Contact
Assess · Groq

Can you own it?

Ownership levelSubstantialnone·limited·partial·substantial·fullAnalytical input B ยท 70/100

This page is a projection of the one entry record, the Use & modify and Transparency factors that Assess covers. The full verdict is set by all four factors together, floor-weighted so the weakest caps the whole.

Which domain expands which factor
  • AssessUse & modify + Transparency
  • ImplementData control + Doesn't fail you
  • UseDoesn't fail you
  • SupportTransparency

Data governance - retention, ZDR & training

The governing documents - the Groq Services Agreement and the your-data docs, both read this session - say inference is not retained by default and is never trained on: Groq "is not permitted to use Inputs or Outputs for training or fine-tuning any AI Model Services or other models" and "will never access Customer Data for training purposes." Zero data retention is available to all customers through Data Controls, not gated to an enterprise tier. Because Groq serves open-weight models on its own LPU hardware, there is no closed third-party model whose data terms would attach to routed inference.

The caveat is in the non-inference features: batch processing retains input/output files for 30 days unless deleted, and fine-tuning retains weights and datasets until the customer deletes them, with that retained data stored in US GCP buckets. So the "not retained" headline holds for streaming inference but not automatically for batch or fine-tuning workflows - plan those data lifecycles explicitly.

Data & IP ownership

The Services Agreement is explicit: the customer "retains all Intellectual Property Rights in Customer Data (including in Inputs and Outputs)," and Groq "does not access, use, store, or retain Inputs or Outputs except as necessary to provide the Cloud Services." Combined with never-training and open-weight-only serving, your data and the knowledge derived from it stay yours. The DPA discloses a published sub-processor list at trust.groq.com/subprocessors with a 15-day written objection right - a correction to the earlier "not disclosed" reading. The caveats are lifecycle rather than training: the batch (30-day) and fine-tuning features retain data in US GCP storage until you delete it. Contractualise the specifics through the DPA and BAA.

Compliance & attestations

The trust centre states SOC 2 Type II is maintained (2025 report). The DPA - read this session - covers GDPR, CCPA and PDPL, and a HIPAA BAA is offered (the BAA excludes the Compound system as a non-covered service). ISO 27001 / 27701 are unconfirmed, and the SOC 2 report itself is gated behind request rather than read here. For ISO-dependent or healthcare procurement, request the current attestation letters and countersign the BAA directly.

Data residency & jurisdiction

Default storage is US, with a European data centre in Helsinki, Finland launched (with Equinix) on 6 July 2025. The EU footprint is therefore real but very recent, region pinning is unconfirmed, and the DPA expressly permits Processing in the United States and other countries - so treat EU residency as an emerging capability to validate in onboarding rather than a mature guarantee. As a US-headquartered company, Groq also carries standing US CLOUD Act exposure regardless of region.

Security controls

Documented controls include SOC 2 Type II scope (trust centre), Data Controls for enabling ZDR, and the Services Agreement's commitment that Groq does not access, store or retain Inputs or Outputs except to provide the service. No independently reviewed penetration test surfaced, and the SOC 2 report itself was not read this session - so this is assessed as solid-but-partial: day-to-day controls are documented, but the deepest independent assurance is not visible.

Pricing & cost model

Pricing is per-token with a rate-limited free/developer tier, read from Groq's own pricing page. Confirmed rates include Llama 3.3 70B $0.59/$0.79 and gpt-oss-120B $0.15/$0.60 per M in/out; other example rates (Llama 3.1 8B $0.05/$0.08, DeepSeek R1 Distill Llama 70B $0.75/$0.99) are approximate, so treat them as an order-of-magnitude guide and confirm live rates before committing.

Reliability posture

The trust centre attests operational controls, but Groq is a fast-scaling hardware startup with no public uptime SLA or status history independently verified this session. Reliability is therefore assessed conservatively: adequate on available evidence, but without an observable status/SLA record to lean on for availability-critical workloads.

How this scores

The ownership factors this domain covers, drawn from the one entry record.

1

Use and modify freelyCan you use it freely and leave without lock-in?

Strong

OpenAI-compatible API (docs read: base URL https://api.groq.com/openai/v1) over open-weight models keeps workloads portable - the same checkpoints run elsewhere or self-hosted - and the Services Agreement confirms the customer retains all IP in Inputs/Outputs; the custom LPU and narrower catalogue are coverage limits, not exit blockers.

How this scores (AOI sub-dimensions)
Transparency & lock-in3/5how portable it is and how easily you can leaveAn OpenAI-compatible API (base URL read from the docs) over open-weight models keeps it portable, but custom LPU hardware and a narrower/curated catalogue (no full DeepSeek/GLM/Mistral or arbitrary fine-tunes) limit coverage and are lock-in considerations.
Cost4/5how the pricing model compares and how predictable it isLow per-token rates read from Groq's own pricing page (Llama 3.3 70B $0.59/$0.79, gpt-oss-120B $0.15/$0.60) plus a rate-limited free/developer tier (e.g.
2

TransparencyAre the binding terms published, legible and independently checkable?

Moderate

The governing Services Agreement and DPA were read this session and are legible - they state customer IP retention, never-train, retention windows and a published sub-processor list - but the SOC 2 report itself is gated (not read) and ISO 27001/region-pinning are unconfirmed.

How this scores
Not a scored AOI dimension. For a hosted provider, transparency is whether the binding terms are published, legible and were actually read - the read/unverified evidence below, not a certification. A strong rating here must trace to a retrieved binding document.
What this means for adoptionYou substantially own low-latency inference here: the Groq Services Agreement and your-data docs - actually read this session - confirm you keep all IP in Inputs/Outputs, Groq never trains on your data, inference is not retained by default, and ZDR is available to all via Data Controls, with a portable OpenAI-compatible API exit. It falls short of full because the opt-in batch and fine-tuning paths retain data in US GCP storage, the SOC 2 report and ISO posture are unverified, and the US HQ (DPA permits US processing) carries CLOUD Act exposure. Turn on ZDR, keep sensitive data out of the batch/fine-tuning paths, and look to an EU-sovereign provider if you need mature EU residency.

Sources

The same evidence records as the entry sheet. Read means the text was verified; unverified means it is known to exist but not yet read.

Documentationread2026-07-25
By default Groq does not retain customer data for inference requests; Groq is not permitted to use Inputs or Outputs to train or fine-tune AI Model Services or other models and will never access Customer Data for training; batch input/output files are retained 30 days unless deleted; fine-tuning weights/datasets are retained until deleted; all customers may enable ZDR in Data Controls; retained data sits in US GCP buckets.
Terms of serviceread2026-07-25
Groq Services Agreement: Customer retains all Intellectual Property Rights in Customer Data (including Inputs and Outputs); Groq will never access Customer Data for training and is not permitted to use Inputs/Outputs to train or fine-tune models; Groq does not access, use, store or retain Inputs/Outputs except as necessary to provide the Cloud Services; on termination Customer Data is deleted within 30 days; eligible customers may enable zero data retention in the Console.
Data Processing Addendumread2026-07-25
GroqCloud Data Processing Addendum: covers GDPR/CCPA/PDPL; Groq maintains a sub-processor list at trust.groq.com/subprocessors with a 15-day written objection right; Personal Data may be transferred to and Processed in the United States and other countries; batch files retained 30 days, fine-tuning data until deleted, ZDR available via Data Controls.
Data Processing Addendumread2026-07-25
GroqCloud Business Associate Addendum: supplements the Services Agreement; Groq acts as business associate/subcontractor for PHI with administrative, technical and physical safeguards; the Compound system is excluded as not a HIPAA Covered Cloud Service.
Securityread2026-07-25
Groq trust centre states SOC 2 Type II is maintained (2025 report) and hosts the GDPR/HIPAA compliance posture and a sub-processor list (updated November 2025); the SOC 2 report itself is gated behind request.
Subprocessorsunverified2026-07-25
Groq publishes its sub-processor list and the nature of services they provide at trust.groq.com/subprocessors (referenced by the DPA); the individual sub-processor entries were not enumerated this session.
Vendor announcementread2026-07-25
Groq launched its first European data centre footprint in Helsinki, Finland on 6 July 2025 with Equinix, bringing inference capacity closer to EU users; Equinix Fabric offers public, private or sovereign infrastructure and builds on Groq's existing Dallas US site.
Vendor announcementread2026-07-25
Groq pricing page: per-token rates including Llama 3.3 70B $0.59/M in, $0.79/M out and gpt-oss-120B $0.15/M in, $0.60/M out, with a free/developer tier; other example rates are approximate.
Documentationread2026-07-25
Groq OpenAI-compatibility docs: use the OpenAI client libraries against base URL https://api.groq.com/openai/v1 with a Groq API key; the /openai/v1/models endpoint lists active models; some advanced OpenAI features are not yet supported.
Documentationread2026-07-25
Groq supported-models docs list the served open-weight catalogue (Llama 3.1 8B, Llama 3.3 70B, gpt-oss 20B/120B, Qwen3, Gemma, Mixtral, DeepSeek R1 Distill Llama 70B) plus Whisper speech-to-text.
Documentationread2026-07-25
Groq model-deprecation docs: Groq gives commercially reasonable prior notice, provides a migration path and recommended replacement for deprecated production models, may discontinue preview models at short notice, and offers a pro-rata refund for prepaid deprecated models left without an alternative.
Documentationread2026-07-25
Groq rate-limits docs: free/developer-tier quotas - e.g.
Terms of serviceunverified2026-07-25
Groq publishes an Acceptable Use & Responsible AI Policy governing permitted use of the Cloud Services; its clauses were not read in full this session.