Assess · Fireworks AI
Can you own it?
Ownership levelPartialnone·limited·partial·substantial·fullAnalytical input C ยท 64.8/100
This page is a projection of the one entry record, the Use & modify and Transparency factors that Assess covers. The full verdict is set by all four factors together, floor-weighted so the weakest caps the whole.
Which domain expands which factor
- AssessUse & modify + Transparency
- ImplementData control + Reliability
- UseReliability
- SupportTransparency
Data governance - retention, ZDR & training
Correction (2026-09-21): an earlier pass claimed to have read the Terms of Service Sec 3.6
directly from a downloaded PDF. An independent Cowork browser session found
fireworks.ai/terms-of-service to be page-level noindexed, returning ROBOTS_DISALLOWED - a real
browser cannot reach it, so the ToS-level clause is not independently verified. What IS confirmed,
via the readable data_handling docs page: Zero Data Retention for serverless and dedicated
inference, with one carve-out - the Response API, which stores conversation data by
default (store=true) with 30-day auto-deletion; store=false disables retention entirely,
and stored responses can be force-deleted by response_id. Separately, via the Privacy
Policy (a different, readable document): "We do not use your prompts, training data, or API
inputs to train or improve our AI models without your explicit opt-in." - training is opt-in,
not a flat "never."
Data & IP ownership
Correction (2026-09-21): a prior claim of a Terms Sec 3.2/7 ownership clause and a DPA
Schedule 4 sub-processor list (naming AWS, GCP, OCI, and Anthropic) rests on the same unreachable
documents as above - fireworks.ai/dpa is also noindexed and ROBOTS_DISALLOWED to a real
browser. These claims are not independently verified; treat them as a documented gap rather than
grounding. There is no confirmed confidentiality clause over Customer Content either way -
confidentiality is coded unknown, not functional_only, pending a rendered PDF or authenticated
Trust Center access.
Residency & sovereignty
On-demand and dedicated deployments can be pinned to US, Europe or Asia-Pacific, though region
selection beyond the default requires a sales-granted quota. A Virtual Cloud (BYOC)
option runs the inference engine inside the customer's own VPC so "data never leaves your secure
environment" - enterprise-negotiated, not self-serve. A separate "US-only serverless" tier
(1.5x price premium) implies default serverless residency is not itself EU-pinned.
CLOUD Act disclosure: Fireworks is contractually domiciled in Delaware, USA; standard US
jurisdiction applies even to EU/APAC-hosted on-demand workloads.
Compliance & attestations
Fireworks' own blog and docs FAQ (both independently browser-confirmed) announce SOC 2 Type
II (2023-10-27), HIPAA compliance, and a triple ISO certification (27001 / 27701 /
42001, 2025-11-19) - no auditor is named on either announcement and neither carries a
certificate/report date. A trust centre exists at trust.fireworks.ai, but it is fully
JS-gated - the certificates and audit reports themselves were not independently read this pass. A
prior claim that the DPA references GDPR SCCs and a UK Addendum is unconfirmed (the DPA itself is
unreachable - see Data governance).
Security controls
Independently browser-confirmed, verbatim: "Data is encrypted in transit (TLS 1.2+) and at
rest (AES-256)." Dedicated workloads run in "logically isolated environments, preventing
cross-customer access or data leakage," access follows least privilege, and
customer-managed keys are available (CMEK). "Regular penetration testing validates
controls" - now confirmed verbatim. No public bug-bounty programme was found, and the
serverless multi-tenancy isolation model itself was not detailed in the sources read (only the
dedicated tier is described).
Pricing & cost model
Per-token serverless pricing (input / discounted cached-input / output) is published directly on
Fireworks' pricing docs, alongside per-GPU-second dedicated pricing. Batch inference runs at
50% of standard price; generic (non-featured) models are priced by parameter-size band; a
"US-only serverless" residency tier carries a 1.5x premium. Example rates: Kimi K3
$3.00/$0.30-cached/$15.00 per 1M tokens; DeepSeek V4.1 Flash $0.30/$0.006-cached/$1.20; GLM-5.3
Flash $0.15/$0.03-cached/$0.50.
Reliability posture
A public status page (status.fireworks.ai, read directly) shows per-endpoint 90-day uptime in
the ~99.67-100% range across roughly 28 tracked serverless model endpoints. No SLA or
service-credit clause was found in the standard Terms of Service - an enterprise contract may
carry a separate, non-public SLA.
How this scores
The ownership factors this domain covers, drawn from the one entry record.
1
Use and modify freelyCan you use it freely and leave without lock-in?
StrongAn OpenAI-compatible API (independently browser-confirmed) over a predominantly open-weight catalogue keeps workloads portable - the same checkpoints run elsewhere or self-hosted, independent of Fireworks' own contract terms.
How this scores (AOI sub-dimensions)
Transparency & lock-in3/5how portable it is and how easily you can leaveCORRECTED 2026-09-20: an OpenAI-compatible API over a predominantly open-weight catalogue keeps workloads portable - the base URL and chat/completions support are independently browser-confirmed.
Cost4/5how the pricing model compares and how predictable it isPer-token serverless pricing (with a discounted cached-input rate and a 50% batch discount) and per-GPU-second dedicated pricing are both public and documented in detail, read directly from Fireworks' own pricing docs, and are broadly competitive for the class (e.g.
2
TransparencyAre the binding terms published, legible and independently checkable?
ModerateThe Privacy Policy and several docs pages are legible and were independently browser-read - they state retention and training-opt-in terms clearly - but the Terms of Service and DPA, the two most contractually load-bearing documents, are page-level noindexed and could not be independently read, and the Trust Center's SOC 2/ISO/HIPAA certifications are corroborated only via company blog posts.
How this scores
Not a scored AOI dimension. For a hosted provider, transparency is whether the binding terms are published, legible and were actually read - the read/unverified evidence below, not a certification. A strong rating here must trace to a retrieved binding document.
What this means for adoptionYou partially own inference here: independently readable docs confirm Zero Data Retention (bar the Response API's 30-day exception) and that training only happens with your explicit opt-in - a decent baseline. But the two documents that would actually settle this - the Terms of Service and the DPA - are page-level noindexed and unreachable to a real browser, so the exact ZDR clause, the confidentiality-clause direction, and the sub-processor list (including a prior, now-unconfirmed claim that Anthropic is named) cannot be independently verified. This is a downgrade from an earlier draft that treated an automated agent's PDF read as equivalent grounding; it was not. Obtain a rendered PDF or authenticated Trust Center access before relying on the stronger claims, and set store=false on the Response API if you need genuine zero-retention there.
Sources
The same evidence records as the entry sheet. Read means the text was verified; unverified means it is known to exist but not yet read.
Terms of serviceunverified2026-09-20
UNCONFIRMED as of 2026-09-20.
Privacy Policyread2026-09-20
Fireworks Privacy Policy (independently browser-read 2026-09-20, lastmod 2026-08-11): 'We do not use your prompts, training data, or API inputs to train or improve our AI models without your explicit opt-in.' 'We do not log or store prompt or generation data for any open models without explicit user opt-in.' This is Privacy Policy language, not a section-numbered ToS clause, but it independently corroborates the substance of no-training-by-default via a readable document.
Documentationread2026-09-20
Fireworks data-handling docs (independently browser-read 2026-09-20): 'The Response API operates under a different retention model when store=True (the default setting).' 'Stored conversation data automatically deletes after 30 days.' 'Users can prevent storage by setting store=False in API requests.' 'The DELETE API endpoint enables immediate removal of specific records by providing the response_id.' 'The Response API retention policy only applies to conversation data when using the Response API endpoints.
Data Processing Addendumunverified2026-09-20
UNCONFIRMED as of 2026-09-20.
Securityread2026-09-20
Fireworks data-security docs (independently browser-read 2026-09-20, verbatim): 'Data is encrypted in transit (TLS 1.2+) and at rest (AES-256).' 'Dedicated workloads run in logically isolated environments, preventing cross-customer access or data leakage.' 'Fine-grained access controls are enforced across all Fireworks environments, following the principle of least privilege.' 'Regular penetration testing validates controls.' No bug bounty programme mentioned.
Vendor announcementread2026-09-20
Fireworks blog post announcing SOC 2 Type II certification and HIPAA compliance.
Vendor announcementread2026-09-20
Fireworks blog post announcing triple ISO certification: ISO 27001, ISO 27701, and ISO 42001.
Securityunverified2026-09-20
Fireworks' Trust Center portal exists at trust.fireworks.ai; it is a JS-rendered SafeBase page whose certificate/report contents were not independently retrieved this pass.
Documentationread2026-09-20
Fireworks serverless pricing docs (read directly): per-token pricing (input / cached input at a discount / output), batch inference at 50% of standard price, generic (non-featured) models priced by parameter-size band, and a 'US-only serverless' residency tier at a 1.5x premium (effective 2026-09-01).
Documentationread2026-09-20
Fireworks on-demand/dedicated-deployment docs (read directly): self-serve deployment via firectl/REST/SDKs/console, billed per GPU-second; regions are GLOBAL by default, with US/Europe/APAC/single-region pinning available but requiring a sales-granted quota.
Vendor announcementread2026-09-20
Fireworks 'Virtual Cloud' (BYOC) blog post (read directly): the Fireworks inference engine runs inside the customer's own VPC so 'data never leaves your secure environment'; GA announced 2025-06-16; access is enterprise/'contact us', not self-serve.
Slaread2026-09-20
Fireworks public status page (read directly): fully operational at check time, with per-endpoint 90-day uptime figures (~99.67-100% range) across roughly 28 tracked serverless model endpoints; no SLA/credit terms are published there.
Documentationread2026-09-20
Fireworks model catalogue page (read directly): current top models include Kimi K3/K2.7/K2.6, DeepSeek V4.1 Flash/V4 Pro/V4 Flash, GLM-5.3/5.2/4.5V, Qwen3.8 Max/Flash + VL + embeddings/reranker, Llama 3.x, Mistral Large 3/Ministral 3/Nemo, NVIDIA Nemotron 3 Ultra/3.5 Lightning, gpt-oss-120B, plus BGE-M3/Voyage embeddings and FLUX image models.
Documentationread2026-09-20
Fireworks OpenAI-compatibility docs (independently browser-read 2026-09-20): base URL 'https://api.fireworks.ai/inference/v1', confirmed OpenAI-compatible Chat Completions and Completions support.