Status page & uptime history
A public status page (status.fireworks.ai, read directly) was fully operational at check
time, with per-endpoint 90-day uptime figures in the ~99.67-100% range across roughly 28
tracked serverless model endpoints.
Security disclosure & trust centre
A trust centre exists at trust.fireworks.ai, corroborated as covering SOC 2 Type II, triple
ISO certification, and HIPAA compliance via Fireworks' own blog announcements - the JS-rendered
portal itself, and the underlying audit reports, were not independently read this pass. No public
vulnerability-disclosure programme (security.txt / bug bounty) was found.
Product/console documentation (docs.fireworks.ai) is the primary support surface. Support-tier
response commitments were not detailed in the sources read this pass - confirm what comes with
your account tier during onboarding.
Model deprecation policy
No published model-deprecation or end-of-life policy was found on Fireworks' public docs in the
sources read this pass. Because the catalogue is predominantly open-weight, a removed model can
generally be self-hosted or sourced from another provider - but confirm Fireworks' own migration
practice directly if this matters for your workload.
The ownership factor this domain covers, drawn from the one entry record.
2
TransparencyAre the binding terms published, legible and independently checkable?
ModerateThe Privacy Policy and several docs pages are legible and were independently browser-read - they state retention and training-opt-in terms clearly - but the Terms of Service and DPA, the two most contractually load-bearing documents, are page-level noindexed and could not be independently read, and the Trust Center's SOC 2/ISO/HIPAA certifications are corroborated only via company blog posts.
How this scores
Not a scored AOI dimension. For a hosted provider, transparency is whether the binding terms are published, legible and were actually read - the read/unverified evidence below, not a certification. A strong rating here must trace to a retrieved binding document.
The same evidence records as the entry sheet. Read means the text was verified; unverified means it is known to exist but not yet read.
Terms of serviceunverified2026-09-20
UNCONFIRMED as of 2026-09-20.
Privacy Policyread2026-09-20
Fireworks Privacy Policy (independently browser-read 2026-09-20, lastmod 2026-08-11): 'We do not use your prompts, training data, or API inputs to train or improve our AI models without your explicit opt-in.' 'We do not log or store prompt or generation data for any open models without explicit user opt-in.' This is Privacy Policy language, not a section-numbered ToS clause, but it independently corroborates the substance of no-training-by-default via a readable document.
Documentationread2026-09-20
Fireworks data-handling docs (independently browser-read 2026-09-20): 'The Response API operates under a different retention model when store=True (the default setting).' 'Stored conversation data automatically deletes after 30 days.' 'Users can prevent storage by setting store=False in API requests.' 'The DELETE API endpoint enables immediate removal of specific records by providing the response_id.' 'The Response API retention policy only applies to conversation data when using the Response API endpoints.
Data Processing Addendumunverified2026-09-20
UNCONFIRMED as of 2026-09-20.
Securityread2026-09-20
Fireworks data-security docs (independently browser-read 2026-09-20, verbatim): 'Data is encrypted in transit (TLS 1.2+) and at rest (AES-256).' 'Dedicated workloads run in logically isolated environments, preventing cross-customer access or data leakage.' 'Fine-grained access controls are enforced across all Fireworks environments, following the principle of least privilege.' 'Regular penetration testing validates controls.' No bug bounty programme mentioned.
Vendor announcementread2026-09-20
Fireworks blog post announcing SOC 2 Type II certification and HIPAA compliance.
Vendor announcementread2026-09-20
Fireworks blog post announcing triple ISO certification: ISO 27001, ISO 27701, and ISO 42001.
Securityunverified2026-09-20
Fireworks' Trust Center portal exists at trust.fireworks.ai; it is a JS-rendered SafeBase page whose certificate/report contents were not independently retrieved this pass.
Documentationread2026-09-20
Fireworks serverless pricing docs (read directly): per-token pricing (input / cached input at a discount / output), batch inference at 50% of standard price, generic (non-featured) models priced by parameter-size band, and a 'US-only serverless' residency tier at a 1.5x premium (effective 2026-09-01).
Documentationread2026-09-20
Fireworks on-demand/dedicated-deployment docs (read directly): self-serve deployment via firectl/REST/SDKs/console, billed per GPU-second; regions are GLOBAL by default, with US/Europe/APAC/single-region pinning available but requiring a sales-granted quota.
Vendor announcementread2026-09-20
Fireworks 'Virtual Cloud' (BYOC) blog post (read directly): the Fireworks inference engine runs inside the customer's own VPC so 'data never leaves your secure environment'; GA announced 2025-06-16; access is enterprise/'contact us', not self-serve.
Slaread2026-09-20
Fireworks public status page (read directly): fully operational at check time, with per-endpoint 90-day uptime figures (~99.67-100% range) across roughly 28 tracked serverless model endpoints; no SLA/credit terms are published there.
Documentationread2026-09-20
Fireworks model catalogue page (read directly): current top models include Kimi K3/K2.7/K2.6, DeepSeek V4.1 Flash/V4 Pro/V4 Flash, GLM-5.3/5.2/4.5V, Qwen3.8 Max/Flash + VL + embeddings/reranker, Llama 3.x, Mistral Large 3/Ministral 3/Nemo, NVIDIA Nemotron 3 Ultra/3.5 Lightning, gpt-oss-120B, plus BGE-M3/Voyage embeddings and FLUX image models.
Documentationread2026-09-20
Fireworks OpenAI-compatibility docs (independently browser-read 2026-09-20): base URL 'https://api.fireworks.ai/inference/v1', confirmed OpenAI-compatible Chat Completions and Completions support.