record was independently verified.

How this scores (AOI sub-dimensions)
Reliability3/5whether it stays up, with an SLA and status historyA public status page (status.fireworks.ai) shows an operational track record with per-endpoint 90-day uptime around 99.67-100% and documented incident communication.
Security3/5the controls protecting your traffic and dataDedicated workloads run in "logically isolated environments, preventing cross-customer access or data leakage" per the data-security docs (independently browser-confirmed verbatim), with TLS 1.2+ in transit and AES-256 at rest, least-privilege access controls, and customer-managed keys (CMEK).
Compliance4/5which independent certifications and attestations it holdsFireworks' own docs certifications FAQ and blog announce SOC 2 Type II (2023-10-27) plus HIPAA compliance, and a separate blog announces triple ISO certification (27001/27701/42001, 2025-11-19) - both independently browser-read; a trust centre exists at trust.fireworks.ai.
4

Doesn't extract your dataDo the binding terms keep your data and IP yours?

Moderate

CORRECTED 2026-09-20: Zero Data Retention (except the Response API) and training-only-with-opt-in are independently confirmed via readable docs and the Privacy Policy. But the ToS-level Zero Data Retention clause, the confidentiality-clause direction, and the DPA's sub-processor Schedule (including a prior claim naming Anthropic) could NOT be independently verified - the two governing documents are unreachable to a real browser. This is a genuine downgrade from a prior strong rating that rested on those unverifiable documents.

How this scores (AOI sub-dimensions)
Data governance3/5retention, training-on-inputs and data ownershipCORRECTED 2026-09-20 after independent Cowork browser verification could not reach the Terms of Service or DPA (both page-level noindexed/ROBOTS_DISALLOWED; the Trust Center hosting the DPA is JS-gated).
Residency3/5where your data is processed and storedOn-demand/dedicated deployments offer a selectable Europe (and Asia-Pacific) region with pinning, and a BYOC/Virtual-Cloud option keeps data entirely in the customer's own VPC.

How the AOI score is computed

The seven dimensions above, each scored 0 to 5, weighted and summed to the 0 to 100 headline. The score is the analytical input behind the ownership verdict, not the verdict itself.

DimensionScoreWeightPoints
Data governance3/50.2414.4
Compliance4/50.1814.4
Residency3/50.169.6
Security3/50.148.4
Reliability3/50.127.2
Transparency & lock-in3/50.106.0
Cost4/50.064.8
HeadlineC · 64.8/100
Dossier coverageAssess 65%Implement 44%Use 43%Support 57%How complete our four-domain documentation is, a measure of our coverage, not of the model. Each domain links to its page.

Sources

Every rating traces to a primary document. Read means the text was verified; unverified means it is known to exist but has not yet been read.

DocumentWhat it grounds
Terms of serviceunverified2026-09-20
UNCONFIRMED as of 2026-09-20.
Privacy Policyread2026-09-20
Fireworks Privacy Policy (independently browser-read 2026-09-20, lastmod 2026-08-11): 'We do not use your prompts, training data, or API inputs to train or improve our AI models without your explicit opt-in.' 'We do not log or store prompt or generation data for any open models without explicit user opt-in.' This is Privacy Policy language, not a section-numbered ToS clause, but it independently corroborates the substance of no-training-by-default via a readable document.
Documentationread2026-09-20
Fireworks data-handling docs (independently browser-read 2026-09-20): 'The Response API operates under a different retention model when store=True (the default setting).' 'Stored conversation data automatically deletes after 30 days.' 'Users can prevent storage by setting store=False in API requests.' 'The DELETE API endpoint enables immediate removal of specific records by providing the response_id.' 'The Response API retention policy only applies to conversation data when using the Response API endpoints.
Data Processing Addendumunverified2026-09-20
UNCONFIRMED as of 2026-09-20.
Securityread2026-09-20
Fireworks data-security docs (independently browser-read 2026-09-20, verbatim): 'Data is encrypted in transit (TLS 1.2+) and at rest (AES-256).' 'Dedicated workloads run in logically isolated environments, preventing cross-customer access or data leakage.' 'Fine-grained access controls are enforced across all Fireworks environments, following the principle of least privilege.' 'Regular penetration testing validates controls.' No bug bounty programme mentioned.
Vendor announcementread2026-09-20
Fireworks blog post announcing SOC 2 Type II certification and HIPAA compliance.
Vendor announcementread2026-09-20
Fireworks blog post announcing triple ISO certification: ISO 27001, ISO 27701, and ISO 42001.
Securityunverified2026-09-20
Fireworks' Trust Center portal exists at trust.fireworks.ai; it is a JS-rendered SafeBase page whose certificate/report contents were not independently retrieved this pass.
Documentationread2026-09-20
Fireworks serverless pricing docs (read directly): per-token pricing (input / cached input at a discount / output), batch inference at 50% of standard price, generic (non-featured) models priced by parameter-size band, and a 'US-only serverless' residency tier at a 1.5x premium (effective 2026-09-01).
Documentationread2026-09-20
Fireworks on-demand/dedicated-deployment docs (read directly): self-serve deployment via firectl/REST/SDKs/console, billed per GPU-second; regions are GLOBAL by default, with US/Europe/APAC/single-region pinning available but requiring a sales-granted quota.
Vendor announcementread2026-09-20
Fireworks 'Virtual Cloud' (BYOC) blog post (read directly): the Fireworks inference engine runs inside the customer's own VPC so 'data never leaves your secure environment'; GA announced 2025-06-16; access is enterprise/'contact us', not self-serve.
Slaread2026-09-20
Fireworks public status page (read directly): fully operational at check time, with per-endpoint 90-day uptime figures (~99.67-100% range) across roughly 28 tracked serverless model endpoints; no SLA/credit terms are published there.
Documentationread2026-09-20
Fireworks model catalogue page (read directly): current top models include Kimi K3/K2.7/K2.6, DeepSeek V4.1 Flash/V4 Pro/V4 Flash, GLM-5.3/5.2/4.5V, Qwen3.8 Max/Flash + VL + embeddings/reranker, Llama 3.x, Mistral Large 3/Ministral 3/Nemo, NVIDIA Nemotron 3 Ultra/3.5 Lightning, gpt-oss-120B, plus BGE-M3/Voyage embeddings and FLUX image models.
Documentationread2026-09-20
Fireworks OpenAI-compatibility docs (independently browser-read 2026-09-20): base URL 'https://api.fireworks.ai/inference/v1', confirmed OpenAI-compatible Chat Completions and Completions support.