Security disclosure & trust centre
Groq's public trust centre (trust.groq.com) is the trust surface, covering its SOC 2 Type
II, GDPR and HIPAA posture and a sub-processor list. A dedicated vulnerability-disclosure
process - a published security.txt, advisory feed, or bug-bounty - was not surfaced this
session, so for coordinated disclosure plan to go through the trust-centre/support contacts rather
than a standing security channel.
Support rests on product and console documentation (console.groq.com/docs). The response
commitments attached to each paid tier and the breadth of community channels (Discord/forum) were
not detailed in the sources read, so confirm the support SLA that comes with your tier during
onboarding.
Model deprecation policy
Groq publishes a model-deprecation policy in its docs. It gives commercially reasonable prior
notice before deprecating a model, and for production models it provides a clear migration
path and a recommended replacement; preview models may be discontinued at short notice.
If you have prepaid for a model that is deprecated without an alternative, Groq offers a
pro-rata refund for the unused prepaid fees. Because the catalogue is open-weight, a removed model
can also generally be self-hosted or sourced from another provider - so deprecation is a migration
task, not a lock-out.
The ownership factor this domain covers, drawn from the one entry record.
2
TransparencyAre the binding terms published, legible and independently checkable?
ModerateThe governing Services Agreement and DPA were read this session and are legible - they state customer IP retention, never-train, retention windows and a published sub-processor list - but the SOC 2 report itself is gated (not read) and ISO 27001/region-pinning are unconfirmed.
How this scores
Not a scored AOI dimension. For a hosted provider, transparency is whether the binding terms are published, legible and were actually read - the read/unverified evidence below, not a certification. A strong rating here must trace to a retrieved binding document.
The same evidence records as the entry sheet. Read means the text was verified; unverified means it is known to exist but not yet read.
Documentationread2026-07-25
By default Groq does not retain customer data for inference requests; Groq is not permitted to use Inputs or Outputs to train or fine-tune AI Model Services or other models and will never access Customer Data for training; batch input/output files are retained 30 days unless deleted; fine-tuning weights/datasets are retained until deleted; all customers may enable ZDR in Data Controls; retained data sits in US GCP buckets.
Terms of serviceread2026-07-25
Groq Services Agreement: Customer retains all Intellectual Property Rights in Customer Data (including Inputs and Outputs); Groq will never access Customer Data for training and is not permitted to use Inputs/Outputs to train or fine-tune models; Groq does not access, use, store or retain Inputs/Outputs except as necessary to provide the Cloud Services; on termination Customer Data is deleted within 30 days; eligible customers may enable zero data retention in the Console.
Data Processing Addendumread2026-07-25
GroqCloud Data Processing Addendum: covers GDPR/CCPA/PDPL; Groq maintains a sub-processor list at trust.groq.com/subprocessors with a 15-day written objection right; Personal Data may be transferred to and Processed in the United States and other countries; batch files retained 30 days, fine-tuning data until deleted, ZDR available via Data Controls.
Data Processing Addendumread2026-07-25
GroqCloud Business Associate Addendum: supplements the Services Agreement; Groq acts as business associate/subcontractor for PHI with administrative, technical and physical safeguards; the Compound system is excluded as not a HIPAA Covered Cloud Service.
Securityread2026-07-25
Groq trust centre states SOC 2 Type II is maintained (2025 report) and hosts the GDPR/HIPAA compliance posture and a sub-processor list (updated November 2025); the SOC 2 report itself is gated behind request.
Subprocessorsunverified2026-07-25
Groq publishes its sub-processor list and the nature of services they provide at trust.groq.com/subprocessors (referenced by the DPA); the individual sub-processor entries were not enumerated this session.
Vendor announcementread2026-07-25
Groq launched its first European data centre footprint in Helsinki, Finland on 6 July 2025 with Equinix, bringing inference capacity closer to EU users; Equinix Fabric offers public, private or sovereign infrastructure and builds on Groq's existing Dallas US site.
Vendor announcementread2026-07-25
Groq pricing page: per-token rates including Llama 3.3 70B $0.59/M in, $0.79/M out and gpt-oss-120B $0.15/M in, $0.60/M out, with a free/developer tier; other example rates are approximate.
Documentationread2026-07-25
Groq OpenAI-compatibility docs: use the OpenAI client libraries against base URL https://api.groq.com/openai/v1 with a Groq API key; the /openai/v1/models endpoint lists active models; some advanced OpenAI features are not yet supported.
Documentationread2026-07-25
Groq supported-models docs list the served open-weight catalogue (Llama 3.1 8B, Llama 3.3 70B, gpt-oss 20B/120B, Qwen3, Gemma, Mixtral, DeepSeek R1 Distill Llama 70B) plus Whisper speech-to-text.
Documentationread2026-07-25
Groq model-deprecation docs: Groq gives commercially reasonable prior notice, provides a migration path and recommended replacement for deprecated production models, may discontinue preview models at short notice, and offers a pro-rata refund for prepaid deprecated models left without an alternative.
Documentationread2026-07-25
Groq rate-limits docs: free/developer-tier quotas - e.g.
Terms of serviceunverified2026-07-25
Groq publishes an Acceptable Use & Responsible AI Policy governing permitted use of the Cloud Services; its clauses were not read in full this session.