Alpha
Contact
Implement · Fireworks AI

Can you run it?

Ownership levelPartialnone·limited·partial·substantial·fullAnalytical input C ยท 64.8/100

This page is a projection of the one entry record, the Reliability and Data control factors that Implement covers. The full verdict is set by all four factors together, floor-weighted so the weakest caps the whole.

Which domain expands which factor
  • AssessUse & modify + Transparency
  • ImplementData control + Reliability
  • UseReliability
  • SupportTransparency

API integration

Fireworks exposes an OpenAI-compatible API at base URL https://api.fireworks.ai/inference/v1 (Chat Completions and Completions) - independently browser-confirmed 2026-09-21. Correction: a prior claim of a Responses API with MCP support was not found on the compatibility docs page and has been removed; do not rely on it.

Authentication & account setup

Public docs confirm API-key-based access via the OpenAI-compatible client libraries, but org/project key-scoping granularity is not documented in the sources read this pass - confirm the exact setup in the Fireworks console.

Region & residency configuration

On-demand deployments default to GLOBAL routing; pinning to US, Europe, or APAC (or a single specific region) requires a sales-granted quota, per the on-demand-deployment docs. A separate "US-only serverless" tier and the enterprise BYOC/Virtual-Cloud option sit at the two ends of the residency spectrum - default serverless in between is not itself region-pinned.

Rate limits, tiers & quotas

Public docs describe pricing tiers (serverless per-token, on-demand per-GPU-second, batch at 50% off) in detail, but a rate-limit/quota table for the serverless API was not surfaced in the sources read this pass - confirm current throughput limits in the console before sizing a production workload.

Portability & exit

Correction: a prior claim of a DPA Sec 11.2 30-day data-export/deletion right is unconfirmed - fireworks.ai/dpa is noindexed and unreachable to a real browser. What remains structurally true and independently confirmed: an OpenAI-compatible API over a predominantly open-weight catalogue keeps workloads portable, even without a confirmed documented exit clause.

How this scores

The ownership factors this domain covers, drawn from the one entry record.

3

ReliabilityDoes it stay up and stay secure?

Moderate

A public status page (independently browser-confirmed) shows a strong recent uptime record (~99.67-100% across 28 tracked endpoints), but no contractual SLA or service-credit clause was found, and no long multi-year track record was independently verified.

How this scores (AOI sub-dimensions)
Reliability3/5whether it stays up, with an SLA and status historyA public status page (status.fireworks.ai) shows an operational track record with per-endpoint 90-day uptime around 99.67-100% and documented incident communication.
Security3/5the controls protecting your traffic and dataDedicated workloads run in "logically isolated environments, preventing cross-customer access or data leakage" per the data-security docs (independently browser-confirmed verbatim), with TLS 1.2+ in transit and AES-256 at rest, least-privilege access controls, and customer-managed keys (CMEK).
Compliance4/5which independent certifications and attestations it holdsFireworks' own docs certifications FAQ and blog announce SOC 2 Type II (2023-10-27) plus HIPAA compliance, and a separate blog announces triple ISO certification (27001/27701/42001, 2025-11-19) - both independently browser-read; a trust centre exists at trust.fireworks.ai.
4

Doesn't extract your dataDo the binding terms keep your data and IP yours?

Moderate

CORRECTED 2026-09-20: Zero Data Retention (except the Response API) and training-only-with-opt-in are independently confirmed via readable docs and the Privacy Policy. But the ToS-level Zero Data Retention clause, the confidentiality-clause direction, and the DPA's sub-processor Schedule (including a prior claim naming Anthropic) could NOT be independently verified - the two governing documents are unreachable to a real browser. This is a genuine downgrade from a prior strong rating that rested on those unverifiable documents.

How this scores (AOI sub-dimensions)
Data governance3/5retention, training-on-inputs and data ownershipCORRECTED 2026-09-20 after independent Cowork browser verification could not reach the Terms of Service or DPA (both page-level noindexed/ROBOTS_DISALLOWED; the Trust Center hosting the DPA is JS-gated).
Residency3/5where your data is processed and storedOn-demand/dedicated deployments offer a selectable Europe (and Asia-Pacific) region with pinning, and a BYOC/Virtual-Cloud option keeps data entirely in the customer's own VPC.
What this means for adoptionYou partially own inference here: independently readable docs confirm Zero Data Retention (bar the Response API's 30-day exception) and that training only happens with your explicit opt-in - a decent baseline. But the two documents that would actually settle this - the Terms of Service and the DPA - are page-level noindexed and unreachable to a real browser, so the exact ZDR clause, the confidentiality-clause direction, and the sub-processor list (including a prior, now-unconfirmed claim that Anthropic is named) cannot be independently verified. This is a downgrade from an earlier draft that treated an automated agent's PDF read as equivalent grounding; it was not. Obtain a rendered PDF or authenticated Trust Center access before relying on the stronger claims, and set store=false on the Response API if you need genuine zero-retention there.

Sources

The same evidence records as the entry sheet. Read means the text was verified; unverified means it is known to exist but not yet read.

Terms of serviceunverified2026-09-20
UNCONFIRMED as of 2026-09-20.
Privacy Policyread2026-09-20
Fireworks Privacy Policy (independently browser-read 2026-09-20, lastmod 2026-08-11): 'We do not use your prompts, training data, or API inputs to train or improve our AI models without your explicit opt-in.' 'We do not log or store prompt or generation data for any open models without explicit user opt-in.' This is Privacy Policy language, not a section-numbered ToS clause, but it independently corroborates the substance of no-training-by-default via a readable document.
Documentationread2026-09-20
Fireworks data-handling docs (independently browser-read 2026-09-20): 'The Response API operates under a different retention model when store=True (the default setting).' 'Stored conversation data automatically deletes after 30 days.' 'Users can prevent storage by setting store=False in API requests.' 'The DELETE API endpoint enables immediate removal of specific records by providing the response_id.' 'The Response API retention policy only applies to conversation data when using the Response API endpoints.
Data Processing Addendumunverified2026-09-20
UNCONFIRMED as of 2026-09-20.
Securityread2026-09-20
Fireworks data-security docs (independently browser-read 2026-09-20, verbatim): 'Data is encrypted in transit (TLS 1.2+) and at rest (AES-256).' 'Dedicated workloads run in logically isolated environments, preventing cross-customer access or data leakage.' 'Fine-grained access controls are enforced across all Fireworks environments, following the principle of least privilege.' 'Regular penetration testing validates controls.' No bug bounty programme mentioned.
Vendor announcementread2026-09-20
Fireworks blog post announcing SOC 2 Type II certification and HIPAA compliance.
Vendor announcementread2026-09-20
Fireworks blog post announcing triple ISO certification: ISO 27001, ISO 27701, and ISO 42001.
Securityunverified2026-09-20
Fireworks' Trust Center portal exists at trust.fireworks.ai; it is a JS-rendered SafeBase page whose certificate/report contents were not independently retrieved this pass.
Documentationread2026-09-20
Fireworks serverless pricing docs (read directly): per-token pricing (input / cached input at a discount / output), batch inference at 50% of standard price, generic (non-featured) models priced by parameter-size band, and a 'US-only serverless' residency tier at a 1.5x premium (effective 2026-09-01).
Documentationread2026-09-20
Fireworks on-demand/dedicated-deployment docs (read directly): self-serve deployment via firectl/REST/SDKs/console, billed per GPU-second; regions are GLOBAL by default, with US/Europe/APAC/single-region pinning available but requiring a sales-granted quota.
Vendor announcementread2026-09-20
Fireworks 'Virtual Cloud' (BYOC) blog post (read directly): the Fireworks inference engine runs inside the customer's own VPC so 'data never leaves your secure environment'; GA announced 2025-06-16; access is enterprise/'contact us', not self-serve.
Slaread2026-09-20
Fireworks public status page (read directly): fully operational at check time, with per-endpoint 90-day uptime figures (~99.67-100% range) across roughly 28 tracked serverless model endpoints; no SLA/credit terms are published there.
Documentationread2026-09-20
Fireworks model catalogue page (read directly): current top models include Kimi K3/K2.7/K2.6, DeepSeek V4.1 Flash/V4 Pro/V4 Flash, GLM-5.3/5.2/4.5V, Qwen3.8 Max/Flash + VL + embeddings/reranker, Llama 3.x, Mistral Large 3/Ministral 3/Nemo, NVIDIA Nemotron 3 Ultra/3.5 Lightning, gpt-oss-120B, plus BGE-M3/Voyage embeddings and FLUX image models.
Documentationread2026-09-20
Fireworks OpenAI-compatibility docs (independently browser-read 2026-09-20): base URL 'https://api.fireworks.ai/inference/v1', confirmed OpenAI-compatible Chat Completions and Completions support.